Five Key Themes Emerging from the 2026 PCI SSC Community Meeting
Annual PCI Security Standards Council Community Meetings are the preeminent gathering of PCI experts, where the current and future challenges and learnings are shared and discussed. This year, the North American Community Meeting took place in Vancouver, Canada, consisting of two full days of content sharing and networking. The Community Meeting is especially notable as it is the 20th year anniversary of the PCI Council’s founding.
As discussions continue at this year’s Community Meeting, several clear themes are emerging that offer insight into where payment security is headed. While the topics span a wide range of technologies and assessment challenges, they collectively point toward an ecosystem that is becoming more automated, more interconnected, and increasingly influenced by artificial intelligence.
This year, several of Tevora’s PCI and Payments Industry experts attended. For those who were unable to attend, here is our summary of the five most salient themes that will influence PCI compliance for the coming year.
- AI Dominates the Conversation
No topic generated more discussion among attendees than AI.
Whether in formal presentations, assessor sessions, networking events, or hallway conversations, organizations are actively evaluating how AI impacts payment security, compliance activities, and PCI scope.
The discussions extend well beyond productivity benefits. Participants are examining how AI systems should be governed, how sensitive data can be protected when AI is involved, and how AI-enabled business processes can be introduced without creating unnecessary risk.
The release of the Security Considerations for AI Systems guidance during the conference further reinforced the importance of these conversations.
- Accountability Still Matters More Than Automation
A recurring message throughout the event is that automation does not eliminate accountability.
Organizations may use AI to assist with documentation, analysis, testing, quality assurance, and research activities, but responsibility for conclusions and decisions remains with qualified personnel.
This theme surfaced repeatedly in discussions surrounding assessment quality, governance, evidence preservation, and reporting practices.
As AI adoption accelerates, maintaining trust in security and compliance processes will continue to rely on clear human ownership and oversight.
- PCI Standards Are Evolving Alongside Technology
The release of new AI guidance illustrates the Council’s ongoing effort to address emerging technologies while maintaining the security objectives that underpin existing standards.
Conference discussions also highlighted the growing importance of industry collaboration in shaping future standards.
Attendees learned that more than 800 community comments were submitted as part of the PCI DSS v5.0 feedback process. While the next version of the standard remains in development, the volume of feedback demonstrates the industry’s continued commitment to collaborative standards evolution.
Rather than rushing change, the message from participants involved in the process is that feedback is being carefully reviewed to help inform future drafts.
- Modernization and Automation Are Gaining Momentum
Another key theme emerging from the conference is standards modernization.
Attendees showed significant interest in discussions surrounding OSCAL, machine-readable evidence, and more efficient approaches to exchanging assessment information.
For years, assessment preparation has largely relied on documents, screenshots, spreadsheets, and manual evidence collection. Emerging modernization efforts suggest the industry is beginning to explore more structured and potentially automated ways of sharing compliance information.
While these initiatives are still developing, they have the potential to improve consistency, reduce administrative effort, and enhance assessment efficiency over time.
- Shared Responsibility Is Becoming Increasingly Important
Payment environments continue to become more distributed and service oriented.
Cloud services, managed security platforms, hosted solutions, payment gateways, AI services, and specialized third-party providers now play critical roles across many payment ecosystems.
As these relationships evolve, organizations must clearly understand where responsibilities begin and end. Conference discussions reinforced the importance of identifying which parties own specific security obligations and ensuring those responsibilities are appropriately documented and understood.
In many respects, this represents one of the defining challenges of modern payment security: maintaining clear accountability within increasingly complex environments.
Looking Forward
The overarching theme from this year’s Community Meeting is evolution.
Artificial intelligence, automation, standards modernization, and increasingly interconnected service ecosystems are reshaping how organizations approach payment security. At the same time, the principles that have long supported effective security programs remain unchanged.
Protect sensitive data. Understand scope. Maintain accountability. Preserve evidence. Manage risk.
Looking ahead, the continued evolution of the PCI standards will be an important area for organizations to monitor. The PCI Security Standards Council is tentatively targeting Q2 2028 for publication of the final version of PCI DSS v5, providing the industry with a significant window to follow the development process, review emerging requirements, and prepare for potential changes to compliance programs.
For more insights on our insight on what we know, what we don’t and what could be coming with this update, dive into our blog here.
While the technologies continue to evolve, those fundamentals remain at the center of the industry’s efforts to secure payment environments for the future.
Tevora Can Help
Tevora’s experienced experts can answer any questions about meeting PCI and would welcome the opportunity to help you meet compliance standards. Give us a call at (833) 292-1609 or email us at [email protected].





