Developer docs
API playgroundTry for free, no card

Search company profiles

PCI Security Standards Council

Full company profile

uuid0006yac

Namestring
PCI Security Standards Council
Legal namestring
PCI Security Standards Council, LLC
Company typeenum
Private
Founded yearint
2006
Descriptiontext

PCI Security Standards Council (PCI SSC) is a global, open standards body founded in 2006 and organized as a limited liability company headquartered in Wakefield, Massachusetts. It was established by American Express, Discover, JCB International, Mastercard and Visa to develop, evolve and enforce technical and operational standards that protect cardholder data across the payments ecosystem. The Council's functional role is to set the rulebook (PCI DSS and adjacent standards), qualify the people and labs that audit compliance, and convene the merchants, vendors, processors and financial institutions that must operate within that rulebook; it currently serves 700+ Participating Organizations across 60+ countries.

Its core product is a portfolio of standards and the qualification programs around them. The flagship, PCI DSS, is currently at v4.0.1 (published 2024) with future-dated requirements phasing in. Surrounding it are PTS POI and PTS HSM standards for hardware devices, P2PE for point-to-point encryption, MPoC for mobile payments on consumer devices (with CPoC and SPoC being sunset), Secure Software and Secure Software Lifecycle for payment applications, and 3DS standards. The business model is standards-governance-as-a-service: revenue comes from tiered Participating Organization membership dues (Associate, Principal, Affiliate), training and qualification of Internal Security Assessors, Qualified Security Assessors, Approved Scanning Vendors, PTS Labs and P2PE assessors, product listing and validation fees paid by vendors whose solutions are tested against the standards, and a community-meetings franchise (Global Community Meetings, regional meetings, the Payment Security Summit) that monetizes engagement. Distribution is community-led, relying on Regional Engagement Boards, Special Interest Groups, public comment periods and partner-led events rather than a traditional field sales motion.

The Council is a mature, 20-year-old institution that recently published its first Annual Report (2025), operates with a headcount in the 11-50 range, has no external funding and does not acquire other entities; it competes on governance authority and ecosystem breadth rather than technology differentiation. AI is treated by the Council as a topic to be addressed within its standards rather than as a product capability.

Short descriptiontext

PCI Security Standards Council is a global standards body that develops and maintains the PCI Data Security Standard and related payment-security frameworks, qualifying assessors and labs to enforce compliance across merchants, vendors, processors, and financial institutions in 60+ countries.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
11–50
akta.pro rankint
HeadquartersWakefield, United States
HQ citystring
Wakefield
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
payment security standards, cardholder data protection, PCI compliance training, payment card industry, data security standards
Industry3 codes
1POS Certification, Testing & Compliance (EMVCo, PCI PTS/PCI DSS)
CodeFSAMADALPrimaryYes
2Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX)
CodeBPAKADACPrimaryNo
3POS Security, Encryption & Key Management (P2PE, HSM, Key Injection)
CodeFSAMADAKPrimaryNo
Product category
Payment Data Security Standards
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model4 records
1Participating Organization Membership Fees
TypeSubscription Recurring
Description

Annual membership fees for organizations participating in PCI SSC programs. Standard membership: $4,000/year; Tier 2 countries (upper-middle, lower-middle, low-income economies): $1,500/year. Principal PO tiers based on revenue: $50,000 (>$1B), $35,000 ($500M-$999M), $27,500 ($100M-$499M), $20,000 (<$100M).

pcisecuritystandards.org
2Training and Qualification Programs
TypeProfessional Services
Description

Revenue from training programs including QSA training ($3,600 new, $2,200 requalification), ISA training ($4,000 non-PO, $2,000 PO), PCIP training ($2,750 non-PO, $1,700 PO), and various knowledge training courses. Additional exam retake fees and training class change fees.

pcisecuritystandards.org
3Assessor and Laboratory Qualification Fees
TypeProfessional Services
Description

Fees for qualifying assessors and laboratories including QSA regional qualification fees (up to $29,000), PFI qualification fees (regional up to $20,000, global $40,000), and laboratory annual management fees ($18,000).

