ShouldEye Trust Intelligence Glossary

Payment Security and PCI Terms

PCI DSS, SAQ levels, P2PE, tokenization vaults, and payment-security controls — educational, not certification advice.

Educational information only. ShouldEye does not provide legal, banking, or individualized financial advice. Dispute rights, deadlines, and outcomes depend on your payment method, card network, issuer, processor, jurisdiction, and the facts of your case. Legal Disclaimers

35 published definitions in this topic.

Payment Security and PCI

ISO 27001

ISO/IEC 27001 is an international standard for establishing and managing an information security management system (ISMS).

Read full definition
Payment Security and PCIRegulation

PCI DSS

PCI DSS is the Payment Card Industry Data Security Standard for protecting cardholder data when it is stored, processed, or transmitted.

Read full definition
Payment Security and PCI

PCI Level 1

PCI Level 1 is a merchant (or service-provider) validation tier commonly used by brands/acquirers based largely on annual transaction volume and sometimes incident history.

Read full definition
Payment Security and PCI

PCI Level 2

PCI Level 2 is a merchant (or service-provider) validation tier commonly used by brands/acquirers based largely on annual transaction volume and sometimes incident history.

Read full definition
Payment Security and PCI

PCI Level 3

PCI Level 3 is a merchant (or service-provider) validation tier commonly used by brands/acquirers based largely on annual transaction volume and sometimes incident history.

Read full definition
Payment Security and PCI

PCI Level 4

PCI Level 4 is a merchant (or service-provider) validation tier commonly used by brands/acquirers based largely on annual transaction volume and sometimes incident history.

Read full definition
Payment Security and PCI

PCI Scope

PCI scope is the set of people, processes, and technologies that store, process, or transmit cardholder data or can affect its security.

Read full definition
Payment Security and PCI

SAQ A

SAQ A is a PCI self-assessment questionnaire aimed at merchants that fully outsource card-data functions to validated third parties with no electronic card data in their environment.

Read full definition
Payment Security and PCI

SAQ A-EP

SAQ A-EP covers e-commerce merchants who outsource payment processing but whose websites can still affect the security of the payment page.

Read full definition
Payment Security and PCI

SAQ D

SAQ D is the most comprehensive self-assessment questionnaire for merchants or service providers not eligible for shorter SAQs.

Read full definition
Payment Security and PCI

SOC 2 Type II

SOC 2 Type II is an attestation report on how well an organization’s controls operated over a period against Trust Services Criteria.

Read full definition