Overview
PCI DSS is a global standard for protecting cardholder data. Your obligations depend on how you accept payments and whether your systems store, process, or transmit card data. Use this tool to plan, validate, and maintain compliance.
Checklist (12 key areas)
Cost estimator
Inputs
Use these fields to visualize possible exposure from processor statements. Values are indicative; adjust for your situation.
Estimate
Annual recurring
€0
One-off (this year)
€0
Potential non-compliance exposure
€0
Estimated total (this year)
€0
Informational only. Not a quote.
PCI FAQs (Quick answers)
In plain language
- Small, redirect-only online sellers: likely SAQ A. Keep card data off your systems, run quarterly scans, train staff, and complete the annual SAQ.
- Custom checkout or browser scripts: may require SAQ A-EP or D. Plan for pen testing, script integrity controls, and more logging.
- In-person with validated terminals: keep terminals updated, segment networks, and follow provider attestation steps.
© Your Company. PCI DSS® is a registered trademark of PCI SSC.