PCI-DSS applies to any organization handling credit card data. If you accept cards, you must comply.
The requirements cover:
- Firewalls and secure networks
- Protecting stored data and encrypting transit
- Antivirus and secure development
- Access control by need-to-know
- Unique user IDs and physical access limits
- Monitoring, testing, and documented policies
Consequences:
Fines from 5,000$ to 100,000$ per month. You may lose the ability to process cards entirely.