Application

PCIComplianceHubLast updated

Any software program or group of programs an entity runs, whether bought, custom-built or bespoke, and whether internal or external-facing such as a website. In PCI DSS the word covers everything from a point-of-sale package to a public web application.

Applies to. Every application on an in-scope system component. Bespoke and custom software carries extra requirements in 6.2 and 6.3; public-facing web applications carry 6.4.
Example. A merchant runs a bought inventory system, a custom order-management service, and a public checkout site. All three are applications; only the second is bespoke software under 6.2, and only the third is a public-facing web application under 6.4.
Limits. How an application was acquired decides which controls apply, not whether any do. Bought software still has to be patched (6.3.3) and its vulnerabilities tracked (6.3.1); custom software must also be developed securely (6.2). An application that never touches account data can still be in scope if it runs on a system that does or can affect its security.
In PCI DSS v4.0.1. 6.2.1, 6.3.1, 6.3.3, 6.4.1