The Payment Card Industry Security Standards Council, or PCI SSC, is an open global forum that was launched back in 2006. It was founded in 2006 by 5 global payment brands:
American Express, Discover Financial Services, JCB International, MasterCard, and Visa Inc.; UnionPay joined as a strategic member in 2020. All of these companies agreed that they would implement the PCI DSS (Data Security Standard) and use it as their requirement for security compliance.

What does the PCI SSC do?

The PCI SSC is the entity that will approve and certify QSAs (Qualified Security Assessors) and ASVs (Approved Scanning Vendors). ASV’s are companies that offer services like ServerScan, including automated scans for vulnerabilities that generate PCI certificates and scan reports, and other security tests such as penetration testing. These approved companies undergo a rigorous testing process that is strictly monitored by the PCI SSC, and also have to pay costly annual fees in order to maintain their standing as a certified QSA or ASV. This allows them to pass PCI certification or certificates in the form of scan reports or other forms on to you, in order for you to prove your compliance with the PCI DSS.

What does the PCI SSC require for PCI compliance?

The PCI DSS requires quarterly ASV scanning for most merchants and service providers with external-facing systems — it's your acquiring bank (or the payment brands, through your acquirer) that enforces this requirement, since the PCI SSC develops and maintains the standard but does not directly enforce compliance on individual merchants. If you’re not sure what requirements you need to comply with, the PCI SSC recommends checking with your acquiring bank. They will have the most clear information on what your company must specifically do to become PCI compliant. If you would like to get a general idea, take a look at our guidelines here.