Published by Capital Insight Ltd · Nicosia Herausgegeben von Capital Insight Ltd · Nikosia
The Banking Dossier
Security

Compliant and breached: what a PCI certificate does not tell you

Konform und trotzdem kompromittiert: Was ein PCI-Zertifikat nicht aussagt

Every business that touches a card number is subject to a security standard written by the card networks themselves. Almost all of them pass. The breaches keep happening. Both of those things are true at once, and the reason is built into how the standard is assessed.

What PCI DSS is, and who wrote it

The Payment Card Industry Data Security Standard is maintained by the PCI Security Standards Council, an organisation founded by the card networks. It is not law. Its force comes from the same contractual chain as everything else in payments: the networks require it of acquirers, acquirers require it of merchants, and non-compliance is a breach of contract rather than a regulatory offence.

The current version is 4.0.1, and its future-dated requirements became mandatory in March 2025. It is a serious document. Segmentation, encryption in transit and at rest, access control, logging, vulnerability management, penetration testing — the substance is what a competent security programme would contain anyway.

The self-assessment problem

Here is the structural weakness. How a merchant demonstrates compliance depends on transaction volume. The largest merchants undergo an audit by a Qualified Security Assessor and produce a Report on Compliance. Everyone below that threshold — which is to say the overwhelming majority of businesses — completes a Self-Assessment Questionnaire.

The questionnaire is a form. The merchant answers it. Nobody verifies the answers unless something goes wrong. A business can hold a current, valid attestation of compliance describing a control environment that does not exist, and the first party to discover the discrepancy will be the forensic investigator hired after the breach.

This is not cynicism about merchants. Most answer honestly. But “compliant” in the SAQ world means “stated that it complies”, and the distance between those two claims is where the standard loses its grip.

Compliance is a snapshot; attacks are continuous

An annual attestation describes a moment. Card-skimming attacks on checkout pages — scripts injected into a payment form to copy card data as it is typed — operate continuously and often persist for months before discovery. A merchant can be genuinely compliant on the day of assessment and compromised the following week without any control formally failing.

The standard has responded: 4.0 added requirements around managing and monitoring scripts on payment pages. That is the right direction. It is also a reminder that the framework tends to arrive after the attack technique is mature.

Who the standard actually protects

Read the liability allocation and the purpose becomes clearer. When card data is stolen, the costs — reissuing cards, absorbing fraud, fielding disputes — fall first on issuers and networks. PCI DSS is the mechanism through which they push a share of that risk down to merchants, and through which they establish, after an incident, that the merchant failed to meet an agreed obligation.

That is legitimate. The party creating the exposure ought to carry some of it. But it means the standard is best understood as a risk-allocation instrument that also improves security, rather than a security instrument that happens to allocate risk. The distinction matters when assessing how much comfort a compliance certificate should give anyone.

What we would look for instead

If the question is whether a business handling card data is actually secure, the useful signals are not the attestation. They are: does the merchant touch card data at all, or does a tokenising provider take it before it reaches their systems? Is the payment form served from an isolated origin? Are there external monitoring results, not just internal claims? Was the last penetration test conducted by someone with no commercial interest in the outcome?

None of those appear on a certificate. All of them tell you more than one.

The honest summary

PCI DSS raised the floor across an industry that badly needed one, and merchants who implement it properly are meaningfully harder to compromise. The problem is not the content of the standard. It is that for most of the market, compliance is asserted rather than examined — and an assertion is exactly as strong as the incentive to make it truthfully.


Sources: PCI Security Standards Council, PCI DSS v4.0.1 and the associated Self-Assessment Questionnaire guidance; card network rules on compliance validation levels. This article describes the assessment framework as published; individual acquirers may impose stricter validation than the minimum.

Jedes Unternehmen, das mit Kartennummern umgeht, unterliegt einem Sicherheitsstandard, den die Kartennetzwerke selbst geschrieben haben. Fast alle bestehen ihn. Die Datenabflüsse gehen trotzdem weiter. Beides stimmt gleichzeitig, und der Grund steckt in der Art, wie der Standard geprüft wird.

Was PCI DSS ist und wer ihn geschrieben hat

Der Payment Card Industry Data Security Standard wird vom PCI Security Standards Council gepflegt, einer von den Kartennetzwerken gegründeten Organisation. Er ist kein Gesetz. Seine Wirkung stammt aus derselben Vertragskette wie alles andere im Zahlungsverkehr: Die Netzwerke verlangen ihn von den Acquirern, die Acquirer von den Händlern, und ein Verstoß ist ein Vertragsbruch, kein Ordnungswidrigkeitstatbestand.

