The encyclopedia · Software & IT · Strategic decision · 2004–2006
Card brands merged their security rules into PCI DSS, one rulebook every merchant followed
Visa and MasterCard's separate programs became PCI DSS in December 2004, the first unified standard all brands required; the PCI Council followed in 2006.
Visa · MasterCard · American Express · Discover · JCB
The solution
By the early 2000s each card brand ran its own data-security program, so merchants faced overlapping requirements — and cardholder data was still being stored carelessly. In the 2005-06 period, breaches from unnecessary cardholder-data storage, default passwords and weak network security were common.
The card brands' answer was to merge their programs: PCI DSS was created by aligning Visa's Account Information Security and Cardholder Information Security programs with MasterCard's Site Data Protection, and introduced in December 2004 as the first unified payments security standard approved and required by all the major brands.
Widespread adoption only took root after the PCI Security Standards Council was formed in 2006 by Visa, MasterCard, American Express, Discover and JCB. The Council maintains the standard, and Qualified Security Assessors and Approved Scanning Vendors test compliance, so the whole payment chain — merchants, processors and vendors — operates under one rulebook.
Why it worked
- One standard replaced five overlapping brand programs
- Compliance became a condition of doing card business
- Certified assessors made verification uniform and credible
- A shared rulebook cut compliance costs for everyone assessed
What can be applied
When every gatekeeper enforces its own rules, suppliers pay five times; a coalition that consolidates rules into one standard cuts cost and makes compliance unavoidable.
Aftermath
PCI DSS has been updated through versions 3.x and 4.0, with 4.0.1 becoming the sole active version in January 2025. It remains the mandatory baseline for any entity that stores, processes or transmits cardholder data, and has spawned related standards for PIN security and software security.
Sources
spotted an error? The archive wants to know.