I use a PCI compliant terminal, POS system, or payment application does that make me PCI DSS compliant?
No, though using PCI compliant devices and software is certainly a good first step towards complying with the PCI DSS.The term “PCI compliant”, when used to describe a specific device or software application, is likely referring to that device or software complying with either the PCI PIN Entry Device (PED) standard or Payment Application-Data Security Standard (PA-DSS), respectively.These standards support, but do not satisfy merchants’ efforts to comply with the PCI DSS by allowing them to choose from PCI certified payment application software and PIN entry devices.Even if a merchant uses PCI compliant devices or software, it must still actively comply with PCI DSS requirements covering the physical security of cardholder data (Requirement 9) and the need for merchants to maintain an information security policy (Requirement 12).