PCI DSS
The Payment Card Industry Data Security Standard: mandatory requirements for any system that stores, processes or transmits cardholder data. Non-compliance can mean fines or loss of the ability to process card payments.
How to read the references
PCI DSS references are requirement numbers, nested under the standard's 12 top-level requirements, 8.2.1 means Requirement 8 › 2 › 1 (Requirement 8 = identify users and authenticate access to system components). Some references keep the Req- prefix, e.g. Req-2.2.4, and the deepest ones point at a specific testing procedure, e.g. 10.2.5.b.
Pavois maps to PCI DSS 4.0.1, the current version. PCI DSS applies to any system that stores, processes or transmits cardholder data.