PCI DSS compliance: The route most NZ businesses miss

Kiwis are naturally resourceful. Kayak strapped to the car roof, chilly bin packed, trip funded by a sausage sizzle outside Bunnings, and enough confidence to figure the rest out along the way. But when it comes to PCI DSS compliance, that resourcefulness splits in three. Some businesses spend like they have hired a helicopter to fly a route they could have driven in a car. Others set off with no map, no fuel, and ‘all good, mate’ attitude. And some start the engine and never leave the car park.

One arrives having spent a fortune they did not need to. One never arrives at all. And one never gets moving.

There’s a smarter route. Most New Zealand businesses haven’t found it yet.

The part of my work I enjoy most? Showing businesses that smarter route. The one where your wallet and your reputation both stay intact.

The Route Nobody Talks About

Let’s be upfront – nobody likes to be told what to do (a.k.a. compliance); and PCI DSS is a compliance standard that applies to any organisation that stores, processes, transmits or impacts the security of cardholder data. Globally, compliance is enforced through the bank that processes your card payments, on behalf of brands like Visa and Mastercard. Non-compliance can lead to penalties.

But in New Zealand, PCI DSS compliance sits in a strange no-man’s land. Unlike larger markets where big enterprises drive compliance culture, 97% of New Zealand businesses are small. Enforcing a compliance standard across a market of that makeup has always been a challenge. Most of these businesses have never had anyone explain what PCI DSS actually means for an operation of their size. Meanwhile, card fraud and scam losses across New Zealand hit NZ$194 million in 2024 alone, with unauthorised card fraud up 32% in a single year.

The result?

Three patterns we keep seeing.

  1. The sledgehammer nut crackers: These businesses throw everything at PCI DSS compliance. Large consulting engagements, expensive tooling, entire IT environments treated as in-scope because nobody showed them how to reduce it. They are just making it bigger than it should be by paying three or four times what they should be. They hired a helicopter to go next door.
  2. Those that bring a knife to a gunfight: These businesses do the bare minimum, or nothing at all, betting that nobody will audit them. They save money in the short term, until a breach occurs, a payment brand imposes fines, or a key client demands proof of compliance they cannot provide. No map, no fuel, total confidence.
  3. The procrastinators: These are the businesses that know PCI DSS applies to them. Their bank has told them. Maybe a client has asked for their evidence of compliance. They start the process but drag their feet on implementation. Security recommendations sit in inboxes. Remediation timelines slip. Controls get documented on paper but never enforced in practice. They want to say they’ve been there without ever going. Everything is packed, engine is running, but they never leave the car park.

Different patterns, same result. Each one costs your business more than it should, whether that is in dollars spent today or in fines, breaches, and lost business tomorrow.

But here is the thing. None of these businesses set out to get it wrong. Whether you are starting your PCI journey or already deep into it, the difference between overpaying and getting it right usually comes down to one thing: whether anyone ever sat down and asked the right questions and helped to navigate from there.

That is where the route changes.

The Landscape is Shifting

For years, most New Zealand businesses have operated without anyone seriously questioning their PCI DSS compliance. That is starting to change. Visa has launched a dedicated three-year Security Roadmap for New Zealand. For many businesses, this will be the first time PCI DSS lands on their radar.

The frustration we hear most often from New Zealand businesses is not about whether PCI DSS matters. It is about navigating it. The validation path depends on how your payments are set up, how your network is built, and where cardholder data flows. But it also depends on understanding which of the standard’s requirements apply to your specific environment and how they should be implemented. Get either side wrong and you end up doing too much, too little, or the wrong things entirely.

How you approach it matters more than what you spend on it. The right approach means decisions that fit your business: segmenting your network to reduce your compliance scope, choosing the right validation path for your payment setup, and building a programme around how your business actually works.

For businesses that have not started, that removes the uncertainty. For those already on the journey, it often reveals that the path can be shorter and less costly than what they have been told. And for those stuck between intention and action, it provides the momentum and technical guidance to turn documentation into real working controls.

Done right, PCI DSS compliance does not just protect your business. It positions it. It safeguards your ability to accept card payments, which for most businesses means your ability to trade. It protects your reputation with customers who trust you with their card data. It reduces your financial exposure to breach costs, and penalties.

Cyber insurers are factoring PCI DSS compliance into underwriting decisions before they will cover you. Partners are requesting evidence of compliance before working with you. And the foundation you build, covering network security, access controls, encryption, monitoring, and incident response, does not just satisfy PCI DSS. It positions your business for whatever compliance framework comes next. Globally, expectations around how businesses protect payment card data are getting stricter, not softer. New Zealand’s turn is coming. The question is whether you build for it now while you have the choice or pay a premium later when you don’t.

If any part of this blog made you think “that sounds like usget in touch. As a QSA, I help organisations across Aotearoa navigate the full PCI DSS compliance journey, from scoping and strategy through to assessment and ongoing support. Let’s find your smarter route.

PCI DSS road ahead