PCI DSS v4.0: Payment Card Industry Data Security Standard

PCI DSS v4.0 is the mandatory security standard for any organization handling card payments. Self-hosting payment infrastructure can radically reduce your compliance scope — or expand it.

🛡️ STATUS BADGE: 🟢 ELIGIBLE (Self-Hosted)

Executive Summary: What is it?

The Payment Card Industry Data Security Standard (PCI DSS) is a global security framework mandated by the card networks (Visa, Mastercard, Amex, Discover) for any organization that stores, processes, or transmits cardholder data. Version 4.0 became the sole enforced standard in March 2024, replacing v3.2.1. Critically, PCI DSS certifies the merchant environment, not the software itself — no tool ships as "PCI certified." What software can do is reduce how much of your environment falls within scope.

CFO / Business Impact: What does it cost/risk?

Technical Reality: How does it work?