Are you ready for PCI compliance?
Davey Winder takes a closer look at the financial transaction security standard and what you need to do to get certified.


The trouble is, according to Andy Gibbs, director of security and compliance at cloud computing provider Star, that many of the smaller level 4 companies (those handling fewer than 20,000 payment card transactions a year) have "complained that the acquirers and payment card industry have not communicated the requirements and deadline clearly enough". As a result, Gibbs believes there will be "thousands of smaller firms struggling to meet the 12 basic requirements of the standard".
This is particularly worrying as level 4 merchants suffering a security breach exposing customer credit card details will automatically be moved up to level 1 (the big boys category for more than six million transactions a year) making the PCI-DSS compliance process much more expensive.
Gibbs and others will say the answer is to outsource payment processing to a specialist platform provider which is already PCI-DSS compliant. Thatt's not bad advice to be honest, but is it too late in the day to get compliant yourself?
Not according to Barclaycards' Neira Jones who insists "it is never too late!".
Jones says Barclaycard always advises its customers:
*Do not treat PCI DSS as an IT project: it is a Change Programme and needs organisational commitment.
*Train staff at all levels (there will be various degrees of training).
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
*Understand how card payments are currently processed (people, process and technology).
*Embed an information security culture within your organisation early.
*If you don't need cardholder information, don't have it...
Davey is a three-decade veteran technology journalist specialising in cybersecurity and privacy matters and has been a Contributing Editor at PC Pro magazine since the first issue was published in 1994. He's also a Senior Contributor at Forbes, and co-founder of the Forbes Straight Talking Cyber video project that won the ‘Most Educational Content’ category at the 2021 European Cybersecurity Blogger Awards.
Davey has also picked up many other awards over the years, including the Security Serious ‘Cyber Writer of the Year’ title in 2020. As well as being the only three-time winner of the BT Security Journalist of the Year award (2006, 2008, 2010) Davey was also named BT Technology Journalist of the Year in 1996 for a forward-looking feature in PC Pro Magazine called ‘Threats to the Internet.’ In 2011 he was honoured with the Enigma Award for a lifetime contribution to IT security journalism which, thankfully, didn’t end his ongoing contributions - or his life for that matter.
You can follow Davey on Twitter @happygeek, or email him at davey@happygeek.com.
-
The race is on for Higher Ed to adapt: Equity in hyflex learning
Hyflex courses can improve student wellbeing and engagement, but only with meeting technology that leaves no one behind
-
Gen Z workers are keen on AI in the workplace – but they’re still skeptical about the hype
News Younger workers could lead the shift to AI, but only think it can can manage some tasks
-
Data sovereignty a growing priority for UK enterprises
News Many firms view data sovereignty as simply a compliance issue
-
Elevating compliance standards for MSPs in 2025
Industry Insights The security landscape is set to change significantly in the years to come with new regulations coming into effect next year, here's how the channel needs to adapt
-
How ready is your company for NIS2?
Supported Content The EU’s latest cybersecurity legislation raises the stakes for enterprises and IT leaders - and ensuring compliance can be a daunting task
-
Top data security trends
Whitepaper Must-have tools for your data security toolkit
-
Conquering technology risk in banking
Whitepaper Five ways leaders can transform technology risk into advantage
-
Advancing your risk management maturity
Whitepaper A roadmap to effective governance and increase resilience
-
When banking works, the world works
Whitepaper Five ways automated processes can drive revenue and growth across your bank
-
Automating digital resiliency in banking
Whitepaper Prioritize investment in solutions that mitigate a lack of digital resiliency when disruptions strike