<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "Is PCI DSS a regulation?"
title: "Is PCI DSS a Regulation"
seoTitle: "Is PCI DSS a Regulation? Compliance Explained"
summary: "PCI DSS is not a law or a government regulation. It is a contractual security standard maintained by the PCI Security Standards Council and enforced by the payment card brands through your acquiring bank. Non-compliance leads to fines, higher transaction fees, or loss of card processing rather than regulatory penalties. How you validate depends on a merchant or service provider level set by transaction volume."
publishedAt: "2026-08-18"
keywords:
  - "PCI DSS regulatory compliance"
  - "is PCI DSS a regulation"
  - "PCI DSS compliance"
  - "PCI compliance levels"
pillar: "Beyond SOC 2"
faqs:
  - question: "Is PCI DSS a legal requirement?"
    answer: "No. It is a contractual obligation you take on through your merchant agreement, maintained by the PCI Security Standards Council and enforced by the card brands via your acquiring bank. Some US states reference it in law, but the enforcement mechanism is commercial rather than regulatory."
  - question: "What happens if you are not PCI compliant?"
    answer: "Fines passed down from the card brands through your acquirer, increased transaction fees, mandatory forensic investigation after an incident, and in serious cases loss of the ability to process cards. Losing card processing is the consequence that actually ends businesses."
  - question: "How do you validate PCI DSS compliance?"
    answer: "By level, which is set by annual transaction volume. Level 1 merchants require a Report on Compliance from a Qualified Security Assessor. Levels 2 to 4 typically complete a Self-Assessment Questionnaire, with the specific SAQ type depending on how you handle card data."
---

## Is PCI DSS a regulation?

**No.** PCI DSS is a **contractual security standard**, not a law. It is maintained by the PCI Security Standards Council, founded by the major card brands, and enforced through your merchant agreement by your acquiring bank rather than by a regulator. Non-compliance produces fines, higher fees, or loss of card processing, not regulatory penalties. A few US states reference it in legislation, but the enforcement mechanism is commercial.

### How it differs from actual regulation

| | PCI DSS | HIPAA / GDPR |
|---|---|---|
| Source | Card brands via the PCI SSC | Legislation |
| Binds you through | Your merchant agreement | Law |
| Enforced by | Acquiring bank, card brands | HHS, data protection authorities |
| Penalty | Fines via acquirer, fee increases, loss of processing | Statutory penalties, enforcement actions |
| Opt out by | Not accepting cards | You cannot |

The practical difference: you can leave PCI DSS scope entirely by not handling card data, which is why so much of PCI advice is about **reducing scope** rather than meeting requirements. Redirecting payments to a hosted page from a compliant processor removes most of your environment from scope, and that is usually a better investment than hardening it.

## Validation depends on your level

Levels are set by annual transaction volume and differ slightly by card brand.

| Level | Roughly | Validation |
|---|---|---|
| 1 | Over 6 million transactions a year | Report on Compliance by a Qualified Security Assessor |
| 2 | 1 to 6 million | SAQ, sometimes a QSA depending on brand |
| 3 | 20,000 to 1 million ecommerce | Self-Assessment Questionnaire |
| 4 | Under 20,000 ecommerce | Self-Assessment Questionnaire |

Most startups are Level 4 and complete an SAQ. Which SAQ type applies depends on how card data flows: **SAQ A** for fully outsourced ecommerce is the shortest by a wide margin, which is another reason scope reduction pays.

## Where PCI overlaps what you already do

If you hold SOC 2 or ISO 27001, a meaningful share of PCI's twelve requirements is already covered: access control, encryption, logging, vulnerability management, and policy. What PCI adds that neither tests is **cardholder data environment segmentation** and requirements specific to card data storage and transmission.

## Honest scope note

Screenata supports SOC 2, HIPAA, ISO 27001, and ISO 42001. **PCI DSS is a Tier 1 framework on our price list but is not seeded as an enrollable framework today**, so treat this page as an explanation rather than a coverage claim. The underlying evidence overlaps substantially with a SOC 2 programme, which is the honest thing to say about the relationship.
