ARM Innovations Logo
ARM Innovations
Indian Compliance Guide

What Is PCI DSS Compliance in India? A 2026 Guide

Let's Start With the Basics

PCI DSS is shorthand for Payment Card Industry Data Security Standard. It's the global framework that tells organisations exactly how to handle, store, and protect cardholder data. If you accept credit or debit cards as payment, this standard applies to you. No exceptions. No excuses.

In India, PCI DSS compliance isn't just about following global rules. It's about staying on the right side of Indian regulators. The Reserve Bank of India now expects PCI DSS compliance as a baseline requirement. Payment aggregators need to demonstrate compliance just to get their license. Acquirers demand it. Customers increasingly expect it.

And here's what changed recently. Since March 31, 2025, PCI DSS v4.0.1 has been the only version that counts. Full enforcement kicked in on that date. Stuff you could skip before? They're now required. Phishing-resistant authentication. Client-side script monitoring. Rigorous data handling protocols. These aren't suggestions anymore.

PCI DSS Compliance in India Guide

What Actually Is PCI DSS?

Think of PCI DSS as the rulebook for anyone who touches card data. Backed by the big card brands, it has 12 core requirements which break down into six core objectives: secure networks, cardholder data protection, vulnerability management, access controls, monitoring, and policy enforcement.

What the 12 Requirements Cover:

Network Security Controls
Secure System Configurations
Protection of Stored Card Data
Encryption of Data in Transit
Anti-Malware Protection
Secure Software Development
Restricted Access to Card Data
Authentication and MFA
Physical Security
Logging and Monitoring
Regular Testing & Scans
Information Security Policies

Why PCI DSS Compliance Matters in India

In India, multiple regulatory and industrial directives make PCI DSS mandatory for card payment processing entities:

1. RBI Payment Aggregator Guidelines

The RBI’s Payment Aggregator directives state that all PAs must conduct strict merchant due diligence and ensure that their merchants comply with PCI DSS standards. PAs need annual security audits by CERT-In empanelled auditors and must report security incidents immediately.

2. NPCI Requirements

The National Payments Corporation of India (NPCI) mandates all UPI, NACH, IMPS, RuPay, and FASTag participants to adhere to applicable PCI requirements, including quarterly scans and annual penetration tests.

3. Visa and Mastercard Mandates

Indian acquiring banks (SBI, HDFC, ICICI, etc.) are required to verify that their merchants process credit card data in compliance with the payment network levels.

Merchant Levels in India

Compliance validation dependencies are categorized into four levels based on annual transaction counts:

LevelAnnual TransactionsRequirement
Level 1> 6 million transactions per yearAnnual Report on Compliance (ROC) by QSA + Quarterly Approved Scanning Vendor (ASV) scans
Level 21 million to 6 million per yearAnnual Self-Assessment Questionnaire (SAQ) + Quarterly ASV scans
Level 320,000 to 1 million e-commerce per yearAnnual SAQ + Quarterly ASV scans
Level 4< 20,000 e-commerce or < 1 million totalAnnual SAQ only

The Cost of Non-Compliance

Fines start from $5,000 to $10,000 per month and escalate to $100,000 after 6 months. In India, violation of RBI’s 2025 guidelines triggers administrative penalties up to ₹1 crore under the Payment and Settlement Systems Act, 2007, alongside deactivated merchant integration channels and frozen settlements under PMLA.

Safeguarding payment channels protects brand equity and consumer trust.

What's Changed with PCI DSS v4.0.1?

The transition to v4.0.1 is the biggest shift in PCI DSS history, expanding validation focus from core servers to what happens inside the customer’s browser:

Client-Side Script Monitoring (6.4.3 & 11.6.1)

You are responsible for tracking, authorising, and monitoring every single script that runs on payment pages (e.g. Magecart script checks, CSP headers, Subresource Integrity hashes).

Targeted Risk Analysis (TRA)

Requirement 12.3.1 mandates formal Targeted Risk Assessments for any control that uses a variable implementation frequency.

