- CISO-Led Security & Governance/
- Security Insights & Advisories/
- Who Needs PCI DSS 4.0.1 Compliance in Thailand?/
Who Needs PCI DSS 4.0.1 Compliance in Thailand?
Table of Contents
The most common PCI DSS question I hear is not “how do I comply?” but “do I even need to?” The answer is broader than most organisations assume, and the consequences of guessing wrong are not theoretical: they are fines, higher interchange fees, and, in a breach, forensic costs and brand damage measured in real money.
The short answer #
The PCI Data Security Standard applies to any entity that stores, processes, or transmits cardholder data, and to any entity that could affect the security of that data. That is deliberately wide, and it sweeps in three groups people routinely assume are exempt.
1. Anyone storing, processing, or transmitting card data #
This is the obvious case, but it includes far more than the merchant who swipes a card. It covers:
- The e-commerce site that takes a card number in a checkout form.
- The ERP that stores a PAN “just for reconciliation.”
- The call centre that keys card numbers into a CRM while on a recorded line.
- The payment gateway, PSP, acquirer, and issuer that touch the data every day.
If card data lands on your systems, even briefly, even in memory, you are in scope. “We only hold it for a second” is not an exemption; it is scope.
2. Even when you use a third-party processor #
The single biggest misconception is “we use Stripe / 2C2P / PayPal, so PCI DSS is not our problem.” Using a third party shrinks your scope; it does not eliminate it.
What it usually means (for a small organisation) is you qualify for a reduced validation form: an SAQ A or SAQ A-EP rather than a full SAQ D, because the card data never touches your systems. But you still have obligations: maintain the script integration correctly, keep the checkout page free of skimming, and manage the third party under Requirement 12.8 of the standard. You still validate; you just validate less.
The trap is scope creep. Add one bespoke field that captures a card number server-side, or redirect through your own endpoint, and you silently move from SAQ A to SAQ D: a dramatically larger obligation. Nobody tells you when that happens.
3. Banks and everyone upstream of the cardholder #
Banks, acquirers, issuers, and payment facilitators are not merely “in scope”: they are the most heavily validated entities in the ecosystem. In Thailand, financial institutions also answer to the Bank of Thailand IT Risk and digital channel guidelines on top of PCI DSS. The two regimes overlap but are not identical, and a BOT audit does not substitute for a PCI DSS validation.
Why scope is everything #
PCI DSS cost scales with scope. Every system, network, and person inside your Cardholder Data Environment (CDE) is subject to the full control set. Shrinking the CDE is therefore the highest-leverage compliance activity you can do:
- Tokenise card data so you store a useless reference instead of a PAN.
- Isolate payment systems behind segmentation so the rest of the business is out of scope.
- Outsource deliberately to a validated service provider for the pieces you do not need to touch.
A well-scoped environment can turn a six-month, six-figure assessment into a manageable, repeatable exercise. A poorly scoped one audits the entire company for no additional security benefit.
4.0.1 changes the game #
PCI DSS 4.0.1 formalised much of what good engineering teams were already doing: treating compliance as a continuous state rather than an annual event, with requirements around targeted risk analysis, customised control approaches, and maintaining security through change. The message is that a point-in-time certificate is no longer enough: the standard now expects the controls to stay true between assessments.
Where to start #
Begin with a PCI DSS Gap Assessment & Scope Reduction before committing to an audit: shrink the CDE, test your segmentation, and only then validate. When you are ready, our QSA-led audit takes you through the full ROC/AOC with an active assessor in Bangkok.