ISO asks for a system. PCI asks for specific controls.
ISO 27001 centers on an ongoing risk-management system; PCI-DSS's highest-leverage move is architectural — never touch raw card data at all.
ISO 27001
An ISMS, not a checklist
An ongoing process of risk assessment and treatment, selecting from ~93 Annex A controls based on your own risk profile.
PCI-DSS
12 requirements, 6 goals
Applies to anyone who stores, processes, or transmits credit card data.
Flat network
Every service can reach the payment component → entire infrastructure in PCI scope.
Segmented + tokenized
Only the payment service touches card data → SAQ A, dramatically less scope.
The cheapest way to comply with PCI-DSS is often architectural: tokenize through a compliant processor and never touch raw card data yourself.