Get Demo
↑

PCI DSS 12 Requirements Explained for Saudi Merchants

A complete guide to the 12 PCI DSS requirements for Saudi organizations, covering each requirement with practical KSA implementation notes, local.

📅 Published: June 2026 🔐 Compliance • PCI DSS ⏱️ 11–14 min read

PCI DSS compliance is mandatory for any organization that stores, processes, or transmits cardholder data, and the framework is built on 12 core requirements that cover everything from network security to access control. For Saudi merchants and financial institutions—especially those regulated by SAMA or operating within the Kingdom's expanding fintech sector—understanding each of the PCI DSS compliance 12 requirements is the first step toward achieving and maintaining compliance. This guide provides a full PCI requirements explained breakdown, with practical PCI compliance KSA implementation notes for each requirement on the PCI control list.

The Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 consists of 12 requirements organized into six goals. While the standard applies globally, Saudi organizations face unique considerations. Aligning PCI DSS with local frameworks like the NCA ECC, SAMA CSF, and PDPL is not just a best practice—it is increasingly expected by regulators and acquiring banks in the Kingdom. Whether you are a Tier 1 merchant, a payment gateway, or a third-party service provider, this PCI DSS 12 requirements explained guide will give you a clear roadmap.

Overview of the 12 PCI DSS Requirements

The 12 requirements are grouped into six goals that form a complete security lifecycle: build and maintain a secure network, protect cardholder data, maintain a vulnerability management program, implement strong access control, monitor and test networks, and maintain an information security policy. Each requirement contains multiple sub-requirements that scale in rigor depending on your organization's transaction volume and risk profile.

Saudi merchants should note that the Saudi Central Bank (SAMA) references PCI DSS within its SAMA CSF for licensed financial institutions. This means that PCI compliance in the Kingdom is not solely a card brand mandate—it is also a regulatory expectation. The following section breaks down each requirement with actionable guidance for organizations in the Kingdom and the wider GCC.

Requirement 1: Install and Maintain a Firewall Configuration

Firewalls are the first line of defense in any cardholder data environment (CDE). Requirement 1 mandates that you establish firewall and router configurations that restrict traffic between untrusted networks and any system component that stores, processes, or transmits cardholder data. This includes both network-level and host-based firewalls.

For Saudi organizations, this requirement intersects directly with NCA ECC critical security controls for network segmentation. You must ensure your CDE is properly isolated from corporate networks. Many KSA merchants make the mistake of placing payment systems on flat networks—a violation that a Qualified Security Assessor (QSA) will flag immediately. Use a demilitarized zone (DMZ) architecture and deny all traffic by default, allowing only explicitly permitted traffic.

Common implementation steps include:

Requirement 2: Do Not Use Vendor-Supplied Defaults

Requirement 2 is straightforward but frequently overlooked: change all default passwords, SNMP community strings, encryption keys, and other security parameters provided by vendors before deploying any system into production. This requirement applies to network devices, servers, POS terminals, payment applications, and even IoT devices that touch the CDE.

In Saudi Arabia, where the adoption of new payment technologies is accelerating under Vision 2030's fintech agenda, many organizations deploy payment terminals and cloud-based gateways without changing factory-default credentials. This is one of the most common findings during initial VAPT services in Saudi Arabia assessments. Develop a documented process for hardening all new devices before they join the network. Use configuration management tools to enforce baseline security settings across all system components.

Requirement 3: Protect Stored Cardholder Data

Requirement 3 addresses data at rest. You must render cardholder data unreadable anywhere it is stored—including databases, log files, backups, and archives. Acceptable methods include one-way hashing (for PAN truncation), tokenization, or strong cryptography. The requirement also mandates that you limit data retention to only what is legally or operationally necessary and dispose of it securely when no longer needed.

Saudi organizations must also consider PDPL compliance services in Saudi Arabia here, as the Personal Data Protection Law imposes additional controls on how financial data is retained and deleted. Map your data flows carefully. Many KSA merchants store primary account numbers (PANs) in logs for debugging purposes—a direct violation. Implement data discovery tools to locate and remediate unauthorized storage of cardholder data.

