<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Pci-Ssc on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/pci-ssc/</link><description>Recent content in Pci-Ssc on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/pci-ssc/index.xml" rel="self" type="application/rss+xml"/><item><title>PCI-DSS</title><link>https://lesitedefrancois.be/en/compliance/pci-dss/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/pci-dss/</guid><description>&lt;p&gt;The &lt;strong&gt;Payment Card Industry Data Security Standard (PCI-DSS)&lt;/strong&gt; is a global security standard developed and maintained by the &lt;strong&gt;PCI Security Standards Council (PCI SSC)&lt;/strong&gt;, which was founded in 2006 by the five major payment card brands (Visa, Mastercard, American Express, Discover, JCB). The current version is &lt;strong&gt;PCI-DSS v4.0.1&lt;/strong&gt; (published June 2024, with mandatory compliance required from 31 March 2025 for all new requirements). PCI-DSS is &lt;strong&gt;not government legislation&lt;/strong&gt; but a contractual obligation — compliance is enforced through the agreements between merchants/service providers and their acquiring banks. Failure to comply results in fines (up to $100,000/month from card brands), increased transaction fees, and ultimately loss of the ability to process card payments. PCI-DSS applies to &lt;strong&gt;any organization worldwide&lt;/strong&gt; that stores, processes, or transmits cardholder data (CHD) or sensitive authentication data (SAD), regardless of size or transaction volume. The standard defines &lt;strong&gt;12 requirements&lt;/strong&gt; organized in 6 control objectives: build and maintain secure networks (firewalls, secure configurations), protect cardholder data (encryption, key management), maintain a vulnerability management program (patching, anti-malware), implement strong access controls (least privilege, MFA, physical access), regularly monitor and test networks (logging, penetration testing), and maintain an information security policy. Compliance is validated through either a &lt;strong&gt;Qualified Security Assessor (QSA)&lt;/strong&gt; on-site assessment (Level 1 merchants) or a &lt;strong&gt;Self-Assessment Questionnaire (SAQ)&lt;/strong&gt; for smaller entities.&lt;/p&gt;</description></item></channel></rss>