PCI DSS

Also called PCI, Payment Card Industry Data Security Standard

ComposedNot built

PCI DSS is the security standard the card networks impose on anyone who touches card data. It is enforced by contract through acquiring banks rather than by a regulator, which is why it behaves differently from a law.

Scope is the whole game

The standard applies where cardholder data is stored, processed or transmitted. Almost every serious PCI strategy is a scope-reduction strategy: tokenise early, push the card into a hosted field, and keep the number out of your own systems. The cheapest compliant architecture is the one where the requirement barely applies.

Why an identity product should want to stay out

An identity system already handles the most sensitive category of data it will ever see. Adding card data widens the blast radius of any breach and adds an annual assessment cycle with no benefit to the verification product itself. Payments can be composed from a licensed provider who already carries that burden.

Where Solidus stands

Out of scope, deliberately, and that is a design decision rather than a gap. The honest phrasing is "we do not handle card data", never "we are PCI compliant", which would claim an assessment that does not exist.

Where it comes from

Someone else specified this. Solidus assembles it.

Maintained by the PCI Security Standards Council, founded by the card networks. Version 4.0.1 was published in July 2024; v3.2.1 retired on 31 March 2024, and the future-dated v4 requirements became mandatory on 31 March 2025. It is contractual rather than statutory: enforcement runs through acquirer agreements, not a regulator.

How to check this

Solidus has not built this. The entry explains the concept.

Scope is the checkable thing: PCI applies where cardholder data is stored, processed or transmitted. Solidus verification flows carry identity documents and credentials, not card numbers, so the honest claim is about scope rather than compliance.

Related

PCI DSS · Solidus Lexicon