Areav3.2.1 (Legacy)v4.0.1 (Current)
Script SecurityServer-side focus onlyClient-side script inventory, authorization, and monitoring required
AuthenticationMFA for admin access onlyPhishing-resistant MFA across all CDE access channels
Risk AssessmentAnnual risk evaluationTargeted Risk Analysis (TRA) for each flexible requirement
EncryptionTLS 1.1 acceptable in some contextsTLS 1.2 or higher is mandatory
MonitoringPeriodic log reviewsAutomated, real-time change detection and alerting

RBI and Indian Regulatory Alignment

RBI Payment Aggregator directions establish baseline compliance alignment for local transactions:

01

100% Data Localisation

All card data and payment processing trails must be stored on local servers within India.

02

24-Hour Purge Rule

No payment transaction data can be stored outside India; foreign server copies must be deleted within 24 hours.

03

Card-on-File Tokenisation

Merchants cannot store raw card credentials (PAN, CVV). They must utilize RBI-approved tokenisation.

04

Merchant Due Diligence

Strict verification checklists for boarding merchants, making sure they comply with target security controls.

What Indian Businesses Need to Do

Achieving compliance requires following a systematic process:

Step 01

Determine Your Level

Assess transaction volume to check whether you need QSA validation (ROC) or a self-assessment questionnaire (SAQ).

Step 02

Scope Your CDE

Identify every system, point of sale, database, cloud resource, or backup server that stores, processes, or transmits card data.

Step 03

Close the Gaps

Perform a gap analysis against v4.0.1. Implement firewalls, strong passwords, encryption, logging, and phishing-resistant MFA.

Step 04

Test and Document

Schedule quarterly ASV vulnerability scans, run annual penetration tests, and compile security diagrams/policies.

Step 05

Get Assessed

Undergo a formal audit from a Qualified Security Assessor (ROC/AOC) or fill out your specific SAQ questionnaire.

Step 06

Maintain Compliance

Avoid treated compliance as an annual sprint. Establish weekly script reviews, firewall updates, and log checks.

Common Challenges and DPDP Act Intersection

Compliance teams face complex operational issues. The Digital Personal Data Protection (DPDP) Act 2023 adds additional obligations:

Technical Challenges

  • Upgrading legacy databases and networks to support TLS 1.2 or higher.
  • Overcoming budget constraints for smaller merchants and startups.
  • Avoiding security gaps from human errors (poor server configuration).
  • Scaling CDE boundaries across complex fintech integrations.

DPDP Act 2023 Obligation Matches

  • PCI DSS compliance satisfies many technical data security safeguards.
  • Must appoint a Data Protection Officer (DPO) and report data leaks to DPD Board.
  • DPDP localisation rules affect multi-region cloud architectures.

How ARM Innovations Helps Indian Businesses

ARM Innovations is a CERT-In empanelled cybersecurity company with deep compliance expertise. They provide:

PCI DSS Gap Assessment

Comprehensive analysis of CDE environments to trace missing v4.0.1 controls before QSAs begin audits.

Implementation Services

Developer-friendly remediations with PoC evidence for vulnerabilities (not generic CVE listings).

QSA Onsite Audit Support

Complete advisory and verification from initial scoping to Attestation of Compliance (AOC) compilation.

Managed Compliance Calendars

Automated scan scheduling, log reviews, and continuous control tracking to maintain compliance.

Frequently Asked Questions

Conclusion

PCI DSS compliance in India is no longer optional. Between the global standard shifting to v4.0.1, RBI guidelines tightening, and customer expectations rising, businesses cannot afford to wait. Get your preparation right, keep your paperwork straight, and partner with a team that has deep compliance expertise to make compliance achievable.

ABOUT THE AUTHOR: ARM Innovations is a CERT-In empanelled cybersecurity company providing PCI DSS audit services, penetration testing, secure code review, and compliance services across 7 countries, including India. Their QSA-led team combines human intelligence with automated rigour to deliver depth that scanners can't match.

Related Resources

Continue your research with these relevant guides and services.

+91 99104 22411WhatsApp