pcisecuritystandards.org
4Product and Solution Listing Fees
TypeLicensing Royalties
Description

Fees for listing validated payment solutions including PTS device listing ($2,000), Secure Software listing ($3,300), 3DS SDK listing ($3,000), and solution submission fees for P2PE, MPoC, SPoC, CPoC programs.

pcisecuritystandards.org
Marketing channels9 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels6 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Pricing details10 tiers
1Standard Participating Organization membership
ModelSubscriptionBilling cadenceAnnual
Notes

$4,000 USD annual renewal fee. New Member Fee also $4,000 USD. Reduced rate of $1,500 USD for organizations in Tier 2 countries (upper-middle, lower-middle, low-income economies per World Bank classification).

pcisecuritystandards.org
2Principal Participating Organization (tiered by revenue)
ModelSubscriptionBilling cadenceAnnual
Notes

Principal PO ($1B and Above): $50,000 USD; Principal PO ($500M - $999M): $35,000 USD; Principal PO ($100M - $499M): $27,500 USD; Principal PO (Under $100M): $20,000 USD.

pcisecuritystandards.org
3PCI Professional (PCIP) Training
ModelSubscriptionBilling cadencePay-as-you-go
Notes

New PCIP Training Non-PO: $2,750 USD; New PCIP Training Principal/Associate PO: $1,700 USD; Requalification Non-PO: $350 USD; Requalification PO: $300 USD. Special offer: $200 off PCIP in-person training classes.

pcisecuritystandards.org
4Qualified Security Assessor (QSA) Training
ModelSubscriptionBilling cadencePay-as-you-go
Notes

New QSA training: $3,600 USD; Requalification QSA training: $2,200 USD; Requalification QSA training (Japanese): $2,900 USD. Regional qualification fees range from $7,250 to $29,000 depending on region.

pcisecuritystandards.org
5Internal Security Assessor (ISA) Training
ModelSubscriptionBilling cadencePay-as-you-go
Notes

New ISA Training Non-PO: $4,000 USD; New ISA Training Principal/Associate PO: $2,000 USD; Requalification ISA Training Non-PO: $1,600 USD; Requalification ISA Training PO: $1,350 USD.

pcisecuritystandards.org
6PCI Awareness Training
ModelPer seatBilling cadencePay-as-you-go
Notes

eLearning 1-24 count: $600 USD per person; 25-99 count: $450 USD per person; 100+ count: $325 USD per person.

pcisecuritystandards.org
7Knowledge Training Programs
ModelSubscriptionBilling cadencePay-as-you-go
Notes

Knowledge 3DS/Physical: $700 USD PO, $1,000 USD Non-PO; Knowledge Card Logical/P2PE/QPA/Secure Software/Secure SLC: $1,200 USD PO, $1,500 USD Non-PO.

pcisecuritystandards.org
8QIR Training
ModelOne time/ perpetual licenseBilling cadencePay-as-you-go
Notes

New QIR training (eLearning only): $100 USD; Requalification QIR training: $100 USD.

pcisecuritystandards.org
9P2PE Program Fees
ModelTransaction based/ take rateBilling cadencePay-as-you-go
Notes

Solution P-ROV Submission: $6,500 USD (includes one Solution-specific P2PE Application) + $3,600 per additional; Component P-ROV Submission: $5,250 USD; Application P-ROV Submission: $3,600 USD per Application.

pcisecuritystandards.org
10MPoC Program
ModelTransaction based/ take rateBilling cadenceAnnual
Notes

Product Report Submission: $3,500 USD base + $250 USD per MPoC App; Annual Checkpoint: $1,000 USD base + $100 USD per MPoC App; Implementation Change: $550 USD.

pcisecuritystandards.org
GTM typeB2B
B2B
Offering typeServices
Services
Core offering1 text field

PCI Security Standards Council develops, maintains, and promotes adoption of global payment data security standards (PCI DSS, P2PE, MPoC, SPoC, CPoC, PTS POI/HSM, Secure Software, 3DS, TSP). It operates a global standards body funded primarily through Participating Organization memberships, assessor and laboratory qualification programs, training and certification fees, and product/solution listing fees for validated payment technologies.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 3 values shown
  • Only 14.3% of global organizations maintained full PCI DSS compliance at interim validation (2024 Payment Security Report)
+2 more records
Product overview1 text field