Requirement 4: Encrypt Transmission of Cardholder Data

Requirement 4 requires strong cryptography and security protocols (such as TLS 1.2 or 1.3) to protect cardholder data transmitted over open public networks. This includes internal networks if the data crosses boundaries between security zones. Wireless networks that connect to the CDE must use industry-standard encryption like WPA2 or WPA3.

For Saudi payment processors and e-commerce merchants, this requirement is critical when integrating with third-party payment gateways. Ensure your encryption implementation extends to all channels: web applications, mobile payment apps, API integrations, and even fax or email systems if they transmit PAN data. In the GCC, many cloud-based payment services are hosted outside the region—verify that encryption is end-to-end and that keys are managed by your organization or a trusted cloud security services in Saudi Arabia partner.

Requirement 5: Protect All Systems Against Malware

Requirement 5 mandates the deployment and maintenance of anti-malware software on all systems commonly affected by malicious software—including servers, workstations, and POS terminals. This requirement also includes scanning emails and file uploads, and ensuring that anti-malware mechanisms are kept current through regular updates and periodic scans.

In practice, this means more than just installing antivirus. Saudi merchants operating in the energy, retail, or financial services sectors should deploy endpoint detection and response (EDR) tools that go beyond signature-based detection. The Agentic SOC AI solution from CyberSilo provides behavioral-based threat detection that can identify novel malware targeting payment environments. Ensure all systems generate audit logs for anti-malware activities as required by PCI DSS logging requirements.

Requirement 6: Develop and Maintain Secure Systems

Requirement 6 covers the entire software development lifecycle for payment applications. You must identify and remediate security vulnerabilities in all system components, apply security patches promptly (within one month for critical vulnerabilities, or sooner per vendor guidance), and develop internal applications according to secure coding standards.

For Saudi organizations using commercial payment applications, this requirement means verifying that your software is built by PCI-listed vendors and checking for the latest version of the Payment Application Data Security Standard (PA-DSS). For custom development—common in Saudi fintech startups—implement a secure software development lifecycle (SSDLC) that includes code review, static and dynamic analysis, and agentic penetration testing before release. CyberSilo's Compliance Standards Automation solution can streamline patch management verification across your environment.

Requirement 7: Restrict Access to Cardholder Data

Requirement 7 enforces the principle of least privilege: grant access to cardholder data only to individuals whose job responsibilities explicitly require it. This applies to both physical and logical access. You must document access control policies, define role-based access, and review access rights at least every six months.

Saudi organizations often find this requirement challenging in environments where IT and operations teams share administrative duties. For example, a POS support technician may not need direct read access to PANs. Implement access control lists (ACLs), database views, or application-level permissions that mask sensitive data. Regular user access reviews should be documented and retained for audit purposes. The PCI DSS compliance services in Saudi Arabia from CyberSilo can help you design and enforce these controls.

Requirement 8: Identify and Authenticate Access

Requirement 8 mandates that every user with access to the CDE be assigned a unique ID and authenticated using at least two factors for remote or administrative access. This includes technicians, third-party vendors, and internal staff. Passwords must meet complexity requirements, be changed periodically, and never be shared or stored in plaintext.

In the KSA context, many merchants still rely on shared POS terminal logins—a major finding during PCI assessments. Transition to individual user accounts and implement multi-factor authentication (MFA) for all remote administration of the CDE. If you use biometric authentication, ensure it is mapped to a unique user identity. For organizations managing diverse workforces, including contractors in NEOM and other giga-projects, a centralized identity and access management (IAM) solution is essential.

Requirement 9: Restrict Physical Access

Requirement 9 covers physical security for cardholder data. You must restrict physical access to systems that store, process, or transmit cardholder data—including servers, network closets, POS terminals, and backup media. This includes visitor management, media disposal procedures, and tamper-resistant hardware.