Aktuell ist Fassung 4.0.1, deren zunächst aufgeschobene Anforderungen im März 2025 verbindlich wurden. Das Dokument ist ernsthaft. Segmentierung, Verschlüsselung bei Übertragung und Speicherung, Zugriffskontrolle, Protokollierung, Schwachstellenmanagement, Penetrationstests — inhaltlich steht darin, was ein kompetentes Sicherheitsprogramm ohnehin enthielte.

Das Problem der Selbstauskunft

Hier liegt die strukturelle Schwäche. Wie ein Händler seine Konformität nachweist, hängt vom Transaktionsvolumen ab. Die größten Händler durchlaufen eine Prüfung durch einen Qualified Security Assessor und erhalten einen Report on Compliance. Alle unterhalb dieser Schwelle — also die überwältigende Mehrheit — füllen einen Self-Assessment Questionnaire aus.

Dieser Fragebogen ist ein Formular. Der Händler beantwortet es. Niemand überprüft die Antworten, solange nichts passiert. Ein Unternehmen kann eine gültige Konformitätsbescheinigung über eine Kontrollumgebung besitzen, die es nicht gibt — und die erste Partei, die den Unterschied bemerkt, ist der Forensiker, den man nach dem Vorfall beauftragt.

Das ist kein Misstrauen gegenüber Händlern. Die meisten antworten ehrlich. Aber „konform” heißt in der Welt der Selbstauskunft „hat erklärt, konform zu sein”, und in der Lücke zwischen diesen beiden Aussagen verliert der Standard seinen Griff.

Konformität ist eine Momentaufnahme, Angriffe sind dauerhaft

Eine jährliche Bescheinigung beschreibt einen Zeitpunkt. Skimming-Angriffe auf Checkout-Seiten — in ein Zahlungsformular eingeschleuste Skripte, die Kartendaten beim Tippen mitschreiben — laufen fortlaufend und bleiben oft monatelang unentdeckt. Ein Händler kann am Prüftag tatsächlich konform sein und in der Woche darauf kompromittiert, ohne dass formal eine Kontrolle versagt hätte.

Der Standard hat reagiert: Fassung 4.0 verlangt, Skripte auf Zahlungsseiten zu verwalten und zu überwachen. Das ist die richtige Richtung. Es erinnert zugleich daran, dass der Rahmen meist erst eintrifft, wenn die Angriffstechnik ausgereift ist.

Wen der Standard tatsächlich schützt

Liest man die Haftungsverteilung, wird der Zweck klarer. Werden Kartendaten gestohlen, treffen die Kosten — Kartenneuausgabe, Betrugsschäden, Streitfallbearbeitung — zuerst kartenausgebende Banken und Netzwerke. PCI DSS ist der Mechanismus, über den diese einen Teil des Risikos an die Händler weiterreichen und über den sie nach einem Vorfall feststellen, dass der Händler eine vereinbarte Pflicht verletzt hat.

Das ist legitim. Wer die Gefährdung schafft, sollte einen Teil davon tragen. Es bedeutet aber, dass der Standard am besten als Instrument der Risikoverteilung zu verstehen ist, das nebenbei die Sicherheit verbessert — nicht als Sicherheitsinstrument, das zufällig Risiko verteilt. Für die Frage, wie viel Beruhigung ein Konformitätszertifikat rechtfertigt, macht das einen Unterschied.

Worauf wir stattdessen schauen

Will man wissen, ob ein Unternehmen mit Kartendaten wirklich sicher arbeitet, sind die nützlichen Signale nicht die Bescheinigung. Sondern: Berührt der Händler Kartendaten überhaupt, oder nimmt ein tokenisierender Dienstleister sie ab, bevor sie seine Systeme erreichen? Wird das Zahlungsformular von einem isolierten Ursprung ausgeliefert? Gibt es externe Messergebnisse statt nur interner Zusicherungen? Wurde der letzte Penetrationstest von jemandem durchgeführt, der am Ergebnis kein wirtschaftliches Interesse hat?

Nichts davon steht auf einem Zertifikat. Alles davon sagt mehr aus als eines.

Die ehrliche Bilanz

PCI DSS hat in einer Branche, die das dringend brauchte, das Mindestniveau angehoben, und Händler, die ihn ernsthaft umsetzen, sind spürbar schwerer anzugreifen. Das Problem ist nicht der Inhalt des Standards. Es ist, dass Konformität für den größten Teil des Marktes behauptet und nicht geprüft wird — und eine Behauptung ist genau so belastbar wie der Anreiz, sie wahrheitsgemäß abzugeben.


Quellen: PCI Security Standards Council, PCI DSS v4.0.1 samt den Hinweisen zum Self-Assessment Questionnaire; Regelwerke der Kartennetzwerke zu den Validierungsstufen. Dieser Beitrag beschreibt den veröffentlichten Prüfrahmen; einzelne Acquirer können strengere Nachweise verlangen als das Minimum.