PCI Security Standards Council operates as a standards development organization offering a comprehensive portfolio of payment security standards and training programs. The core offering consists of security standards including PCI DSS (the foundational data security standard), P2PE (point-to-point encryption), Secure Software and Secure SLC, and various payment terminal/device standards (PTS POI, PIN Security, Card Production). The Council also provides mobile payment standards (MPoC, CPoC, SPoC), 3D Secure standards (PCI 3DS Core and SDK), tokenization standards (TSP), and HSM security requirements. Supporting the standards are qualification programs that train and certify security assessors (QSA, PCIP, ISA, PFI, QPA, QIR, ASV, CPSA) and software assessors (Secure Software, Secure SLC). Knowledge Training programs help organizations understand assessment processes. The portfolio is complemented by community meetings, forums, the PCI Perspectives Blog, and the Coffee with the Council Podcast for ongoing industry engagement.

Scale indicator4 records

Each record includes

Type, Value, Description, Source

Partnership4 partners
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-08
Description

Dreamplug Technologies Private Limited, operating as CRED, has become a new Principal Participating Organization at PCI SSC. CRED is a members-only fintech platform offering credit card bill payments, lending, rent payments, and commerce experiences. As a Principal PO, CRED will collaborate on cloud-based payment security, tokenization, authentication mechanisms, fraud prevention, API security, and data protection best practices.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-03
Description

Smartcomply, a Nigerian-founded cybersecurity and compliance technology firm, has been admitted as an Associate Participating Organization of PCI SSC, becoming among the first companies in its category from Nigeria to participate in shaping international payment data security standards. The membership enables Smartcomply to contribute to global payment security standards while bringing African market insights—particularly on mobile money, instant payments, and cross-border systems—to the Council's forums.

Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-01-29
Description

QNA, a leader in the global events industry, partners with PCI SSC to organize the Payment Security Summit series. The summit is an invitation-only forum bringing together senior stakeholders from government, regulatory bodies, financial institutions, payment networks, fintech companies, and cybersecurity leaders. Following successful editions in Mumbai, Riyadh, Johannesburg, Cairo, and Dubai, the partnership expanded to include Sydney and Tokyo as new host cities.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2025-12-16
Description

SecurePII, a global software company specializing in data privacy and PCI compliance solutions, has joined PCI SSC as an Associate Participating Organization. The company will contribute its expertise in securing payment data in voice channels and large-scale communications environments, supporting the ongoing development of PCI Security Standards worldwide.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight5 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

FIDO Alliance develops open authentication standards (passkeys, FIDO2) that, like PCI SSC's 3DS Core and SDK, sit at the intersection of payments, identity, and security. Both are member-driven bodies whose standards become de facto industry requirements through adoption by payments and platform players.

TypeDirect peer
Description

GlobalPlatform is a standards body specifying architectures and management frameworks for secure elements, trusted execution environments, and secure chips. It is comparable to PCI SSC as a multi-stakeholder organization producing security and technology standards consumed by the payments and digital identity ecosystem.

TypeBroad incumbent
Description

CSA is a broad, established security standards body (notably the Security, Trust & Assurance Registry and Cloud Controls Matrix) serving a wider remit than payments. It is comparable to PCI SSC as a community-driven standards organization with membership, training, and certification programs, though it operates across industries rather than payments-specific.

TypeBroad incumbent
Description

ISA is a multi-sector trade association that develops cybersecurity frameworks, policy guidance, and standards used by both public and private sectors. It is comparable to PCI SSC in operating as an association-driven standards influencer, though its scope spans all industries rather than payments.

TypeBroad incumbent
Description

ISO develops the 27000-series information security standards (e.g., ISO 27001) that PCI SSC aligns with. As the dominant international standards body, ISO is a broad incumbent comparable to PCI SSC in delivering globally adopted compliance frameworks, though operating at a much larger scale and across industries.

