Beyond SOC 2
Is PCI DSS a regulation?
Is PCI DSS a regulation?
No. PCI DSS is a contractual security standard, not a law. It is maintained by the PCI Security Standards Council, founded by the major card brands, and enforced through your merchant agreement by your acquiring bank rather than by a regulator. Non-compliance produces fines, higher fees, or loss of card processing, not regulatory penalties. A few US states reference it in legislation, but the enforcement mechanism is commercial.
How it differs from actual regulation
| PCI DSS | HIPAA / GDPR | |
|---|---|---|
| Source | Card brands via the PCI SSC | Legislation |
| Binds you through | Your merchant agreement | Law |
| Enforced by | Acquiring bank, card brands | HHS, data protection authorities |
| Penalty | Fines via acquirer, fee increases, loss of processing | Statutory penalties, enforcement actions |
| Opt out by | Not accepting cards | You cannot |
The practical difference: you can leave PCI DSS scope entirely by not handling card data, which is why so much of PCI advice is about reducing scope rather than meeting requirements. Redirecting payments to a hosted page from a compliant processor removes most of your environment from scope, and that is usually a better investment than hardening it.
Validation depends on your level
Levels are set by annual transaction volume and differ slightly by card brand.
| Level | Roughly | Validation |
|---|---|---|
| 1 | Over 6 million transactions a year | Report on Compliance by a Qualified Security Assessor |
| 2 | 1 to 6 million | SAQ, sometimes a QSA depending on brand |
| 3 | 20,000 to 1 million ecommerce | Self-Assessment Questionnaire |
| 4 | Under 20,000 ecommerce | Self-Assessment Questionnaire |
Most startups are Level 4 and complete an SAQ. Which SAQ type applies depends on how card data flows: SAQ A for fully outsourced ecommerce is the shortest by a wide margin, which is another reason scope reduction pays.
Where PCI overlaps what you already do
If you hold SOC 2 or ISO 27001, a meaningful share of PCI's twelve requirements is already covered: access control, encryption, logging, vulnerability management, and policy. What PCI adds that neither tests is cardholder data environment segmentation and requirements specific to card data storage and transmission.
Honest scope note
Screenata supports SOC 2, HIPAA, ISO 27001, and ISO 42001. PCI DSS is a Tier 1 framework on our price list but is not seeded as an enrollable framework today, so treat this page as an explanation rather than a coverage claim. The underlying evidence overlaps substantially with a SOC 2 programme, which is the honest thing to say about the relationship.