The PCI Security Standards Council (PCI SSC) has published a document which maps the PCI Data Security Standard (PCI DSS) v4.0.1 to the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0. With both organizations sharing the common goal to enhance data security, this document provides a resource for stakeholders to use in understanding how to align security efforts to meet objectives in both PCI DSS and the NIST CSF.
In this blog, we interviewed Chelsea Lopez, Client Engagement Operations Director at PCI SSC, to discuss how meeting PCI DSS requirements can help toward achieving NIST CSF outcomes for secure payment environments.
1. Tell us a little about the mapping document published by PCI SSC.
Chelsea Lopez: This is a really great example of our PCI SSC community coming together to build something by the industry, for the industry. This effort represents an update to work that PCI SSC published in 2019, mapping the previous versions of these two sets of security controls.
The PCI DSS v4.0.1 to NIST Cybersecurity Framework 2.0 mapping document was developed by the PCI SSC Board of Advisors as a tool to support organizations’ security control management efforts. Recognizing that both PCI DSS v4.0.1 and NIST CSF 2.0 share the common goal of strengthening and enhancing data security, the mapping document provides a practical resource for stakeholders to use in understanding how to align security efforts to meet objectives in both PCI DSS and NIST CSF.
2. What are the primary differences between PCI DSS and the NIST Cybersecurity Framework?
Chelsea Lopez: NIST CSF helps organizations manage cybersecurity risk by defining high-level cybersecurity outcomes rather than prescribing specific controls. It provides a common structure for understanding, assessing, prioritizing, and communicating cybersecurity risks. It can be used by any organization to better understand, assess, prioritize, and communicate its cybersecurity efforts.
PCI DSS defines security requirements specific for the protection of payment data. PCI SSC also provides supporting validation and guidance documentation to help organizations understand the intent of the requirements. PCI DSS is designed to protect environments for organizations that are involved in storing, processing, or transmitting payment data.
3. Are PCI DSS requirements and the NIST Cybersecurity Framework interchangeable?
Chelsea Lopez: Both PCI DSS and NIST CSF are solid security approaches that address common security goals and principles as relevant to specific risks. While NIST CSF identifies general security outcomes and activities, PCI DSS provides specific direction and guidance on how to meet security outcomes for payment environments. When used together, PCI DSS and NIST CSF can provide a holistic approach to managing cybersecurity risk. Because PCI DSS and NIST CSF are intended for different audiences and uses, they are not interchangeable, and neither one is a replacement for the other.
4. How should stakeholders engage with the mapping document produced by PCI SSC?
Chelsea Lopez: Stakeholders can use this mapping to identify opportunities for control reporting efficiencies and greater alignment between organizational security objectives. For example, the mapping can help identify where the implementation of a particular security control can support both a PCI DSS requirement and a NIST Cybersecurity Framework outcome. Additionally, an entity’s internal evaluations to determine the effectiveness of implemented controls may help the entity prepare for either a PCI DSS or NIST Cybersecurity Framework assessment, or both. As a reminder, organizations should always consult with their internal security and legal counsel to determine what security requirements may be applicable to their organization.
5. Where can stakeholders find additional resources regarding mapping PCI DSS to the NIST Cybersecurity Framework?
Chelsea Lopez: We have a variety of helpful resources available on the PCI SSC website, including a one-page Executive Brief, an At-A-Glance Summary document, and the full mapping document. These are now available in our Document Library and linked below for easy access.