6PCI Forensic Investigator (PFI) firms (e.g., Trustwave, Verizon)
TypeOthers
Description

Trustwave and similar firms are qualified PFI / QSA organizations that operate inside the PCI SSC ecosystem rather than competing with it. They are comparable as adjacent ecosystem participants delivering compliance and forensic services under PCI SSC's standards and qualifications framework.

TypeRegional player
Description

Smartcomply is a Nigerian cybersecurity and compliance technology firm that recently joined PCI SSC as an Associate Participating Organization. It is comparable as a regional compliance and payment security vendor building African-market solutions aligned with PCI SSC standards, reflecting the Council's emerging-market expansion.

TypeBroad incumbent
Description

NIST publishes the Cybersecurity Framework, SP 800-53, and other security standards frequently referenced alongside PCI DSS. While a U.S. government body rather than industry consortium, it is a comparable authority shaping payment security practices and frequently cross-referenced by PCI SSC materials.

TypeDirect peer
Description

EMVCo is the global technical body that manages and evolves the EMV specifications for card-based payments. Like PCI SSC, it is a multi-stakeholder standards organization funded by major payment networks, with a directly analogous role in payment security and interoperability standards.

TypeEmerging player
Description

PCI Pal provides PCI-compliant payment security solutions, particularly for contact center and voice environments. It is comparable as a participant in the PCI compliance market that builds products to PCI SSC's P2PE and cardholder data protection standards, though it is a vendor rather than a standards body.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers3 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment5 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile5 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature6 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
No data
Compliance4 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

PCI Security Standards Council

Payment Data Security Standardspcisecuritystandards.org

PCI Security Standards Council is a global standards body that develops and maintains the PCI Data Security Standard and related payment-security frameworks, qualifying assessors and labs to enforce compliance across merchants, vendors, processors, and financial institutions in 60+ countries.

What PCI Security Standards Council does

PCI Security Standards Council (PCI SSC) is a global, open standards body founded in 2006 and organized as a limited liability company headquartered in Wakefield, Massachusetts. It was established by American Express, Discover, JCB International, Mastercard and Visa to develop, evolve and enforce technical and operational standards that protect cardholder data across the payments ecosystem. The Council's functional role is to set the rulebook (PCI DSS and adjacent standards), qualify the people and labs that audit compliance, and convene the merchants, vendors, processors and financial institutions that must operate within that rulebook; it currently serves 700+ Participating Organizations across 60+ countries.

Its core product is a portfolio of standards and the qualification programs around them. The flagship, PCI DSS, is currently at v4.0.1 (published 2024) with future-dated requirements phasing in. Surrounding it are PTS POI and PTS HSM standards for hardware devices, P2PE for point-to-point encryption, MPoC for mobile payments on consumer devices (with CPoC and SPoC being sunset), Secure Software and Secure Software Lifecycle for payment applications, and 3DS standards. The business model is standards-governance-as-a-service: revenue comes from tiered Participating Organization membership dues (Associate, Principal, Affiliate), training and qualification of Internal Security Assessors, Qualified Security Assessors, Approved Scanning Vendors, PTS Labs and P2PE assessors, product listing and validation fees paid by vendors whose solutions are tested against the standards, and a community-meetings franchise (Global Community Meetings, regional meetings, the Payment Security Summit) that monetizes engagement. Distribution is community-led, relying on Regional Engagement Boards, Special Interest Groups, public comment periods and partner-led events rather than a traditional field sales motion.

The Council is a mature, 20-year-old institution that recently published its first Annual Report (2025), operates with a headcount in the 11-50 range, has no external funding and does not acquire other entities; it competes on governance authority and ecosystem breadth rather than technology differentiation. AI is treated by the Council as a topic to be addressed within its standards rather than as a product capability.