Saudi merchants operating in retail or hospitality environments often overlook physical access to POS terminals. Ensure terminals are secured against tampering, and that cameras or logs track who accesses server rooms. For organizations with multiple branches across the Kingdom, define consistent physical security standards. Any media—such as hard drives or backup tapes—containing cardholder data must be destroyed or degaussed before disposal. Document all physical security controls in your PCI DSS policy.

Requirement 10: Track and Monitor All Access

Requirement 10 is one of the most technically demanding. It requires that you log all access to network resources and cardholder data, including user actions, privileged operations, failed login attempts, and changes to system configurations. Logs must be retained for at least one year (with three months immediately accessible) and reviewed daily or weekly depending on the volume.

For Saudi enterprises, achieving Requirement 10 often requires a centralized log management and SIEM platform. CyberSilo's ThreatHawk SIEM + SOAR is designed to ingest logs from diverse payment systems, normalize them, and generate alerts for suspicious activities. Automated log review reduces the manual burden on compliance teams. Ensure your log retention aligns with both PCI DSS and NCA ECC logging requirements—typically one year minimum for PCI, but NCA ECC may require longer for certain financial data.

Compliance Note for KSA: Saudi QSAs often focus heavily on Requirement 10 during audits because weak logging undermines the entire audit trail. If you cannot prove who accessed cardholder data and when, your compliance report will show a finding. Automate log collection and anomaly detection where possible.

Requirement 11: Test Security Systems Regularly

Requirement 11 mandates regular testing of security controls, including quarterly vulnerability scans (conducted by an Approved Scanning Vendor, or ASV), annual penetration testing, internal vulnerability scans, and network segmentation checks. It also requires file integrity monitoring (FIM) on critical system files and internal or external penetration testing at least once a year.

Saudi merchants should treat this requirement as an ongoing program rather than a once-a-year checkbox. Work with a locally present QSA and use VAPT services in Saudi Arabia for penetration testing to ensure that findings reflect the regional threat landscape. File integrity monitoring can be deployed using tools like the CIS Benchmarking Tool to detect unauthorized changes to configuration files, databases, and payment application binaries. Document all test results and remediation actions for your auditor.

Requirement 12: Maintain an Information Security Policy

Requirement 12 is the backbone of your PCI DSS program. It requires that you establish, publish, maintain, and disseminate a comprehensive information security policy that addresses all 12 requirements. This includes an incident response plan, a risk assessment process, a security awareness program for all employees, and a formal vendor management program for third-party service providers.

For Saudi organizations, merging PCI DSS Requirement 12 with local frameworks like GRC services in Saudi Arabia creates operational efficiency. Your security policy should reference both PCI DSS and relevant NCA, SAMA, and PDPL controls. ensure that all third parties handling cardholder data are contractually bound to PCI DSS compliance and that you validate their compliance annually. Security awareness training should be role-specific and delivered in both English and Arabic for maximum effectiveness across your workforce.

Practical Implementation Tips for Saudi Merchants

Achieving compliance across all PCI DSS 12 requirements is not a one-time project but an ongoing discipline. Start with a gap analysis against the full PCI control list. Prioritize requirements based on current risk posture and regulatory pressure from SAMA or your acquiring bank. Consider engaging a local Qualified Security Assessor (QSA) who understands the intersection of PCI DSS with NCA ECC and SAMA CSF.

Automation is your ally. Manual compliance reviews are error-prone and unsustainable for growing organizations. Tools like the Compliance Standards Automation platform from CyberSilo can map PCI controls to evidence, track remediation, and generate reports ready for your annual assessment. This is especially valuable for Saudi merchant groups operating across multiple subsidiaries or brands.

Finally, do not overlook the human factor. A well-configured firewall and strong encryption mean little if an employee writes down PANs on a notepad or connects a compromised laptop to the CDE. Build security awareness into your culture, and make compliance a shared responsibility across IT, operations, compliance, and executive leadership.

