PCI Security Standards Council
PCI Security Standards Council is a global standards body that develops and maintains the PCI Data Security Standard and related payment-security frameworks, qualifying assessors and labs to enforce compliance across merchants, vendors, processors, and financial institutions in 60+ countries.
- Company typePrivate
- Founded2006
- HeadquartersWakefield, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What PCI Security Standards Council does
PCI Security Standards Council (PCI SSC) is a global, open standards body founded in 2006 and organized as a limited liability company headquartered in Wakefield, Massachusetts. It was established by American Express, Discover, JCB International, Mastercard and Visa to develop, evolve and enforce technical and operational standards that protect cardholder data across the payments ecosystem. The Council's functional role is to set the rulebook (PCI DSS and adjacent standards), qualify the people and labs that audit compliance, and convene the merchants, vendors, processors and financial institutions that must operate within that rulebook; it currently serves 700+ Participating Organizations across 60+ countries.
Its core product is a portfolio of standards and the qualification programs around them. The flagship, PCI DSS, is currently at v4.0.1 (published 2024) with future-dated requirements phasing in. Surrounding it are PTS POI and PTS HSM standards for hardware devices, P2PE for point-to-point encryption, MPoC for mobile payments on consumer devices (with CPoC and SPoC being sunset), Secure Software and Secure Software Lifecycle for payment applications, and 3DS standards. The business model is standards-governance-as-a-service: revenue comes from tiered Participating Organization membership dues (Associate, Principal, Affiliate), training and qualification of Internal Security Assessors, Qualified Security Assessors, Approved Scanning Vendors, PTS Labs and P2PE assessors, product listing and validation fees paid by vendors whose solutions are tested against the standards, and a community-meetings franchise (Global Community Meetings, regional meetings, the Payment Security Summit) that monetizes engagement. Distribution is community-led, relying on Regional Engagement Boards, Special Interest Groups, public comment periods and partner-led events rather than a traditional field sales motion.
The Council is a mature, 20-year-old institution that recently published its first Annual Report (2025), operates with a headcount in the 11-50 range, has no external funding and does not acquire other entities; it competes on governance authority and ecosystem breadth rather than technology differentiation. AI is treated by the Council as a topic to be addressed within its standards rather than as a product capability.
PCI Security Standards Council firmographics
Firmographics- Name
- PCI Security Standards Council
- Legal name
- PCI Security Standards Council, LLC
- Website
- https://pcisecuritystandards.org
- Company type
- Private
- Founded year
- 2006
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- PCI Security Standards Council is a global standards body that develops and maintains the PCI Data Security Standard and related payment-security frameworks, qualifying assessors and labs to enforce compliance across merchants, vendors, processors, and financial institutions in 60+ countries.
- Ownership category
- akta.pro rank
PCI Security Standards Council industry classification
Industry- Product category
- Payment Data Security Standards
- akta.pro primary industry
- POS Certification, Testing & Compliance (EMVCo, PCI PTS/PCI DSS) (FSAMADAL)
- akta.pro secondary industries
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC), POS Security, Encryption & Key Management (P2PE, HSM, Key Injection) (FSAMADAK)
Keywords
Where PCI Security Standards Council is headquartered
LocationHeadquarters
- HQ city
- Wakefield
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
PCI Security Standards Council business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Participating Organization Membership Fees: Annual membership fees for organizations participating in PCI SSC programs. Standard membership: $4,000/year; Tier 2 countries (upper-middle, lower-middle, low-income economies): $1,500/year. Principal PO tiers based on revenue: $50,000 (>$1B), $35,000 ($500M-$999M), $27,500 ($100M-$499M), $20,000 (<$100M).
- Training and Qualification Programs: Revenue from training programs including QSA training ($3,600 new, $2,200 requalification), ISA training ($4,000 non-PO, $2,000 PO), PCIP training ($2,750 non-PO, $1,700 PO), and various knowledge training courses. Additional exam retake fees and training class change fees.
- Assessor and Laboratory Qualification Fees: Fees for qualifying assessors and laboratories including QSA regional qualification fees (up to $29,000), PFI qualification fees (regional up to $20,000, global $40,000), and laboratory annual management fees ($18,000).
