PCI SECURITY STANDARDS COUNCIL▊
The compliance regime whose own flagship dataset has never produced a breached company that was actually compliant — a fact both sides claim as proof.
- ENTITY
- PCI Security Standards Council — founded 2006 by Visa, Mastercard, American Express, Discover and JCB to administer the Payment Card Industry Data Security Standard (PCI DSS) FACT
- OPERATION
- A 12-requirement security standard, mandatory for anyone touching cardholder data, validated by annual assessments — performed by Qualified Security Assessors (QSAs) whom the assessed company hires and pays FACT
- EVENT
- THE ZERO — across the entire run of Verizon's Payment Security Reports, no organization that suffered a confirmed card breach has been found to have been in full PCI DSS compliance at the time of the breach FACT
- PATTERN
- Full compliance is rarely sustained between audits — by 2023, 14.3% of assessed organizations held 100% compliance at interim validation FACT
- DISPOSITION
- No adjudication, no regulator finding, no fraud allegation anywhere in this record. The charge sheet is a data argument, and both readings of the data appear below. FACT
First party. Official channel:
@PCISSC (linked from pcisecuritystandards.org). The Council's position on the Verizon findings, from Council CTO Troy Leach on the Council's own blog:
"PCI DSS compliance is an important aspect of a security program, but as we've always said, security can't start and end with compliance… 'PCI DSS-compliant' is to confirm for that moment in time, the processes exist to have a reliable defense… Some breaches occur when systems not evaluated are the point of compromise."
-->
Here is a rare specimen: a regime whose central empirical fact — nobody breached was ever actually compliant — is cited by its critics as proof the standard is theater, and by its defenders as proof the standard works. Same number. Two religions.
Every merchant, processor, and gateway that touches a payment card lives under this standard. It is not law; it is contract — enforced by the five brands that own the Council, through fines levied on the breached. The compliance industry it feeds — assessors, scanners, consultancies — is paid by the companies being assessed.
The archive's interest is the gap between the certificate and the outcome. The certificate says: on assessment day, the controls were in place. The breach data say: on breach day, they never were. Whether that gap indicts the standard, the companies, or the audit model is exactly the argument below. Both sides get the microphone.
the drama timeline
ACT I — THE FRANCHISE (2004–2006)
Five competing card brands, five competing security programs, one merger. The standard arrives first; the governing body arrives two years later.
-
DEC 2004
PCI DSS 1.0
The card brands align their separate security programs (Visa's CISP among them) into a single Payment Card Industry Data Security Standard: 12 requirements covering firewalls, encryption, access control, logging, testing, and policy. Compliance is mandatory for entities that store, process, or transmit cardholder data.
-
SEP 2006
The Council is founded
Visa, Mastercard, American Express, Discover and JCB launch the PCI Security Standards Council to administer the standard, certify the assessors (QSAs), and manage the program. The brands keep enforcement — and the fines — to themselves; the Council writes the rules and runs the assessor ecosystem.
Note the anatomy at birth: the body that writes the standard does not enforce it, the brands that enforce it do not pay for failures, and the companies that pay for failures also pay for the audits.
ACT II — THE EXHIBITS (2007–2014)
The standard's hardest years are the ones where its certificates and the breach headlines share a calendar.
-
2007–2009
TJX, then Heartland
TJX (up to 94 million records) is found in litigation to have been non-compliant with most of the standard — a case FOR the standard, if anything. Then Heartland Payment Systems (~130 million cards) is breached while holding current PCI compliance certification, having been certified repeatedly during the very window the intruders were inside. The standard's awkward exhibit A. Full case file: Heartland.
-
2013–2014
Target
Target is breached (~40 million cards) weeks after, per the banks' later complaint, its assessor scanned the network and found no vulnerabilities. The banks sue the QSA itself — then drop the suit. The QSA's defense becomes the compliance industry's own motto: an assessment is a point in time, not a guarantee. Full case file: Trustwave.