PCI Security Standards Council firmographics

Firmographics
Name
PCI Security Standards Council
Legal name
PCI Security Standards Council, LLC
Website
https://pcisecuritystandards.org
Company type
Private
Founded year
2006
Operating status
Operating
Headcount range
11–50 employees
Short description
PCI Security Standards Council is a global standards body that develops and maintains the PCI Data Security Standard and related payment-security frameworks, qualifying assessors and labs to enforce compliance across merchants, vendors, processors, and financial institutions in 60+ countries.
Ownership category
akta.pro rank

PCI Security Standards Council industry classification

Industry
Product category
Payment Data Security Standards
akta.pro primary industry
POS Certification, Testing & Compliance (EMVCo, PCI PTS/PCI DSS) (FSAMADAL)
akta.pro secondary industries
Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC), POS Security, Encryption & Key Management (P2PE, HSM, Key Injection) (FSAMADAK)

Keywords

  • Payment security standards
  • Cardholder data protection
  • PCI compliance training
  • Payment card industry
  • Data security standards

Where PCI Security Standards Council is headquartered

Location

Headquarters

HQ city
Wakefield
HQ country
United States
HQ region
North America

Offices1 record

Markets served

PCI Security Standards Council business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure

Revenue model

  1. Participating Organization Membership Fees: Annual membership fees for organizations participating in PCI SSC programs. Standard membership: $4,000/year; Tier 2 countries (upper-middle, lower-middle, low-income economies): $1,500/year. Principal PO tiers based on revenue: $50,000 (>$1B), $35,000 ($500M-$999M), $27,500 ($100M-$499M), $20,000 (<$100M).
  2. Training and Qualification Programs: Revenue from training programs including QSA training ($3,600 new, $2,200 requalification), ISA training ($4,000 non-PO, $2,000 PO), PCIP training ($2,750 non-PO, $1,700 PO), and various knowledge training courses. Additional exam retake fees and training class change fees.
  3. Assessor and Laboratory Qualification Fees: Fees for qualifying assessors and laboratories including QSA regional qualification fees (up to $29,000), PFI qualification fees (regional up to $20,000, global $40,000), and laboratory annual management fees ($18,000).
  4. Product and Solution Listing Fees: Fees for listing validated payment solutions including PTS device listing ($2,000), Secure Software listing ($3,300), 3DS SDK listing ($3,000), and solution submission fees for P2PE, MPoC, SPoC, CPoC programs.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualStandard Participating Organization membership
SubscriptionAnnualPrincipal Participating Organization (tiered by revenue)
SubscriptionPay-as-you-goPCI Professional (PCIP) Training
SubscriptionPay-as-you-goQualified Security Assessor (QSA) Training
SubscriptionPay-as-you-goInternal Security Assessor (ISA) Training
Per seatPay-as-you-goPCI Awareness Training
SubscriptionPay-as-you-goKnowledge Training Programs
One time/ perpetual licensePay-as-you-goQIR Training
Transaction based/ take ratePay-as-you-goP2PE Program Fees
Transaction based/ take rateAnnualMPoC Program

Go-to-market motion1 record

Distribution channels6 records

Marketing channels9 records

PCI Security Standards Council product offering

Product offering

Core offering

PCI Security Standards Council develops, maintains, and promotes adoption of global payment data security standards (PCI DSS, P2PE, MPoC, SPoC, CPoC, PTS POI/HSM, Secure Software, 3DS, TSP). It operates a global standards body funded primarily through Participating Organization memberships, assessor and laboratory qualification programs, training and certification fees, and product/solution listing fees for validated payment technologies.

Product overview

PCI Security Standards Council operates as a standards development organization offering a comprehensive portfolio of payment security standards and training programs. The core offering consists of security standards including PCI DSS (the foundational data security standard), P2PE (point-to-point encryption), Secure Software and Secure SLC, and various payment terminal/device standards (PTS POI, PIN Security, Card Production). The Council also provides mobile payment standards (MPoC, CPoC, SPoC), 3D Secure standards (PCI 3DS Core and SDK), tokenization standards (TSP), and HSM security requirements. Supporting the standards are qualification programs that train and certify security assessors (QSA, PCIP, ISA, PFI, QPA, QIR, ASV, CPSA) and software assessors (Secure Software, Secure SLC). Knowledge Training programs help organizations understand assessment processes. The portfolio is complemented by community meetings, forums, the PCI Perspectives Blog, and the Coffee with the Council Podcast for ongoing industry engagement.