Map Your PCI Controls with Confidence

Unsure where your organization stands against the 12 PCI DSS requirements? CyberSilo's compliance specialists can help you assess your current posture, identify gaps specific to your Saudi operation, and automate evidence collection for your next audit.

Common Challenges for KSA Merchants

Saudi organizations face several recurring challenges when implementing the PCI DSS 12 requirements. First, many merchants operate legacy POS systems that cannot support modern encryption protocols like TLS 1.2 or MFA. Upgrading these systems often requires significant capital investment and vendor coordination. Second, third-party service providers—including cloud hosting providers, payment gateways, and IT support firms—may not be fully PCI-compliant, shifting liability back to the merchant. Third, the dual burden of complying with both PCI DSS and local frameworks like SAMA CSF can stretch internal compliance teams.

To overcome these challenges, adopt a risk-based approach. Use the PCI control list as a baseline and layer on local regulatory requirements. Engage a managed security services provider like CyberSilo to handle continuous monitoring, vulnerability scanning, and log review. Many Saudi merchants find that outsourcing parts of Requirements 10 and 11 to a trusted provider reduces cost while improving audit readiness.

Frequently Asked Questions

What are the 12 PCI DSS requirements in simple terms?

The 12 requirements cover: firewall configuration, default password removal, data protection at rest, encryption in transit, malware protection, secure systems development, access restriction, user authentication, physical security, logging and monitoring, regular testing, and an overall security policy. Each requirement maps to specific controls that protect cardholder data.

How many PCI DSS requirements are there?

There are 12 core requirements, organized under six goals. Each requirement contains multiple sub-requirements (over 300 in PCI DSS v4.0.1) that vary in applicability based on your organization's size, transaction volume, and risk profile. The PCI DSS 12 requirements form the foundation of all compliance assessments.

Is PCI DSS mandatory in Saudi Arabia?

Yes, for any organization that stores, processes, or transmits cardholder data in the Kingdom. While PCI DSS is a contractual requirement from card brands (Visa, Mastercard, etc.), SAMA also mandates it for licensed financial institutions through the SAMA CSF. Non-compliance can result in fines, increased transaction fees, or loss of the ability to process payments.

Can small merchants in KSA comply with all 12 requirements?

Yes. The PCI Security Standards Council provides a Self-Assessment Questionnaire (SAQ) for smaller merchants with simplified validation. While the requirements remain the same, the level of documentation and testing is scaled down. Many Saudi small businesses use PCI-compliant payment gateways to minimize the scope of their own compliance obligations.

What is the difference between PCI DSS v3.2.1 and v4.0.1 for requirement 8?

In v4.0.1, Requirement 8 places greater emphasis on multi-factor authentication (MFA), making it mandatory for all administrative access to the CDE (not just remote access) by March 2025. It also introduces more specific password complexity and rotation rules. Saudi merchants should plan for these changes now if they are still on v3.2.1.

Our Conclusion & Recommendation

Understanding and implementing the PCI DSS 12 requirements is a complex but essential undertaking for any Saudi merchant, processor, or service provider. The standard is not merely a compliance checkbox—it is a proven framework for protecting cardholder data and reducing the risk of a breach that could damage your reputation and result in regulatory penalties from SAMA or NCA.

We recommend that Saudi organizations adopt a structured approach: assess your current posture against the full PCI control list, prioritize remediation based on risk, and automate where possible. CyberSilo's Compliance Standards Automation platform, combined with PCI DSS compliance services in Saudi Arabia, provides a complete solution for mapping, monitoring, and maintaining PCI compliance across your enterprise. Start with a focused assessment of Requirements 3, 4, 10, and 11—these are where most KSA merchants have gaps—and build your program from there.

Ready to Align Your Organization with PCI DSS?

CyberSilo's team of certified PCI compliance experts serves organizations across Saudi Arabia and the GCC. Let us help you navigate the 12 requirements, close audit findings, and maintain continuous compliance.