Background: The Payment Card Industry Data Security Standard (PCI-DSS) was created to increase controls around cardholder data to reduce credit card fraud via its exposure. From nearly the beginning of its introduction, the standard has been criticized for the expense associated with annual certification and for security being less than advertised. The recent increase in public data breaches has underlined concerns around whether the investment required provides the level of security needed.