nerdexam
(ISC)2

CCSP · Question #14

What sort of legal enforcement may the Payment Card Industry (PCI) Security Standards Council not bring to bear against organizations that fail to comply with the Payment Card Industry Data Security…

The correct answer is B. Jail time. The PCI Security Standards Council (PCI SSC) is an industry body, not a governmental or law enforcement agency, and therefore lacks the authority to impose legal penalties such as jail time.

Submitted by haruto_sh· Apr 18, 2026Legal, Risk and Compliance

Question

What sort of legal enforcement may the Payment Card Industry (PCI) Security Standards Council not bring to bear against organizations that fail to comply with the Payment Card Industry Data Security Standard (PCI DSS)?

Options

  • AFines
  • BJail time
  • CSuspension of credit card processing privileges
  • DSubject to increased audit frequency and scope

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    87% (20)
  • C
    9% (2)

Why each option

The PCI Security Standards Council (PCI SSC) is an industry body, not a governmental or law enforcement agency, and therefore lacks the authority to impose legal penalties such as jail time.

AFines

Fines can be imposed by the card brands (Visa, MasterCard, etc.) for PCI DSS non-compliance, often passed down through acquiring banks to merchants.

BJail timeCorrect

The PCI Security Standards Council (PCI SSC) is a private organization established by major payment card brands, not a governmental entity with legal authority to levy criminal penalties. While non-compliance can lead to significant business consequences like fines, revocation of processing privileges, or increased audit requirements imposed by individual card brands, it cannot result in jail time.

CSuspension of credit card processing privileges

The suspension of credit card processing privileges is a severe consequence that card brands can impose on non-compliant organizations.

DSubject to increased audit frequency and scope

Organizations failing to comply with PCI DSS are often subjected to increased audit frequency and scope by their acquiring banks or card brands as a measure to ensure compliance.

Concept tested: PCI DSS enforcement limitations

Source: https://www.pcisecuritystandards.org/pci_dss_faq_v3-2-1/#_Does_PCI_SSC

Topics

#PCI DSS#Compliance Enforcement#Legal Consequences#Payment Card Security

Community Discussion

No community discussion yet for this question.

Full CCSP Practice