- Product and Solution Listing Fees: Fees for listing validated payment solutions including PTS device listing ($2,000), Secure Software listing ($3,300), 3DS SDK listing ($3,000), and solution submission fees for P2PE, MPoC, SPoC, CPoC programs.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Standard Participating Organization membership |
| Subscription | Annual | Principal Participating Organization (tiered by revenue) |
| Subscription | Pay-as-you-go | PCI Professional (PCIP) Training |
| Subscription | Pay-as-you-go | Qualified Security Assessor (QSA) Training |
| Subscription | Pay-as-you-go | Internal Security Assessor (ISA) Training |
| Per seat | Pay-as-you-go | PCI Awareness Training |
| Subscription | Pay-as-you-go | Knowledge Training Programs |
| One time/ perpetual license | Pay-as-you-go | QIR Training |
| Transaction based/ take rate | Pay-as-you-go | P2PE Program Fees |
| Transaction based/ take rate | Annual | MPoC Program |
Go-to-market motion1 record
Distribution channels6 records
Marketing channels9 records
PCI Security Standards Council product offering
Product offeringCore offering
PCI Security Standards Council develops, maintains, and promotes adoption of global payment data security standards (PCI DSS, P2PE, MPoC, SPoC, CPoC, PTS POI/HSM, Secure Software, 3DS, TSP). It operates a global standards body funded primarily through Participating Organization memberships, assessor and laboratory qualification programs, training and certification fees, and product/solution listing fees for validated payment technologies.
Product overview
PCI Security Standards Council operates as a standards development organization offering a comprehensive portfolio of payment security standards and training programs. The core offering consists of security standards including PCI DSS (the foundational data security standard), P2PE (point-to-point encryption), Secure Software and Secure SLC, and various payment terminal/device standards (PTS POI, PIN Security, Card Production). The Council also provides mobile payment standards (MPoC, CPoC, SPoC), 3D Secure standards (PCI 3DS Core and SDK), tokenization standards (TSP), and HSM security requirements. Supporting the standards are qualification programs that train and certify security assessors (QSA, PCIP, ISA, PFI, QPA, QIR, ASV, CPSA) and software assessors (Secure Software, Secure SLC). Knowledge Training programs help organizations understand assessment processes. The portfolio is complemented by community meetings, forums, the PCI Perspectives Blog, and the Coffee with the Council Podcast for ongoing industry engagement.
Differentiator
Problem solved
Functional benefit
Quantifiable outcome
- Only 14.3% of global organizations maintained full PCI DSS compliance at interim validation (2024 Payment Security Report)
- +2 more outcomes
Companies that use PCI Security Standards Council
Customer profileNamed customers3 records
Segments5 records
Ideal customer profiles5 records
PCI Security Standards Council technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
PCI Security Standards Council partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and flagship.
- Dreamplug Technologies Private Limited (CRED)coreDreamplug Technologies Private Limited, operating as CRED, has become a new Principal Participating Organization at PCI SSC. CRED is a members-only fintech platform offering credit card bill payments, lending, rent payments, and commerce experiences. As a Principal PO, CRED will collaborate on cloud-based payment security, tokenization, authentication mechanisms, fraud prevention, API security, and data protection best practices.
- SmartcomplycoreSmartcomply, a Nigerian-founded cybersecurity and compliance technology firm, has been admitted as an Associate Participating Organization of PCI SSC, becoming among the first companies in its category from Nigeria to participate in shaping international payment data security standards. The membership enables Smartcomply to contribute to global payment security standards while bringing African market insights—particularly on mobile money, instant payments, and cross-border systems—to the Council's forums.
- QNAflagshipQNA, a leader in the global events industry, partners with PCI SSC to organize the Payment Security Summit series. The summit is an invitation-only forum bringing together senior stakeholders from government, regulatory bodies, financial institutions, payment networks, fintech companies, and cybersecurity leaders. Following successful editions in Mumbai, Riyadh, Johannesburg, Cairo, and Dubai, the partnership expanded to include Sydney and Tokyo as new host cities.
- SecurePIIcoreSecurePII, a global software company specializing in data privacy and PCI compliance solutions, has joined PCI SSC as an Associate Participating Organization. The company will contribute its expertise in securing payment data in voice channels and large-scale communications environments, supporting the ongoing development of PCI Security Standards worldwide.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
PCI Security Standards Council competitors and assessment
Company assessmentDirect peers
- FIDO Alliance: FIDO Alliance develops open authentication standards (passkeys, FIDO2) that, like PCI SSC's 3DS Core and SDK, sit at the intersection of payments, identity, and security. Both are member-driven bodies whose standards become de facto industry requirements through adoption by payments and platform players.
- GlobalPlatform: GlobalPlatform is a standards body specifying architectures and management frameworks for secure elements, trusted execution environments, and secure chips. It is comparable to PCI SSC as a multi-stakeholder organization producing security and technology standards consumed by the payments and digital identity ecosystem.
