# PCI DSS Overview | Secureframe

> Learn the basics of PCI DSS, including how it applies to your business and customers, who enforces it, and the consequences of non-compliance.

canonical: https://secureframe.com/hub/pci-dss/overview

[Nearly half of all American adults](https://www.security.org/digital-safety/credit-card-fraud-report/) — approximately 127 million people — have had a fraudulent charge on their credit or debit cards.

In 2004, the Payment Card Industry Data Security Standard (PCI DSS) was created as an internationally uniform standard to make card transactions more secure for both businesses and their customers. Today, it is well regarded and the industry standard to secure confidential card data from fraud or theft and build trust with customers. 

Any organization that accepts, handles, stores, transmits, or could impact the security of card payment information will understand the importance of these objectives, especially if they’re trying to grow their business.

In this overview for beginners, we’ve broken down the PCI DSS framework into clear-cut fundamentals so you can quickly and easily understand whether you need to be compliant. 

You’ll learn everything you need to know about PCI DSS, including why it was created, how it applies to your business and customers, the benefits of compliance, and the consequences of non-compliance.

## Beginner: I'm New to PCI DSS

**Let’s start from the beginning. **

Understanding the basics of PCI compliance helps streamline the entire preparation and assessment process, allowing you to [get compliant](https://secureframe.com/hub/pci-dss/how-to-become-pci-compliant) faster and with less stress.

Here are the essentials you need to know.

## The Basics of PCI DSS

The Payment Card Industry Data Security Standard (commonly known as PCI DSS) is a set of security requirements for merchants and service providers that store, process, transmit, or could impact the security of card data.

It is administered and managed by the PCI Security Standards Council (PCI SSC), an independent body that was created by Visa, MasterCard, American Express, Discover and JCB.

## The History and Purpose of PCI DSS

Although the first version of PCI DSS was passed in 2004, its roots stretch back to the late 90s when online shopping was introduced. This led to a significant spike in payment fraud.   

In response, Visa established its [own set of security standards](https://usa.visa.com/partner-with-us/pci-dss-compliance-information.html) for businesses accepting payments online in 2001. Other payment companies followed suit, which left merchants struggling to meet multiple sets of security standards.

As payment fraud continued to rise, the major payment card brands — American Express, Discover Financial Services, JCB International, Mastercard and Visa — came together to establish a uniform way to regulate payment security among merchants and service providers. 

This led to the first iteration of PCI DSS, which was introduced in December 2004. The standard has continued to evolve to meet the ever changing payment card industry and the new technologies being implemented daily.

## How do you become PCI compliant? 

To achieve compliance, merchants and service providers must follow certain requirements for storing, processing, transmitting, and securing cardholder data. 

[The 12 requirements](https://secureframe.com/hub/pci-dss/12-requirements) are:

- Install and maintain network security controls
- Apply secure configurations to all system components
- Protect stored account data
- Protect cardholder data with strong cryptography during transmission over open, public networks
- Protect all systems and networks from malicious software
- Develop and maintain secure systems and software
- Restrict access to system components and cardholder data by business need-to-know
- Identify users and authenticate access to system components
- Restrict physical access to cardholder data
- Log and monitor all access to system components and cardholder data
- Test security of systems and networks regularly
- Support information security with organizational policies and programs

Now that you have a solid understanding of what PCI DSS is, let’s dive deeper into the compliance process.
