PCI DSS Compliance in the UAE

Take card payments in the UAE? PCI DSS applies to you — and it is one of the few standards that explicitly requires penetration testing. Here is what that means in practice.

VAPT services in Dubai and the UAE by Rootsec

What is PCI DSS?

PCI DSS — the Payment Card Industry Data Security Standard — applies to every organisation that stores, processes or transmits cardholder data: e-commerce, retail, hospitality, fintech. It is enforced through your acquiring bank, and in the UAE acquirers are increasingly strict about evidence. The standard is maintained by the PCI Security Standards Council.

PCI DSS explicitly requires penetration testing

Requirement 11 mandates regular security testing: internal and external penetration testing at least annually and after significant changes, plus segmentation testing if you rely on network segmentation to reduce scope. This is one of the few frameworks where a pentest is not “best practice” but a written requirement.

Your PCI DSS testing checklist:

  • External and internal penetration test of the cardholder data environment — annually
  • Segmentation test proving your CDE is genuinely isolated
  • Quarterly vulnerability scans (ASV for external)
  • Retest after remediation, with evidence

Reducing your PCI scope (and cost)

The cheapest cardholder data environment is a small one. Tokenisation, hosted payment pages and real network segmentation shrink what needs testing — we routinely help clients cut their PCI testing scope before quoting, which usually saves more than the test costs.

Related guides and services

Frequently asked questions

Quick answers on card-payment security.
Does PCI DSS require penetration testing?

Yes — Requirement 11 mandates internal and external penetration testing at least annually and after significant changes, plus segmentation testing where applicable.

Who enforces PCI DSS in the UAE?

Your acquiring bank enforces it contractually; non-compliance risks fines and losing the ability to process cards.

What is a segmentation test?

A test proving that your cardholder data environment is genuinely isolated from the rest of your network, so your PCI scope stays small.

How can I reduce PCI DSS costs?

Shrink the cardholder data environment: tokenisation, hosted payment pages and real segmentation reduce what must be tested and audited.

Next step

Need your PCI DSS penetration test?

Book a free 30-minute strategy call. You get clarity on scope, approach and a fixed price — no obligations.