Skip to contentSkip to content
🇺🇸
Regional Benchmark

PCI Compliance in United States

The United States is the largest PCI DSS market globally, accounting for over 40% of all card transactions. US organisations face the highest number of PCI audits annually, driven by card brand mandates from Visa, Mastercard, American Express, and Discover.

Run PCI Benchmark →
1,180
Avg Audit Hours
annually
$178k
Avg Cost (USD)
≈ $178k USD
58/100
Avg Maturity
maturity score

US organisations should note that several states have enacted additional data security requirements that interact with PCI DSS — including California (CCPA), New York (SHIELD Act), and Texas (TBPC). Some acquiring banks also impose enhanced compliance timelines beyond PCI minimums.

Top PCI-Active Industries in United States

E-CommerceRetailFinancial ServicesHealthcareTechnologyHospitality

Regional Compliance Context

Visa USA Compliance Programme
Level 1–4 merchant requirements enforced by acquiring banks
State Data Breach Laws
All 50 states have breach notification laws; 5+ have enhanced security requirements
FTC Safeguards Rule
Financial institutions must implement security controls; overlaps with PCI DSS
CCPA (California)
Additional data subject rights and processing requirements for CA residents

Frequently Asked Questions

Is PCI compliance mandatory in the US?

PCI DSS is not a US federal law but is mandated by card brands (Visa, Mastercard, AMEX, Discover) through contractual agreements with acquiring banks. Non-compliance results in fines, increased transaction fees, and potential loss of card processing rights.

How much does PCI compliance cost in the US?

US organisations average $178,000 annually for PCI compliance. Small merchants using SAQ-A typically spend $15,000–$50,000; Level 1 enterprises with ROC requirements can exceed $500,000.

How many US organisations are PCI compliant?

According to Verizon's Payment Security Report, only around 43% of US organisations maintained full PCI compliance throughout the assessment period, though compliance rates have improved significantly with automation tools.

Do US state laws affect PCI compliance?

Yes. California, New York, Texas, and other states have data security laws that may require controls beyond PCI DSS minimums. Compliance teams should conduct a gap analysis between state requirements and their PCI programme.

Run PCI BenchmarkIntelligence DashboardPCI DSS GuideCost Calculator

Get Your United States PCI Benchmark

See how your compliance programme compares to United States industry averages.

Run Free Benchmark →