ISO 27001 vs PCI DSS
Information Security vs Card-Data Security

ISO 27001 is a broad ISMS covering any information asset. PCI DSS is narrow and contractual — if you store, process or transmit card data, the card brands (Visa, Mastercard, AmEx, Discover, JCB) require PCI DSS.

Option A
ISO 27001
ISO/IEC 27001:2022
Year: 2022
VS
Option B
PCI DSS
PCI DSS v4.0
Year: 2022 (effective 2024)

Who Each Standard Is For

ISO 27001 is for…

Any organisation managing sensitive information — not just card data.

PCI DSS is for…

Merchants, service providers, payment processors handling cardholder data (CHD) or sensitive authentication data (SAD).

Side-by-Side Comparison

All ten dimensions head-to-head:

AspectISO 27001PCI DSS
ScopeEntire ISMS, any informationCardholder data environment (CDE) only
Mandatory?VoluntaryContractually mandatory for card-data handlers
IssuerISO/IECPCI Security Standards Council (Visa/MC/Amex/Discover/JCB)
OutputCertificateReport on Compliance (ROC) or Self-Assessment Questionnaire (SAQ)
LevelsSingle certificationLevel 1–4 by transaction volume
AssessorAccredited CB auditorQualified Security Assessor (QSA) or internal
FrequencyAnnual surveillanceAnnual ROC/SAQ + quarterly ASV scans
SpecificityRisk-based, organisation-defined controlsPrescriptive (12 requirements, ~300 sub-requirements)
Cost (SME)£15k–£40kSAQ: free–£5k; ROC: £20k–£100k+
Overlap~40–60% with PCI DSS controls~40–60% with ISO 27001 Annex A

When to Choose Which

Choose ISO 27001 when…

Choose ISO 27001 when your buyers ask for it; you don’t handle card data; or you want a holistic ISMS.

Choose PCI DSS when…

Choose PCI DSS — mandatory — if you store, process or transmit cardholder data in any way.

Or hold both

If you process card data you need PCI DSS regardless. Adding ISO 27001 strengthens your broader ISMS, satisfies non-PCI buyers, and reuses ~50% of the same controls.

Frequently Asked Questions

Is PCI DSS a law?

No — it’s a contractual standard imposed by the card brands. Non-compliance can lead to fines and loss of card-processing rights, but it is not statutory.

What’s an SAQ?

Self-Assessment Questionnaire — a simplified compliance route for smaller merchants who handle fewer transactions and use certified providers.

What changed in PCI DSS v4.0?

More customisable approach, stronger authentication requirements (MFA everywhere), continuous validation focus, expanded scope of cardholder data environment definition.

Can ISO 27001 satisfy PCI DSS?

No — ISO 27001 cannot substitute. But the overlap reduces effort significantly.

Related Comparisons

Ready to start your gap analysis?

Both standards have free interactive gap-analysis tools — no sign-up, no install.