By Murty Nisthala, CISA, CISSP, CCSP. Reviewed by Girija Togarati, ISO 27001 Lead Auditor.

Yes. PCI DSS compliance is mandatory for any organisation in India that stores, processes or transmits payment card data.

The RBI mandate

The Reserve Bank of India specifically requires PCI DSS certification for payment aggregators and payment gateways as a condition of their operating licence. Banks, fintechs and merchants that handle card data must also comply.

Who must comply

If card data touches your systems, PCI DSS applies. This includes e commerce, BPOs, fintechs and any business taking card payments.

Get compliant

Univate scopes your environment and runs PCI DSS end to end so you meet the mandate.

Univate Solutions delivers PCI DSS Certification in India end to end. Book a free consultation and get a fixed quote. Explore cybersecurity services.