🇺🇸
Regional Benchmark
PCI Compliance in United States
The United States is the largest PCI DSS market globally, accounting for over 40% of all card transactions. US organisations face the highest number of PCI audits annually, driven by card brand mandates from Visa, Mastercard, American Express, and Discover.
Run PCI Benchmark →1,180
Avg Audit Hours
annually
$178k
Avg Cost (USD)
≈ $178k USD
58/100
Avg Maturity
maturity score
US organisations should note that several states have enacted additional data security requirements that interact with PCI DSS — including California (CCPA), New York (SHIELD Act), and Texas (TBPC). Some acquiring banks also impose enhanced compliance timelines beyond PCI minimums.
Top PCI-Active Industries in United States
E-CommerceRetailFinancial ServicesHealthcareTechnologyHospitality
Regional Compliance Context
Visa USA Compliance Programme
Level 1–4 merchant requirements enforced by acquiring banks
State Data Breach Laws
All 50 states have breach notification laws; 5+ have enhanced security requirements
FTC Safeguards Rule
Financial institutions must implement security controls; overlaps with PCI DSS
CCPA (California)
Additional data subject rights and processing requirements for CA residents
Frequently Asked Questions
Get Your United States PCI Benchmark
See how your compliance programme compares to United States industry averages.
Run Free Benchmark →