Registrations

PCI DSS Compliance

For merchants and fintechs handling card data: what PCI DSS v4.0.1 actually requires by level, how RBI’s payment-aggregator rules now fold it in, and what a consultant can (and can’t) do versus a QSA.

Why founders pick CapEasy

5.0★ across 335+ Google reviews

2,700+ founders served across India

Overview

The Payment Card Industry Data Security Standard binds anyone who stores, processes or transmits cardholder data — merchants and service providers alike. It is not enacted as Indian statute; you comply with it because Visa, Mastercard and RuPay write it into the contracts that let you accept their cards. The current version is PCI DSS v4.0.1, and requirements that were previously future-dated became fully enforceable on 31 March 2025 — if your controls still assume the older baseline, you are already behind.

For payment aggregators the picture changed in September 2025. RBI’s Master Direction on Regulation of Payment Aggregators explicitly folds PCI DSS into its own cybersecurity mandate, alongside data localisation and yearly CERT-In cyber audits. That framework, in force since the 2020/2021 PA-PG guidelines and reaffirmed in the 2025 direction, also bars merchants and aggregators from storing card numbers, CVVs or expiry dates outright — the answer is tokenisation, not a bigger vault.

Here is the part most pages selling this service will not say plainly: CapEasy does not certify anyone, and no consultant can. Only a PCI Security Standards Council-accredited Qualified Security Assessor company may perform the on-site assessment and sign the Report on Compliance for Level 1 merchants and most service providers. What a consultant legitimately does is gap assessment, remediation and control implementation, SAQ completion support, and getting your evidence and your team ready for the QSA to walk in — we do that work, not the sign-off.

PCI DSS is also not a badge you earn once. Validation runs annually: an ROC for Level 1, an SAQ for everyone else, plus quarterly external scans where they apply. Treat it as a recurring discipline, because that is what the card networks expect, and for aggregators, RBI now expects it too.

Who it’s for

  • Merchants accepting card payments online or in person who need to know their PCI level and what it obliges them to do
  • Payment aggregators and gateways operating under RBI’s PA-PG framework, where PCI DSS is now bundled into the cybersecurity mandate
  • SaaS and marketplace platforms that touch cardholder data directly rather than fully offloading it to a hosted checkout
  • Service providers (processors, gateways, hosting or infrastructure vendors) restricted to SAQ D regardless of size
  • Businesses facing a first QSA assessment who need their evidence, scope and controls in order before the audit starts

Eligibility & requirements

  • Merchant compliance level is set by annual card-transaction volume: Level 1 (over 6 million transactions/year), Level 2 (1–6 million), Level 3 (20,000–1 million e-commerce), Level 4 (under 20,000 e-commerce, or up to 1 million total)
  • Level 1 merchants need an annual on-site assessment producing a Report on Compliance; Levels 2–4 generally self-validate through a Self-Assessment Questionnaire plus quarterly ASV network scans
  • Service providers are restricted to SAQ D — the only SAQ option available to them, regardless of scale
  • Controls must meet PCI DSS v4.0.1; requirements future-dated under v4.0 became mandatory on 31 March 2025
  • No storage of card numbers, CVVs or expiry dates under RBI’s payment-aggregator framework — cardholder data has to move through tokenisation, not sit in your systems
  • For non-bank payment aggregators, RBI’s September 2025 Master Direction treats PCI DSS as part of a wider cybersecurity mandate alongside data localisation and annual CERT-In audits
  • The obligation is contractual, from card-network and acquiring-bank agreements, not a standalone Indian law

How CapEasy handles it

  1. Gap assessment against PCI DSS v4.0.1, mapped to your merchant or service-provider level
  2. Scope definition — identify every system that touches cardholder data, and where tokenisation or network segmentation can shrink that scope before anything else
  3. Prioritised remediation plan covering the gaps the assessment surfaces
  4. Control implementation — encryption, access control, logging and monitoring, and the vendor-management terms your processors and gateways need to carry the same obligations
  5. SAQ preparation and completion support, matched to the correct SAQ type for your level, including SAQ D for service providers
  6. QSA-readiness preparation for Level 1 merchants and providers who need the on-site assessment — evidence package, walkthroughs, and closing findings before the QSA arrives
  7. Coordination of quarterly ASV scans where required
  8. An annual re-validation cycle so compliance carries forward, not rebuilt from scratch

