After July 2021, the 2.3.x release line no longer received quality updates or user guide updates. PHP 7.3 reached end of support in December 2021, and Adobe Commerce 2.3.x reached end of support in September 2022. We strongly recommend upgrading to Adobe Commerce 2.4.x to help maintain PCI compliance.

PCI Compliance Guidelines

This site contains archived merchant documentation for a version of Adobe Commerce and Magento Open Source that has reached end-of-support. The documentation available here is intended for historical reference only and is not maintained. The Adobe Commerce Merchant Documentation for current releases is published on the Adobe Experience League.

The Payment Card Industry (PCI) has established a set of requirements for businesses that accept payment by credit card over the Internet. In addition to maintaining a secure server environment, merchants who handle customer credit card information must meet the following guidelines.

PCI requirements

checkbox Install and maintain a firewall configuration to protect cardholder data.
checkbox Do not use vendor-supplied defaults for system passwords and other security parameters.
checkbox Protect stored cardholder data.
checkbox Encrypt transmission of cardholder data across open, public networks.
checkbox Use and regularly update antivirus software.
checkbox Develop and maintain secure systems and applications.
checkbox Restrict access to cardholder data by business need to know.
checkbox Assign a unique ID to each person with computer access.
checkbox Restrict physical access to cardholder data.
checkbox Track and monitor all access to network resources and cardholder data.
checkbox Regularly test security systems and processes.
checkbox Maintain a policy that addresses information security.

To learn more, see Magento Approach to PCI Compliance.

As your business grows, you may be required to file a compliance report on an annual basis. PCI reporting requirements increase in proportion to merchant level, but are waived for businesses that process fewer than 20,000 credit card transactions per year. To learn more, visit the PCI Security Standards Council website.