# PCI DSS Requirements | Secureframe

> Learn the key requirements of PCI DSS, including data subject rights, data privacy principles, and data transfer requirements.

canonical: https://secureframe.com/hub/pci-dss/report

Not only is [PCI DSS compliance](https://secureframe.com/hub/pci-dss/what-is-pci-dss-compliance) a requirement for any organization that impacts the security of [cardholder data](https://secureframe.com/hub/pci-dss/cardholder-data), the framework is regarded as one of the best ways to secure confidential transaction data from theft or fraud and build trust with customers. 

PCI DSS is difficult to maintain, explaining why  [only 27.9% of organizations achieved 100% PCI compliance](https://www.verizon.com/business/reports/payment-security-report/2022/the-state-of-pci-dss-compliance/) when assessed between audits in 2019 and only 43.4% did in 2020. This indicates that the majority of organizations are putting the security of customers’ cardholder data at risk due to a lack of long-term PCI compliance strategy and execution. 

One challenge is the framework’s complexity. It currently consists of 6 prime objectives, 12 requirements, and hundreds of controls.

To help you get a clear understanding of this framework and guidance for [how to comply](https://secureframe.com/hub/pci-dss/how-to-become-pci-compliant), we are going to focus on the key areas below.

## Intermediate: I’m preparing for PCI DSS compliance

**So you’re in prep mode for PCI DSS compliance. **

Accepting payment cards means that your company needs to comply with PCI DSS to protect customer data. 

Consisting of 6 prime objectives, 12 requirements, and hundreds of controls, PCI DSS is among the most complex security and compliance standards.

We’ll cover some key areas below to ensure you have a clear understanding of this framework before offering guidance for how to comply.

## What are PCI DSS compliance requirements?

PCI DSS requirements cover a wide range of operational and technical controls that impact not only how cardholder data is stored, processed, or transmitted but also ensure the security of the machines and networks involved in these processes and the personnel responsible for administration of these controls.

The [12 requirements](https://secureframe.com/hub/pci-dss/12-requirements) are:

- Install and maintain network security controls
- Apply secure configurations to all system components
- Protect stored account data
- Protect cardholder data with strong cryptography during transmission over open, public networks
- Protect all systems and networks from malicious software
- Develop and maintain secure systems and software
- Restrict access to system components and cardholder data by business need-to-know
- Identify users and authenticate access to system components
- Restrict physical access to cardholder data
- Log and monitor all access to system components and cardholder data
- Test security of systems and networks regularly
- Support information security with organizational policies and programs

## Which cardholder data is protected by PCI DSS?

Cardholder data protected by PCI DSS includes the full Primary Account Number (PAN) along with any of the following information: cardholder name, expiration date, and service code. 

Under PCI DSS requirement 3, organizations can store PANs, cardholder names, and expiration dates. However, they cannot store CVVs or additional data elements known as sensitive authentication data.

## What are the levels of PCI compliance?

The PCI DSS standard has six levels of compliance in total — four for merchants and two for service providers — based on the number of card transactions processed annually. Each PCI compliance level has a different set of requirements so it’s important to identify which your business falls under.

The [PCI compliance levels](https://secureframe.com/hub/pci-dss/levels) are: 

- **Merchant Level 1**: More than 6M transactions
- **Merchant Level 2**: 1-6M transactions
- **Merchant Level 3**: 20k-1M transactions
- **Merchant Level 4**: Less than 20k transactions
- **Service Provider Level 1**: More than 300k transactions
- **Service Provider Level 2**: Less than 300k transactions

## Streamline PCI DSS compliance with automation 

[Compliance automation software](https://secureframe.com/hub/pci-dss/manual-vs-automated) cuts out hundreds of hours of manual work when you’re preparing for PCI compliance. Look for software that integrates with your tech stack to automate evidence collection and continuously monitor your infrastructure for vulnerabilities. Vendor management, employee onboarding, and expert support throughout the assessment are also key features to look for.