- EMVCo: EMVCo is the global technical body that manages and evolves the EMV specifications for card-based payments. Like PCI SSC, it is a multi-stakeholder standards organization funded by major payment networks, with a directly analogous role in payment security and interoperability standards.
Broad incumbents
- Cloud Security Alliance (CSA): CSA is a broad, established security standards body (notably the Security, Trust & Assurance Registry and Cloud Controls Matrix) serving a wider remit than payments. It is comparable to PCI SSC as a community-driven standards organization with membership, training, and certification programs, though it operates across industries rather than payments-specific.
- Internet Security Alliance (ISA): ISA is a multi-sector trade association that develops cybersecurity frameworks, policy guidance, and standards used by both public and private sectors. It is comparable to PCI SSC in operating as an association-driven standards influencer, though its scope spans all industries rather than payments.
- ISO (International Organization for Standardization): ISO develops the 27000-series information security standards (e.g., ISO 27001) that PCI SSC aligns with. As the dominant international standards body, ISO is a broad incumbent comparable to PCI SSC in delivering globally adopted compliance frameworks, though operating at a much larger scale and across industries.
- NIST (National Institute of Standards and Technology): NIST publishes the Cybersecurity Framework, SP 800-53, and other security standards frequently referenced alongside PCI DSS. While a U.S. government body rather than industry consortium, it is a comparable authority shaping payment security practices and frequently cross-referenced by PCI SSC materials.
Others
- PCI Forensic Investigator (PFI) firms (e.g., Trustwave, Verizon): Trustwave and similar firms are qualified PFI / QSA organizations that operate inside the PCI SSC ecosystem rather than competing with it. They are comparable as adjacent ecosystem participants delivering compliance and forensic services under PCI SSC's standards and qualifications framework.
Regional players
- Smartcomply: Smartcomply is a Nigerian cybersecurity and compliance technology firm that recently joined PCI SSC as an Associate Participating Organization. It is comparable as a regional compliance and payment security vendor building African-market solutions aligned with PCI SSC standards, reflecting the Council's emerging-market expansion.
Emerging players
- PCI Pal: PCI Pal provides PCI-compliant payment security solutions, particularly for contact center and voice environments. It is comparable as a participant in the PCI compliance market that builds products to PCI SSC's P2PE and cardholder data protection standards, though it is a vendor rather than a standards body.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights6 records
Customer concentration
PCI Security Standards Council social profiles
Digital presencePCI Security Standards Council compliance and trust
Trust signalCompliance4 records
PCI Security Standards Council financial estimates
Financial estimateRevenue estimate
Valuation estimate
PCI Security Standards Council leadership team
Management profileNumber of profiles
PCI Security Standards Council funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
PCI Security Standards Council M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about PCI Security Standards Council
What does PCI Security Standards Council do?
PCI Security Standards Council develops, maintains, and promotes adoption of global payment data security standards (PCI DSS, P2PE, MPoC, SPoC, CPoC, PTS POI/HSM, Secure Software, 3DS, TSP). It operates a global standards body funded primarily through Participating Organization memberships, assessor and laboratory qualification programs, training and certification fees, and product/solution listing fees for validated payment technologies.
Is PCI Security Standards Council a public or private company?
PCI Security Standards Council is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was PCI Security Standards Council founded?
PCI Security Standards Council was founded in 2006. It employs 11 to 50 people.
Where is PCI Security Standards Council based?
PCI Security Standards Council is headquartered in Wakefield, United States, in the North America region.
How does PCI Security Standards Council make money?
Four revenue lines are on record. Participating Organization Membership Fees are the primary driver. The others are training and Qualification Programs, assessor and Laboratory Qualification Fees and product and Solution Listing Fees.
Who are PCI Security Standards Council's main competitors?
Direct peers on record are FIDO Alliance, GlobalPlatform and EMVCo. Broad incumbents are Cloud Security Alliance (CSA), Internet Security Alliance (ISA), ISO (International Organization for Standardization) and NIST (National Institute of Standards and Technology). PCI Forensic Investigator (PFI) firms (e.g., Trustwave, Verizon) is listed as an others. Smartcomply is listed as a regional player. PCI Pal is listed as an emerging player.
Does PCI Security Standards Council have an API?
No public API is recorded for PCI Security Standards Council.
What industry is PCI Security Standards Council in?
PCI Security Standards Council's product category is Payment Data Security Standards. Its primary akta.pro industry code is FSAMADAL, POS Certification, Testing & Compliance (EMVCo, PCI PTS/PCI DSS), with a secondary code of BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX).