AC

PCI-DSS Compliance: 12 Requirements Guide for Turkish Fintechs

TL;DR

PCI-DSS Seviye 1-4 ölçeğinde 12 gereklilik (sınır güvenliği, kart şifreleme, erişim, izleme, politika). Türkiye uygulamasında KVKK + 6493 + ISO entegrasyonu.

15 Şubat 2026 Financial Law 2 dk okuma 6 görüntülenme Son güncelleme: 9 Mayıs 2026

PCI-DSS (Payment Card Industry Data Security Standard) is mandatory for all institutions that process card data. Levels: 1 (6M+ tx/year) - 4 (20K-1M tx/year). It is applied together with KVKK + 6493 SK in Türkiye.

Levels

LevelAnnual txAudit
16M+Annual QSA on-site
21M-6MAnnual SAQ + ASV scan
320K-1MAnnual SAQ + ASV scan
420K-1MAnnual SAQ (self)

12 PCI-DSS requirements

  • Firewall configuration standards.
  • Not using default passwords and security parameters.
  • Storing cardholder data by encrypting it (AES-256).
  • Card data encrypted transmission in an open network (TLS 1.2+).
  • Antivirus.
  • Secure application development (SDLC, OWASP top 10).
  • Access control, least privilege.
  • Unique ID + MFA for each user.
  • Physical access restriction.
  • Monitoring all access and activity (SIEM, log retention 1 year).
  • Annual security tests (pen-test, code review).
  • Information security policy.
  • Where to get PCI-DSS audit in Türkiye?

    From QSA (Qualified Security Assessor) companies. There are approved QSAs in Türkiye such as KPMG, EY, Deloitte, PwC, Procoders, Tridom. Annual on-site audit ranges from 25-100K USD.

    Does it conflict with KVKK?

    Does not contradict; complement. PCI-DSS is focused on card data, KVKK is for all personal data. KVKK m.12 data security requirement is easily met thanks to PCI-DSS compliance.

    Is Tokenization sufficient?

    Tokenization narrows the PCI-DSS scope, but does not eliminate it completely. The infrastructure that produces tokens and maintains mapping remains in the PCI-DSS scope.

    What happens in case of violation?

    Card association (Visa, MC) penalty: 5K-100K USD/month; Turkish payment integrators may terminate the contract; KVKK article 12/5 violation notification 72 hours. Customer compensation cases are long.

    SAQ vs RoC difference?

    SAQ (Self-Assessment Questionnaire): Level 2-4. RoC (Report on Compliance): Level 1; Regulated by QSA.

    Relevant legislation

    • Law No. 6493 — Payment & electronic money; licensing, operating permit.
    • BRSA Regulations — Payment institution / EML permission, capital, reporting.
    • 5549 SKMASAK; KYC, STR, regular activity.
    • KVKK + GDPR — Data security, cross-border transfer.
    • PCI-DSS — Card storage; PCI level 1-4 compliance.
    Legal notice: This article is for general information purposes; A meeting with a lawyer is required for a concrete case. Durations, rates and practice are shaped by jurisprudence; Check the current legislation before applying.

    Kaynaklar ve referanslar

    Kaynaklar

    PCI-DSS Uyumu: Türkiye Fintech'leri için 12 Gereklilik Rehberi içeriği hazırlanırken resmi mevzuat ve yüksek yargı kaynakları esas alınmıştır.

    Telif bildirimi This content and all related Q&A texts are protected under Turkish Copyright Law No. 5846. Unauthorized copying, reproduction, publication, adaptation, bulk extraction, or commercial use is prohibited; legal and criminal remedies are reserved in case of infringement.

    Hukuki destek arıyorsanız

    Bu konuda profesyonel hukuki destek için Aycan Ceylan Avukatlık Bürosu olarak yanınızdayız.

    Görüşme Planla