Differentiator

Problem solved

Functional benefit

Quantifiable outcome

  • Only 14.3% of global organizations maintained full PCI DSS compliance at interim validation (2024 Payment Security Report)
  • +2 more outcomes

Companies that use PCI Security Standards Council

Customer profile

Named customers3 records

Segments5 records

Ideal customer profiles5 records

PCI Security Standards Council technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature6 records

PCI Security Standards Council partnerships and signals

Strategic signal

Partnerships

Four partnerships are on record, tiered core and flagship.

  • Dreamplug Technologies Private Limited (CRED)coreStrategic or Co-development Partner · 8 June 2026Dreamplug Technologies Private Limited, operating as CRED, has become a new Principal Participating Organization at PCI SSC. CRED is a members-only fintech platform offering credit card bill payments, lending, rent payments, and commerce experiences. As a Principal PO, CRED will collaborate on cloud-based payment security, tokenization, authentication mechanisms, fraud prevention, API security, and data protection best practices.
  • SmartcomplycoreStrategic or Co-development Partner · 3 June 2026Smartcomply, a Nigerian-founded cybersecurity and compliance technology firm, has been admitted as an Associate Participating Organization of PCI SSC, becoming among the first companies in its category from Nigeria to participate in shaping international payment data security standards. The membership enables Smartcomply to contribute to global payment security standards while bringing African market insights—particularly on mobile money, instant payments, and cross-border systems—to the Council's forums.
  • QNAflagshipStrategic or Co-development Partner · 29 January 2026QNA, a leader in the global events industry, partners with PCI SSC to organize the Payment Security Summit series. The summit is an invitation-only forum bringing together senior stakeholders from government, regulatory bodies, financial institutions, payment networks, fintech companies, and cybersecurity leaders. Following successful editions in Mumbai, Riyadh, Johannesburg, Cairo, and Dubai, the partnership expanded to include Sydney and Tokyo as new host cities.
  • SecurePIIcoreStrategic or Co-development Partner · 16 December 2025SecurePII, a global software company specializing in data privacy and PCI compliance solutions, has joined PCI SSC as an Associate Participating Organization. The company will contribute its expertise in securing payment data in voice channels and large-scale communications environments, supporting the ongoing development of PCI Security Standards worldwide.

Scale indicators4 records

Recent moves6 records

Expansion highlights5 records

PCI Security Standards Council competitors and assessment

Company assessment

Direct peers

  • FIDO Alliance: FIDO Alliance develops open authentication standards (passkeys, FIDO2) that, like PCI SSC's 3DS Core and SDK, sit at the intersection of payments, identity, and security. Both are member-driven bodies whose standards become de facto industry requirements through adoption by payments and platform players.
  • GlobalPlatform: GlobalPlatform is a standards body specifying architectures and management frameworks for secure elements, trusted execution environments, and secure chips. It is comparable to PCI SSC as a multi-stakeholder organization producing security and technology standards consumed by the payments and digital identity ecosystem.
  • EMVCo: EMVCo is the global technical body that manages and evolves the EMV specifications for card-based payments. Like PCI SSC, it is a multi-stakeholder standards organization funded by major payment networks, with a directly analogous role in payment security and interoperability standards.

Broad incumbents

  • Cloud Security Alliance (CSA): CSA is a broad, established security standards body (notably the Security, Trust & Assurance Registry and Cloud Controls Matrix) serving a wider remit than payments. It is comparable to PCI SSC as a community-driven standards organization with membership, training, and certification programs, though it operates across industries rather than payments-specific.
  • Internet Security Alliance (ISA): ISA is a multi-sector trade association that develops cybersecurity frameworks, policy guidance, and standards used by both public and private sectors. It is comparable to PCI SSC in operating as an association-driven standards influencer, though its scope spans all industries rather than payments.
  • ISO (International Organization for Standardization): ISO develops the 27000-series information security standards (e.g., ISO 27001) that PCI SSC aligns with. As the dominant international standards body, ISO is a broad incumbent comparable to PCI SSC in delivering globally adopted compliance frameworks, though operating at a much larger scale and across industries.
  • NIST (National Institute of Standards and Technology): NIST publishes the Cybersecurity Framework, SP 800-53, and other security standards frequently referenced alongside PCI DSS. While a U.S. government body rather than industry consortium, it is a comparable authority shaping payment security practices and frequently cross-referenced by PCI SSC materials.

