PCI DSS Compliance
Handle payment card data safely under PCI DSS. Scope your cardholder data environment, pick the right SAQ, implement required controls like encryption, segmentation, and logging, minimize scope with tokenization, and prepare evidence for your acquirer or QSA.
This skill guides teams through PCI DSS for storing, processing, or transmitting cardholder data. It helps you define and shrink your CDE scope, select the correct Self-Assessment Questionnaire, implement mandated controls (encryption, access control, network segmentation, logging), lean on tokenization and hosted fields to reduce scope, and assemble evidence for assessment.
When to use
Use when building payment flows or e-commerce that touch card data — scoping the CDE, choosing an SAQ, implementing controls, and reducing scope with tokenization.
Examples
Scope the CDE
Define what's in scope
Help me scope my PCI DSS cardholder data environment and identify which systems are in scope
Reduce scope
Tokenization and hosted fields
Redesign my checkout to use tokenization and hosted payment fields so I qualify for a simpler SAQ
Pick the right SAQ
Match your architecture
Given that we never store card numbers and use Stripe hosted fields, which PCI DSS SAQ applies and what controls do we still need?