Overview
The Payment Card Industry Data Security Standard binds anyone who stores, processes or transmits cardholder data — merchants and service providers alike. It is not enacted as Indian statute; you comply with it because Visa, Mastercard and RuPay write it into the contracts that let you accept their cards. The current version is PCI DSS v4.0.1, and requirements that were previously future-dated became fully enforceable on 31 March 2025 — if your controls still assume the older baseline, you are already behind.
For payment aggregators the picture changed in September 2025. RBI’s Master Direction on Regulation of Payment Aggregators explicitly folds PCI DSS into its own cybersecurity mandate, alongside data localisation and yearly CERT-In cyber audits. That framework, in force since the 2020/2021 PA-PG guidelines and reaffirmed in the 2025 direction, also bars merchants and aggregators from storing card numbers, CVVs or expiry dates outright — the answer is tokenisation, not a bigger vault.
Here is the part most pages selling this service will not say plainly: CapEasy does not certify anyone, and no consultant can. Only a PCI Security Standards Council-accredited Qualified Security Assessor company may perform the on-site assessment and sign the Report on Compliance for Level 1 merchants and most service providers. What a consultant legitimately does is gap assessment, remediation and control implementation, SAQ completion support, and getting your evidence and your team ready for the QSA to walk in — we do that work, not the sign-off.
PCI DSS is also not a badge you earn once. Validation runs annually: an ROC for Level 1, an SAQ for everyone else, plus quarterly external scans where they apply. Treat it as a recurring discipline, because that is what the card networks expect, and for aggregators, RBI now expects it too.
Who it’s for
- Merchants accepting card payments online or in person who need to know their PCI level and what it obliges them to do
- Payment aggregators and gateways operating under RBI’s PA-PG framework, where PCI DSS is now bundled into the cybersecurity mandate
- SaaS and marketplace platforms that touch cardholder data directly rather than fully offloading it to a hosted checkout
- Service providers (processors, gateways, hosting or infrastructure vendors) restricted to SAQ D regardless of size
- Businesses facing a first QSA assessment who need their evidence, scope and controls in order before the audit starts
Eligibility & requirements
- Merchant compliance level is set by annual card-transaction volume: Level 1 (over 6 million transactions/year), Level 2 (1–6 million), Level 3 (20,000–1 million e-commerce), Level 4 (under 20,000 e-commerce, or up to 1 million total)
- Level 1 merchants need an annual on-site assessment producing a Report on Compliance; Levels 2–4 generally self-validate through a Self-Assessment Questionnaire plus quarterly ASV network scans
- Service providers are restricted to SAQ D — the only SAQ option available to them, regardless of scale
- Controls must meet PCI DSS v4.0.1; requirements future-dated under v4.0 became mandatory on 31 March 2025
- No storage of card numbers, CVVs or expiry dates under RBI’s payment-aggregator framework — cardholder data has to move through tokenisation, not sit in your systems
- For non-bank payment aggregators, RBI’s September 2025 Master Direction treats PCI DSS as part of a wider cybersecurity mandate alongside data localisation and annual CERT-In audits
- The obligation is contractual, from card-network and acquiring-bank agreements, not a standalone Indian law
How CapEasy handles it
- Gap assessment against PCI DSS v4.0.1, mapped to your merchant or service-provider level
- Scope definition — identify every system that touches cardholder data, and where tokenisation or network segmentation can shrink that scope before anything else
- Prioritised remediation plan covering the gaps the assessment surfaces
- Control implementation — encryption, access control, logging and monitoring, and the vendor-management terms your processors and gateways need to carry the same obligations
- SAQ preparation and completion support, matched to the correct SAQ type for your level, including SAQ D for service providers
- QSA-readiness preparation for Level 1 merchants and providers who need the on-site assessment — evidence package, walkthroughs, and closing findings before the QSA arrives
- Coordination of quarterly ASV scans where required
- An annual re-validation cycle so compliance carries forward, not rebuilt from scratch
Documents you’ll typically need
- A diagram of where cardholder data enters, moves through and exits your systems
- A list of every system and vendor touching card data: gateway, POS, backend, hosting
- Any prior SAQ or Report on Compliance, if you have been validated before
- Existing security policies (information security, access control, incident response), if they exist
- Acquiring bank and card-network merchant details relevant to your validation
- Details of any tokenisation or card-vaulting already in place
CapEasy is a private consultancy and is not affiliated with any government authority. We help you assess eligibility and prepare and file your application; eligibility and approval depend on your specifics and the relevant department’s discretion.



