Screenata

Beyond SOC 2

Is PCI DSS a regulation?

August 18, 20262 min read

Is PCI DSS a regulation?

No. PCI DSS is a contractual security standard, not a law. It is maintained by the PCI Security Standards Council, founded by the major card brands, and enforced through your merchant agreement by your acquiring bank rather than by a regulator. Non-compliance produces fines, higher fees, or loss of card processing, not regulatory penalties. A few US states reference it in legislation, but the enforcement mechanism is commercial.

How it differs from actual regulation

PCI DSSHIPAA / GDPR
SourceCard brands via the PCI SSCLegislation
Binds you throughYour merchant agreementLaw
Enforced byAcquiring bank, card brandsHHS, data protection authorities
PenaltyFines via acquirer, fee increases, loss of processingStatutory penalties, enforcement actions
Opt out byNot accepting cardsYou cannot

The practical difference: you can leave PCI DSS scope entirely by not handling card data, which is why so much of PCI advice is about reducing scope rather than meeting requirements. Redirecting payments to a hosted page from a compliant processor removes most of your environment from scope, and that is usually a better investment than hardening it.

Validation depends on your level

Levels are set by annual transaction volume and differ slightly by card brand.

LevelRoughlyValidation
1Over 6 million transactions a yearReport on Compliance by a Qualified Security Assessor
21 to 6 millionSAQ, sometimes a QSA depending on brand
320,000 to 1 million ecommerceSelf-Assessment Questionnaire
4Under 20,000 ecommerceSelf-Assessment Questionnaire

Most startups are Level 4 and complete an SAQ. Which SAQ type applies depends on how card data flows: SAQ A for fully outsourced ecommerce is the shortest by a wide margin, which is another reason scope reduction pays.

Where PCI overlaps what you already do

If you hold SOC 2 or ISO 27001, a meaningful share of PCI's twelve requirements is already covered: access control, encryption, logging, vulnerability management, and policy. What PCI adds that neither tests is cardholder data environment segmentation and requirements specific to card data storage and transmission.

Honest scope note

Screenata supports SOC 2, HIPAA, ISO 27001, and ISO 42001. PCI DSS is a Tier 1 framework on our price list but is not seeded as an enrollable framework today, so treat this page as an explanation rather than a coverage claim. The underlying evidence overlaps substantially with a SOC 2 programme, which is the honest thing to say about the relationship.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.