Skip to contentSkip to content
🇦🇺
Regional Benchmark

PCI Compliance in Australia

Australia has a mature card payments market regulated by the Reserve Bank of Australia (RBA) and the Australian Payments Network (AusPayNet). Organisations must satisfy PCI DSS mandates alongside APRA prudential standards and the Privacy Act 1988.

Run PCI Benchmark →
840
Avg Audit Hours
annually
A$195k
Avg Cost (AUD)
≈ $126k USD
63/100
Avg Maturity
maturity score

APRA CPS 234 Information Security, effective November 2019, requires APRA-regulated entities to maintain information security capabilities commensurate with the size and extent of their information asset exposure. PCI DSS is recognised as a strong control framework for payment data protection.

Top PCI-Active Industries in Australia

Financial ServicesRetailE-CommerceHealthcareHospitality

Regional Compliance Context

APRA CPS 234
Information security obligations for all APRA-regulated entities including banks and insurers
Privacy Act 1988
Australian Privacy Principles (APPs) govern how personal financial information may be collected and used
AusPayNet Security Framework
Australian Payments Network requires PCI DSS compliance for all card scheme participants
Notifiable Data Breaches Scheme
Mandatory breach notification to OAIC and affected individuals within 30 days

Frequently Asked Questions

Is PCI compliance mandatory in Australia?

PCI DSS is mandatory for all Australian organisations that store, process, or transmit cardholder data, enforced by AusPayNet and acquiring banks. APRA-regulated entities face additional obligations under CPS 234.

How does APRA CPS 234 relate to PCI DSS?

CPS 234 requires APRA-regulated entities to maintain information security proportionate to their exposure. PCI DSS provides a recognised control framework and organisations can align both programmes to reduce dual audit burden.

How much does PCI compliance cost in Australia?

Australian organisations average A$195,000 (~$125k USD) annually. The higher cost reflects geographic isolation, smaller vendor markets, and APRA overlay requirements. Automation can reduce costs by 35–45%.

What are the penalties for PCI non-compliance in Australia?

Card brands can impose fines of $5,000–$100,000 per month. APRA can require additional capital holdings. The Privacy Act breach notification failure can attract penalties up to A$2.22 million for serious breaches.

Run PCI BenchmarkIntelligence DashboardPCI DSS GuideCost Calculator

Get Your Australia PCI Benchmark

See how your compliance programme compares to Australia industry averages.

Run Free Benchmark →