Any entity that stores, transmits, or processes credit card data must be PCI DSS compliant. That means any company processing financial transactions should meet PCI DSS requirements. Even if your company employs a third-party vendor to process payments, you still need to secure data transmitted by your website.
PCI DSS requirements are a set of cybersecurity best practices and procedures that help to prevent data breaches and ensure the secure processing, storage, and transmission of cardholder data. No fully PCI DSS compliant organizations suffered a data breach from 2018 through 2020 according to Verizon’s 2022 Payment Security Report. The same report states that only 43.4% of organizations were compliant with PCI DSS in 2020.
PCI DSS compliance level
< % non compliant
According to the Verizon 2022 Payment Security Report