Others

  • PCI Forensic Investigator (PFI) firms (e.g., Trustwave, Verizon): Trustwave and similar firms are qualified PFI / QSA organizations that operate inside the PCI SSC ecosystem rather than competing with it. They are comparable as adjacent ecosystem participants delivering compliance and forensic services under PCI SSC's standards and qualifications framework.

Regional players

  • Smartcomply: Smartcomply is a Nigerian cybersecurity and compliance technology firm that recently joined PCI SSC as an Associate Participating Organization. It is comparable as a regional compliance and payment security vendor building African-market solutions aligned with PCI SSC standards, reflecting the Council's emerging-market expansion.

Emerging players

  • PCI Pal: PCI Pal provides PCI-compliant payment security solutions, particularly for contact center and voice environments. It is comparable as a participant in the PCI compliance market that builds products to PCI SSC's P2PE and cardholder data protection standards, though it is a vendor rather than a standards body.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat6 records

Key risks5 records

Key highlights6 records

Customer concentration

PCI Security Standards Council social profiles

Digital presence

PCI Security Standards Council compliance and trust

Trust signal

Compliance4 records

PCI Security Standards Council financial estimates

Financial estimate

Revenue estimate

Valuation estimate

PCI Security Standards Council leadership team

Management profile

Number of profiles

PCI Security Standards Council funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

PCI Security Standards Council M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about PCI Security Standards Council

What does PCI Security Standards Council do?

PCI Security Standards Council develops, maintains, and promotes adoption of global payment data security standards (PCI DSS, P2PE, MPoC, SPoC, CPoC, PTS POI/HSM, Secure Software, 3DS, TSP). It operates a global standards body funded primarily through Participating Organization memberships, assessor and laboratory qualification programs, training and certification fees, and product/solution listing fees for validated payment technologies.

Is PCI Security Standards Council a public or private company?

PCI Security Standards Council is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was PCI Security Standards Council founded?

PCI Security Standards Council was founded in 2006. It employs 11 to 50 people.

Where is PCI Security Standards Council based?

PCI Security Standards Council is headquartered in Wakefield, United States, in the North America region.

How does PCI Security Standards Council make money?

Four revenue lines are on record. Participating Organization Membership Fees are the primary driver. The others are training and Qualification Programs, assessor and Laboratory Qualification Fees and product and Solution Listing Fees.

Who are PCI Security Standards Council's main competitors?

Direct peers on record are FIDO Alliance, GlobalPlatform and EMVCo. Broad incumbents are Cloud Security Alliance (CSA), Internet Security Alliance (ISA), ISO (International Organization for Standardization) and NIST (National Institute of Standards and Technology). PCI Forensic Investigator (PFI) firms (e.g., Trustwave, Verizon) is listed as an others. Smartcomply is listed as a regional player. PCI Pal is listed as an emerging player.

Does PCI Security Standards Council have an API?

No public API is recorded for PCI Security Standards Council.

What industry is PCI Security Standards Council in?

PCI Security Standards Council's product category is Payment Data Security Standards. Its primary akta.pro industry code is FSAMADAL, POS Certification, Testing & Compliance (EMVCo, PCI PTS/PCI DSS), with a secondary code of BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX).

