retail and ecommerce

PCI DSS for retail and ecommerce

PCI DSS 4.0.1 applies to any retailer or ecommerce business that stores, processes, or transmits cardholder data. For most merchants the practical goal is to reduce how much of your environment touches card data.

Start free PCI DSS overview

Why it matters for retail and ecommerce

Card networks require PCI DSS compliance to accept payments. For retail and ecommerce, non-compliance risks fines and losing the ability to take card payments, which is existential for a store.

What to focus on

Scope reduction is the main lever

Using a compliant payment processor, hosted payment pages, and tokenization keeps most of your systems out of scope. The less of your environment that touches card data, the smaller and cheaper your assessment.

The 12 requirements

PCI DSS groups controls into 12 requirements spanning network security, protecting cardholder data, vulnerability management, access control, monitoring, and policy. Many overlap with general security hygiene.

Know your merchant level

Your transaction volume sets your merchant level, which determines whether you validate with a Self-Assessment Questionnaire or a full Report on Compliance. Your acquiring bank confirms which applies.

Do it once, not twice

Keel is built on one crosswalked control library, so a control you implement for PCI DSS counts toward every other framework it satisfies. Add a second framework later and it mostly reuses this work. See the crosswalk explorer for the exact overlap.

Start free Check your readiness

Common questions

How do retailers lower PCI DSS cost?

By reducing scope: use a PCI-compliant processor and tokenization so your own systems rarely touch raw card data. Less scope means a simpler assessment and lower ongoing cost.

Which PCI DSS version applies?

PCI DSS 4.0.1 is the current version. Keel authors its PCI DSS content against 4.0 (requirements unchanged in 4.0.1).

Framework names are referenced factually for guidance. Keel is not affiliated with or endorsed by the bodies that publish them. See our legal and trademarks page.