Knowledge center
Is PCI DSS mandatory in Mexico?
PCI DSS is expressly referenced in regulation applicable to credit institutions for certain electronic-banking services. For merchants, the requirement usually arrives through an acquirer, aggregator, processor, gateway, payment brand, contract or requesting party.
Why it matters
The Resolution published in Mexico’s Official Gazette on November 27, 2018 refers to payment-card industry security certifications, including PCI DSS, in Article 316 Bis 10(V). That provision is directed at credit institutions and does not, by itself, create a direct general legal obligation for every Mexican merchant. Application and validation depend on the real payment environment and requester.
What to confirm
- Who requests PCI DSS and the contractual basis
- Actual payment model and providers
- Required document and validation method
Mexico Official Gazette, Resolution dated November 27, 2018, Article 316 Bis 10(V) · Official resolution · reviewed 2026-07-31
This content is informational and is not legal advice. The applicable route and validation method depend on the operation and requesting party.