Documents you’ll typically need

  • A diagram of where cardholder data enters, moves through and exits your systems
  • A list of every system and vendor touching card data: gateway, POS, backend, hosting
  • Any prior SAQ or Report on Compliance, if you have been validated before
  • Existing security policies (information security, access control, incident response), if they exist
  • Acquiring bank and card-network merchant details relevant to your validation
  • Details of any tokenisation or card-vaulting already in place

CapEasy is a private consultancy and is not affiliated with any government authority. We help you assess eligibility and prepare and file your application; eligibility and approval depend on your specifics and the relevant department’s discretion.

Frequently asked

PCI DSS Compliance — questions founders ask

Not as a standalone Indian statute — it is contractually required by the card networks (Visa, Mastercard, RuPay) for anyone handling cardholder data here. For non-bank payment aggregators specifically, RBI’s September 2025 Master Direction on Regulation of Payment Aggregators folds PCI DSS into its own cybersecurity compliance mandate, alongside data localisation and yearly CERT-In audits, so it is now also a regulatory expectation for that category, not only a contract term.

No, and no consultant can. Only a PCI Security Standards Council-accredited Qualified Security Assessor company may perform the formal on-site assessment and sign the Report on Compliance for Level 1 merchants and most service providers. We do the gap assessment, the remediation work, SAQ completion support and QSA-readiness preparation — the assessment itself and the sign-off on it are the QSA’s alone, and no engagement with us changes that.

Merchant level is set by annual card-transaction volume: Level 1 is over 6 million transactions a year, Level 2 is 1–6 million, Level 3 is 20,000–1 million e-commerce transactions, and Level 4 is under 20,000 e-commerce or up to 1 million total. Level 1 needs an annual on-site QSA assessment and a Report on Compliance; Levels 2–4 generally self-validate with a Self-Assessment Questionnaire and quarterly ASV scans. Service providers, regardless of size, are restricted to SAQ D.

SAQ D is the Self-Assessment Questionnaire covering the full range of PCI DSS requirements, with no shortened path. It is the only SAQ option available to service providers — the lighter, more scoped SAQ types that some merchants qualify for are simply not available to a business that processes, stores or transmits cardholder data on behalf of others, whatever its own transaction volume looks like.

No. Under RBI’s payment-aggregator framework, in force since the 2020/2021 PA-PG guidelines and reaffirmed in the September 2025 Master Direction, merchants and aggregators are barred from storing card numbers, CVVs or expiry dates anywhere in their own systems. The intended route is tokenisation, which also tends to shrink how much of your environment falls inside PCI DSS scope in the first place — fewer systems touching real card data means less to assess and secure.

If you are a non-bank payment aggregator, yes — it explicitly names PCI DSS as part of a cybersecurity compliance mandate that also covers data localisation and yearly CERT-In cyber audits. Merchants who previously treated this purely as a card-network contract obligation now sit alongside a regulator that expects the same standard from aggregators specifically, which raises the bar on how seriously the gap has to be closed.

Your CapEasy experts

Connect with us

Talk to the people who handle this work every day — no call centre, no hand-offs.

Ayush Joshi

Ayush Joshi

Co-Founder

Ex-OYO and Tenaciousfly. 7+ years in business development, strategic acquisitions, financing and debt syndication.

Aditya Jain

Aditya Jain

Co-Founder

Ex-Bank of America. 4+ years in investment banking, EU & Indian compliances, ESG compliances, and project management.

Manav Raval

Virtual CFO & Tax Specialist

Section 80-IAC, tax planning and startup compliance. Previously at Toyota Motor Corporation and Jaguar Land Rover.

Book a free consultation.

An honest assessment of where you are and what comes next — no cost, no pressure, no inflated promises.