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
HackerNoonSecurityMetrics Contributes to GEAR, Shares AI Solutions at the PCI SSC NA 2026 Community MeetingSecurityMetrics will contribute to PCI SSC's GEAR at the North America and Europe 2026 Community Meetings. The company will present a tech talk on monitoring lessons learned and showcase its Spectre AI solution. It has over 26 years of data security experience and has tested over 100 million systems.FinancialContent Business PageSecurityMetrics Contributes to GEAR, Shares AI Solutions at the PCI SSC NA 2026 Community MeetingSecurityMetrics will contribute to GEAR and present AI solutions at the PCI SSC North America and Europe 2026 Community Meetings. The company, a PCI certified ASV and QSA, will also host a tech talk on monitoring lessons learned. It aims to share technologies beyond PCI compliance, including its Spectre AI solution.ArabnewsThe AI race to secure Saudi Arabia’s payment boomPCI Security Standards Council's regional director Nitin Bhatnagar discussed Saudi Arabia's expanding digital payments and security challenges at LEAP 2026. He noted e-payments accounted for 85% of retail payments in 2025 and urged a shift to continuous security. He also advised consumers to keep personal data separate from work devices and avoid public Wi-Fi.CfotechPCI council marks 20 years with AI focus in Kuala LumpurThe PCI Security Standards Council is holding its Asia-Pacific Community Meeting in Kuala Lumpur to mark its 20th anniversary, focusing on the impact of artificial intelligence on payment security and fraud risks. The event will convene industry stakeholders to discuss how AI reshapes cardholder data protection, automated governance, and trust within interconnected payment ecosystems.SecurityBrief AustraliaPCI council marks 20 years with AI focus in Kuala LumpurThe PCI Security Standards Council is holding its Asia-Pacific Community Meeting in Kuala Lumpur to mark its 20th anniversary, focusing on how artificial intelligence impacts payment security and cardholder data risks. The event brings together industry stakeholders to discuss autonomous systems, fraud detection challenges, and automated governance tools amidst rising cybercrime concerns. A regional case study on India will explore national approaches to strengthening resilience against these evolving threats.BusinessLineCrossbow Enterprise Cybersecurity Secures Third Consecutive PCI SSC GEAR Term (2026–2028), Bringing Nearly 12 Years of Expertise to Global Payment SecurityCrossbow Enterprise Cybersecurity has been selected for the PCI Security Standards Council's 2026–2028 Global Executive Assessor Roundtable (GEAR), marking its third consecutive term on this global payment security forum. The company joins 32 other organizations as a strategic partner to provide industry and technical insight to PCI SSC plans, leveraging nearly 12 years of experience in cybersecurity and compliance.Indian Economic ObserverCrossbow Enterprise Cybersecurity Secures Third Consecutive PCI SSC GEAR Term (2026-2028), Bringing Nearly 12 Years of Expertise to Global Payment SecurityCrossbow Enterprise Cybersecurity has been selected for the PCI Security Standards Council's 2026-2028 Global Executive Assessor Roundtable (GEAR), marking its third consecutive term on this global payment security forum. The company joins 32 other organizations as a strategic partner to provide industry and technical insight to PCI SSC plans and projects. This appointment highlights Crossbow's role in bridging evolving payment technologies with global compliance standards.The HinduCrossbow Enterprise Cybersecurity Secures Third Consecutive PCI SSC GEAR Term (2026–2028), Bringing Nearly 12 Years of Expertise to Global Payment SecurityCrossbow Enterprise Cybersecurity has been selected for the PCI Security Standards Council's 2026–2028 Global Executive Assessor Roundtable (GEAR), marking its third consecutive term on the forum. The company joins 32 other organizations to provide industry and technical insight to PCI SSC plans, leveraging nearly 12 years of experience in payment security and compliance.Ani NewsCrossbow Enterprise Cybersecurity Secures Third Consecutive PCI SSC GEAR Term (2026-2028), Bringing Nearly 12 Years of Expertise to Global Payment SecurityCrossbow Enterprise Cybersecurity has been selected for its third consecutive term on the PCI Security Standards Council's 2026-2028 Global Executive Assessor Roundtable (GEAR). As one of 33 selected organizations, Crossbow will provide industry and technical insight to guide PCI SSC plans and projects on behalf of the assessor community.FinancialContent Business PageCrossbow Enterprise Cybersecurity Secures Third Consecutive PCI SSC GEAR Term (2026–2028), Bringing Nearly 12 Years of Expertise to Global Payment SecurityCrossbow Enterprise Cybersecurity has been selected for a third consecutive term on the PCI Security Standards Council’s Global Executive Assessor Roundtable (GEAR) for the 2026–2028 period. This appointment places Crossbow among 33 global assessor organizations collaborating with PCI SSC leadership to guide the evolution of payment security standards.