What the PCI DSS standard actually assesses
PCI DSS (Payment Card Industry Data Security Standard) is the global security standard that applies to any organisation that stores, processes or transmits cardholder data. The current version is v4.0.1, which has been in force since 31 March 2025.
The PCI DSS standard is structured around a number of requirements covering the entire cardholder data environment (CDE):
- network security (firewall, segmentation),
- access control for sensitive data,
- password policy and strong authentication,
- monitoring of access and events,
- vulnerability and patch management,
- data protection through encryption in transit and at rest,
- periodic penetration tests.
In total, version 4.0 comprises more than 250 security controls. This scope covers both the physical infrastructure (data centres, end-user devices) and web applications, making it a substantial framework.
The four PCI DSS levels
The PCI DSS standard classifies organisations into four levels based on their annual volume of card transactions:
- Level 1: over 6 million,
- Level 2: between 1 and 6 million,
- Level 3: between 20,000 and 1 million,
- Level 4: under 20,000.
The method of validating compliance depends on the PCI DSS level:
- Levels 2 to 4 are based on a self-assessment questionnaire (SAQ), the depth of which varies depending on the chosen integration method. An SAQ-A comprises 24 questions; an SAQ-D comprises 329. In both cases, it is the organisation itself that certifies its compliance.
- Level 1 operates differently. It requires an annual audit conducted by an independent Qualified Security Assessor (QSA), quarterly scans by an Approved Scanning Vendor (ASV) and annual penetration tests. The auditor produces a Report of Compliance (RoC) and a signed Attestation of Compliance (AoC). PCI DSS Level 1 certification is therefore based on third-party verification, not on a self-assessment.
PCI DSS Level 1: a business selection criterion
When selecting payment service providers, business customers systematically require the highest level of security, accompanied by a certificate of compliance issued by a qualified assessor.
This mechanism is explained by the logic of cascading audits: a company subject to internal or regulatory audits must be able to demonstrate that its critical suppliers have adequate security controls in place. A payment service provider (PSP) that processes its customers’ card details is one such supplier.
The regulatory environment is driving this trend. DORA, which has applied to European financial institutions since January 2025, imposes operational resilience requirements that largely overlap with PCI DSS controls. For organisations falling within the scope of DORA, working with PCI DSS Level 1-certified service providers forms part of a coherent compliance strategy.
What certification offers customers
When a merchant integrates payments via a PCI DSS Level 1-certified service provider using hosted or tokenised components (hosted payment page, input fields isolated on the PSP side), sensitive card data never passes through the merchant’s own systems. Their environment is then deemed to be outside the scope for card data, which allows them to remain on an SAQ-A rather than an SAQ-D, reducing the compliance effort tenfold.
In practice, an e-commerce manager or finance director who chooses a PCI DSS-certified payment service provider (PSP) simplifies their own compliance programme, reduces the workload on their IT teams and limits their exposure in the event of an incident. This is a tangible operational benefit, not merely a sign of trust.
CentralPay is PCI DSS Level 1 certified. Merchants using its hosted integration methods benefit directly from this reduced scope in their own compliance process.
PCI DSS as an indicator of overall security maturity
The PCI DSS requirements overlap with those of other information security standards, such as ISO 27001 on security management, NIS2 on the resilience of critical infrastructure, and DORA on the operational resilience of financial institutions.
This convergence has a practical implication: a PCI DSS Level 1-certified service provider has already implemented a significant proportion of the security controls required by these other frameworks. For a client subject to multiple standards, this reduces the workload involved in supplier qualification. PCI DSS certification thus becomes an indicator of overall security maturity.
By 2026–2027, regulatory requirements regarding cybersecurity for organisations handling financial data will continue to tighten across Europe. Against this backdrop, PCI DSS certification will become a key selling point.


