If your organisation processes and/or transmits credit card payments, or stores cardholder data, it’s likely that you’re familiar with the acronym PCI DSS, also known as the Payment Card Industry Data Security Standard (PCI DSS). It’s a set of rules designed to protect payment data and maintain your organisation’s security posture. The PCI DSS is split into twelve requirements.

Requirement 5 is all about malware: stopping it, controlling it, and making sure your systems aren’t a playground for hackers.

Let’s break down what PCI Requirement 5 asks of you, why it matters, and how to get it right.

 

What Does PCI DSS Requirement 5 Say?

At its core, Requirement 5 says, “Protect all systems against malware and regularly update anti-virus software or programs.” In plain English, this is about making sure malicious software – such as viruses, ransomware, spyware – can’t sneak into your systems and compromise cardholder data.

On paper, it sounds straightforward. But the devil is in the details, and compliance means more than installing a free antivirus program and calling it a day.

 

Why Is PCI DSS Requirement 5 Important?

Malware is one of the biggest threats to any business that handles payment data. A single infected workstation or server can give attackers a foothold, letting them steal card numbers or install ransomware that locks you out of your systems. PCI DSS Requirement 5 exists because real-world breaches almost always start with something small, like a phishing email, malicious attachment, or a drive-by download from an unpatched website. Standard-issue antivirus alone isn’t enough anymore, but it’s an essential first step.

 

The Key Pieces of PCI Requirement 5

Here is a breakdown of PCI Requirement 5 – including all the sub-requirements – and what they actually mean:

PCI Requirement 5.1: Deploy Anti-malware Protections On All Systems Prone to Malware.

PCI 5.1.1 – Identify Malware-Susceptible Systems

Determine all system components commonly affected by malware.

PCI 5.1.2 – Deploy Anti-Malware Mechanisms

Implement tools capable of detecting and protecting against all known malware types on identified systems.

If a system can run malware, you need anti-malware. This covers all endpoints—workstations, laptops, and even some servers. For systems that aren’t commonly affected (think: Linux servers running only internal apps), you need to document why, and have a process for reviewing that decision regularly.

 

PCI Requirement 5.2: Keep Malware Definitions Up to Date

5.2.1 – Keep Anti-Malware Mechanisms Active and Current

Ensure anti-malware solutions are updated, continuously running, and protected from tampering.

5.2.2 – Document Exceptions

If anti-malware cannot be used, document the justification and implement alternative security controls.

It’s not enough to install an antivirus once and forget about it. You need to make sure the software is updated automatically with the latest signatures, so it can detect new threats as they emerge. Remember: Outdated antivirus software is useless!

 

PCI Requirement 5.3: Perform Regular Scans

Anti-malware tools should be set to scan files, programs, and memory regularly—at least once a week, and ideally more often. If a scan detects something nasty, there needs to be a documented process for dealing with it.

 

PCI Requirement 5.4: Generate and Review Anti-Malware Logs

5.4.1 – Implement Technical Anti-Phishing Controls

Use email filters, web proxies, and DNS filtering to detect and block phishing attempts.

5.4.2 – User Awareness and Training

Educate users to recognise and report phishing attempts during onboarding and at regular intervals.

5.4.3 – Monitor and Respond to Phishing Reports

This new requirement enhances an organisation’s ability to respond to phishing attempts reported by users by creating a feedback loop that is integrated into incident response and threat intelligence processes.

You have to log anti-malware activities and review those logs. If the software finds malware, you need to know about it (and act on it). This is about closing the feedback loop—detection is pointless if nobody’s watching.

 

PCI Requirement 5.5: Address Evolving Threats (Advanced Malware)

Modern malware can bypass traditional anti-virus. That’s why PCI DSS 4.0.1 (the latest version) pushes businesses to consider more advanced anti-malware solutions—think endpoint detection and response (EDR), behavioural analysis, and other next-gen tools—especially if you’re handling lots of cardholder data or are a more attractive target.

 

Best Practices for Meeting PCI Requirement 5

Automation: Automate everything by scheduling scans and updates to ensure nothing is overlooked. Manual processes are easy to forget.

Use centralised management: If you’re a larger business, manage anti-malware from a central dashboard. Such an arrangement makes it easier to see what’s happening and push out updates.

Test Your Defences: Run periodic tests to make sure malware detection and response processes work. Don’t wait for a real attack to find out you have gaps.

Document Exceptions: If you’re not running anti-malware on certain systems, document why and review that decision at least annually.

Train Your Staff: Human error is still the biggest risk. Teach employees how to spot suspicious emails and report anything strange, and remind them regularly.

 

Common Pitfalls – What Organisations Get Wrong When Addressing PCI Requirement 5

Set-and-Forget Mentality: Simply installing antivirus software once and then leaving it unattended can lead to significant problems. Make sure updates and scans are happening, and check the logs.

Ignoring Servers: Malware doesn’t just target desktops – servers are juicy targets too, especially those handling payment data.

Skipping Documentation: In a PCI audit, if it’s not documented, it didn’t happen. Keep records of updates, scans, and incident responses.

 

PCI DSS Requirement 5 is not just about ticking a compliance box. It’s about building a proactive and sustainable defense against malware and phishing threats. As attackers evolve, so must your security strategy.

If your organisation is unsure how to implement these controls—or needs help selecting the right tools – engaging a trusted security advisor is a wise step. Maintaining compliance is important, but protecting your customers’ data is even more critical.

If you’d like expert advice and guidance to help your organisation comply with PCI DSS Requirements, get in touch with our team to book a complimentary security review.