ACT III — THE DATASET (2019–2024)
Verizon has been assessing PCI environments and investigating card breaches since before the Council existed. Its annual report is the closest thing the argument has to a scoreboard.
-
NOV 2019
The 2019 Payment Security Report
Verizon states it can "definitively" say it has never reviewed an environment or investigated a PCI data breach involving an entity that was truly PCI DSS compliant — "even if it had a signed Attestation of Compliance." Among breached organizations, 0% were compliant with Requirements 3, 8, 10, 11 and 12; only a quarter had Requirement 9 fully in place. Verizon's framing, carried in the same coverage: "It is not that PCI DSS fails, but that companies fail to maintain compliance from one audit to the next."
-
2024
The 2024 Payment Security Report — the pattern holds
"The results of the comparison remain consistent year after year. To date, we are not aware of any disclosed public records of any organization experiencing a confirmed payment card data breach that validated its PCI DSS compliance and was found to be in full compliance with the requirements at the time of the breach." Meanwhile the full-compliance trend line sags to 14.3% for 2023 — Verizon notes the disruptive transition to PCI DSS v4.0 as a likely contributing factor.
Eighteen years in, the scoreboard reads: nobody compliant has ever been breached, and almost nobody stays compliant. The syllogism is left as an exercise for the reader, which is precisely the problem.
both sides, on the record
The certificate predicts nothing. Every breached organization in Verizon's multi-decade dataset turned out to be non-compliant when it mattered — including ones holding signed Attestations of Compliance. The paper said secure; the forensics said otherwise [1] [3].
The model can't sustain itself. Full compliance at interim validation fell from roughly half of organizations to 14.3% by 2023. An annual audit that decays within the year is a snapshot business, renewed annually, forever [1].
The incentives are the tell (the critics' argument, theirs): the assessed pays the assessor; the brands that own the Council fine the breached; the standard's failures generate remediation and re-assessment revenue for the same ecosystem that certified the failure. See Heartland's CEO on his own QSAs, and the banks' complaints against Target's [5] [6].
The zero cuts the other way. Read straight, Verizon's finding says no fully compliant organization has ever been found breached — the standard's floor held every time it was actually standing. Verizon itself frames the problem as sustainability, not the standard: companies pass, then let controls lapse [1] [3].
Correlation is not the standard failing. Breached companies being non-compliant does not show compliant companies get breached; industry analysts have flagged the sloppy versions of the "PCI is worthless" inference as a logical fallacy [7]. Verizon also notes unbreached organizations typically go beyond the PCI baseline — the standard as floor, not ceiling [1].
The Council's own position, on the record: compliance is "an important aspect of a security program, but… security can't start and end with compliance"; an assessment confirms controls "for that moment in time"; some breaches enter through systems that were never in assessment scope — and successive versions of the standard (11.3.4 segmentation testing, v4.0's continuous-process emphasis) were written to close exactly those gaps [4].
YOU DECIDE
Scoped to the claims. The zero is real, published by Verizon for years, and undisputed in both directions: no breached company was compliant, and no compliant company is known to have been breached. The sustained-compliance collapse to 14.3% is real. The structural facts — who owns the Council, who pays the assessor, who pays the fines — are public record. Whether that adds up to a baseline the industry fails to maintain, or a certificate business engineered so failure is always the customer's fault, is the one question the dataset cannot answer for you.
Weigh the costly signal: eighteen years, billions in assessments, and the regime's best empirical defense is that its certificate has never once been present at the scene of the crime.
The archive does not judge. It keeps the scoreboard.
evidence locker
PRIMARY RECORD
CONTEXT & ANALYSIS
The standard. Every number above traces to Verizon's own published reports or to named press coverage of them; the Council's structure traces to its own site; the Council's defense is quoted from its own blog at full strength. The "audit-revenue theater" characterization is presented as the critics' argument, never adopted as fact. No fraud is alleged, no motive asserted, no adjudication claimed — because none exists. If it couldn't survive a defamation challenge, it wouldn't be on this page.