---
title: New Guidance: PCI DSS for Large Organizations
description: "PCI Security Standards Council has published a new Information Supplement: PCI DSS for Large Organizations. This document was produced by the 2019 Special Interest Group (SIG), whose members provided their expertise and shared experience of managing PCI DSS assessments in large organizations. "
image: https://blog.pcisecuritystandards.org/hubfs/best-practices-pci-dss-large-organizations-v3.jpg
---

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/new-guidance-pci-dss-for-large-organizations#)

# [New Guidance: PCI DSS for Large Organizations](https://blog.pcisecuritystandards.org/new-guidance-pci-dss-for-large-organizations)

 Posted by [Lindsay Goodspeed](https://blog.pcisecuritystandards.org/author/lindsay-goodspeed) on 20 Feb, 2020 in [PCI DSS](https://blog.pcisecuritystandards.org/topic/pci-dss) and [Compliance](https://blog.pcisecuritystandards.org/topic/compliance) and [SIGs](https://blog.pcisecuritystandards.org/topic/sigs) and [BAU](https://blog.pcisecuritystandards.org/topic/bau) and [Resource Guide](https://blog.pcisecuritystandards.org/topic/resource-guide)

![best-practices-pci-dss-large-organizations-v3](https://blog.pcisecuritystandards.org/hs-fs/hubfs/best-practices-pci-dss-large-organizations-v3.jpg?width=800&name=best-practices-pci-dss-large-organizations-v3.jpg "best-practices-pci-dss-large-organizations-v3")

<https://www.linkedin.com/shareArticle?mini=true&url=https://blog.pcisecuritystandards.org/new-guidance-pci-dss-for-large-organizations>

<https://www.facebook.com/share.php?u=https://blog.pcisecuritystandards.org/new-guidance-pci-dss-for-large-organizations>

<https://twitter.com/intent/tweet?original_referer=https://blog.pcisecuritystandards.org/new-guidance-pci-dss-for-large-organizations&url=https://blog.pcisecuritystandards.org/new-guidance-pci-dss-for-large-organizations&source=tweetbutton&text=New%20Guidance: PCI%20DSS%20for%20Large%20Organizations> 

[mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/new-guidance-pci-dss-for-large-organizations](mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/new-guidance-pci-dss-for-large-organizations)

PCI Security Standards Council has published a new Information Supplement: PCI DSS for Large Organizations. This document was produced by the 2019 [Special Interest Group (SIG)](https://www.pcisecuritystandards.org/get_involved/special_interest_groups), whose members provided their expertise and shared experience of managing PCI DSS assessments in large organizations.

Often the larger an organization becomes, the more interconnected and complex its relationships with internal business units and third parties become. As a result of this complexity, large organizations may need to evolve their approaches for implementing and maintaining PCI DSS controls across the entire organization. The document provides guidance and suggestions that cover a range of business considerations, including:

- Roles, responsibilities, and ownership of PCI DSS functions
- Sustaining compliance
- Mergers and acquisitions
- Managing acquirers and payment channels
- Education and awareness
- Systems management to maintain PCI DSS compliance
- Multiple audits and assessment
- Laws, regulations, and standards

Read the information supplement [here](https://www.pcisecuritystandards.org/document_library?category=large&document=large).

This information supplement is a result from a PCI SSC Special Interest Group. Special Interest Groups (SIGs) are community-driven initiatives that focus on payment security challenges related to PCI Security Standards. SIGs promote the collaboration between industry representatives, subject matter experts, the Council and the Payment Brands to allow the development of practical payment security resources.

***Note:** *Although the information in the SIG document is principally intended for large organizations, entities of all sizes may find the information valuable. The material provided in this document is supplemental and does not supersede or replace any PCI DSS requirements. *<https://blog.pcisecuritystandards.org/information-supplement-best-practices-for-maintaining-pci-dss-compliance>

[![View the New Guidance: PCI DSS for Large Organizations](https://no-cache.hubspot.com/cta/default/281302/964f46fe-8abe-41da-93b8-74143c53e5f3.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/964f46fe-8abe-41da-93b8-74143c53e5f3)

 

### LIKE WHAT YOU READ?

Subscribe to the PCI Perspectives blog to receive insights, information and practical resources to help your organization protect payment data.

[Subscribe Here](https://training.pcisecuritystandards.org/subscribe-to-pci-perspectives-blog)

![Lindsay Goodspeed](https://blog.pcisecuritystandards.org/hubfs/Headshots/lindsay-goodspeed.jpg)

[ Lindsay Goodspeed ](https://blog.pcisecuritystandards.org/author/lindsay-goodspeed)

[Twitter ](https://twitter.com/PCISSC) [LinkedIn](https://www.linkedin.com/in/lindsaygoodspeed) [Email](mailto:blog@pcisecuritystandards.org) [Website](https://www.pcisecuritystandards.org/)

 As Senior Manager, Corporate Communications for the Council, Ms. Goodspeed drives awareness of PCI Security Standards and resources for the protection of payment card data.

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/new-guidance-pci-dss-for-large-organizations#)