The Challenge
A multinational payment processor's compliance team found a problem during a routine gap assessment: their Brazilian acquirer partner had implemented network segmentation controls that didn't align with PCI DSS Requirement 1.2.1. The partner's security architect had used what seemed like official guidance, but it was actually a community forum post, poorly translated and outdated.
This isn't rare. When compliance resources are only in English, or when translated materials are hard to find, teams use whatever they can find. Sometimes that's accurate, but often it's not.
The PCI Security Standards Council faced this issue on a large scale. Their language microsites, available in Chinese, French, German, Japanese, Spanish, and Portuguese, offered translated content, but the structure was lacking. Users couldn't efficiently search the Document Library for translated resources. Navigation didn't match the English site, and core sections were missing or inconsistent. This meant compliance teams in non-English-speaking regions spent more time searching for guidance than implementing it.
The Environment and Constraints
The PCI SSC, like many regulatory bodies, can't just translate everything. Some resources don't have official translations. New documents are published in English first. Certain technical annexes reference English-language standards without equivalent localized versions.
This creates a structural problem. If your microsite architecture treats translation as a simple mirror of the English site, you end up with broken links, incomplete sections, and user confusion when a document exists in English but not in the user's language. If you remove everything that isn't translated, you create gaps that force users back to English, or worse, to unofficial sources.
Feedback from the PCI Board of Advisors highlighted these usability issues. Compliance teams reported difficulty locating translated versions of documents they knew existed. The Document Library lacked effective search and filtering by language. The microsite structure didn't match the English site, so users familiar with one couldn't navigate the other efficiently.
For a standards body serving global payment ecosystems, this friction carries risk. A QSA in São Paulo shouldn't have to guess whether the Portuguese guidance they found is current. A security manager in Tokyo shouldn't need to cross-reference English and Japanese versions to confirm alignment. When the path to authoritative resources includes unnecessary obstacles, compliance quality suffers.
The Approach Taken
The PCI SSC redesigned the microsites with a focus on structural consistency and improved resource discovery. The Document Library was reorganized so users can search and filter documents by their translated language. This addresses the core workflow: a compliance professional needs to find the Portuguese version of the PCI DSS Quick Reference Guide without manually scanning every document listing.
The microsites now follow a standardized structure aligned with the English site. Sections like Get Involved, Standards, About, and Resources, including the PCI DSS Glossary, appear consistently across languages. Where content hasn't been translated, the structure accounts for this explicitly rather than creating navigation dead ends.
This approach reflects a specific architectural decision: consistency matters more than completeness. It's better to show a user that a resource exists only in English than to hide its existence entirely. The standardized structure means a compliance manager who uses the English site can navigate the Japanese microsite without relearning the information architecture.
The language selector moved to the upper-right corner of the main website, making language switching a persistent option rather than a buried setting.
Results and Metrics
The redesigned microsites delivered measurable improvements in resource accessibility. Users can now locate translated documents through structured search and filtering rather than manual browsing. The standardized navigation reduced the cognitive load of switching between languages, a compliance team working across multiple regions no longer encounters different information architectures for each language.
The inclusion of key sections like the PCI DSS Glossary in translated microsites addresses a specific compliance need: terminology consistency. When your security team in Madrid and your development team in Barcelona both reference "entorno de datos de titulares de tarjetas," they're using the same official term for Cardholder Data Environment. This reduces misalignment in scoping exercises and control implementation.
The enhanced structure also improved transparency around translation coverage. Users can see which resources have been translated and which exist only in English, eliminating the uncertainty that previously drove teams to unofficial sources.
What They Would Do Differently
The PCI SSC's approach suggests they prioritized structural improvements over expanding translation coverage, a practical choice given resource constraints. A different approach might have focused on translating more documents before redesigning the microsites, but that would have left the navigation and discovery problems in place.
One area for future iteration: version control visibility. When a document updates in English before the translated version is available, users need clear indication of which version the translation reflects. This is particularly critical for PCI DSS itself, where requirement changes have compliance implications.
Another opportunity: localized examples in guidance documents. Translating text is necessary but not sufficient. A code example showing Rendering PAN Unreadable in a Python script translates mechanically, but a compliance scenario describing US merchant categories may not resonate with a European acquirer. Localizing examples to reflect regional payment flows and regulatory contexts would increase practical utility.
Takeaways for Your Team
If you're managing compliance across multiple regions, the PCI SSC's redesign offers a framework for thinking about resource accessibility:
Consistency beats completeness. Don't hide resources that aren't fully translated. Show users what exists, even if some content remains in English. This prevents teams from assuming a resource doesn't exist when it's simply not translated yet.
Structure your Document Library for filtering. Your compliance team shouldn't need to know the exact document title to find translated guidance. Implement search and filter capabilities that let users narrow by language, document type, and topic.
Align navigation across languages. If your compliance portal has different structures for different languages, you're forcing users to learn multiple systems. Standardize the information architecture so regional teams can navigate efficiently.
Make terminology consistent. If you're operating in multiple languages, maintain a glossary that defines standard terms in each language. This is particularly important for scoping exercises where misaligned terminology leads to gaps in CDE identification.
Plan for version lag. English resources will update before translations catch up. Build workflows that flag when a translated document is behind the current English version, so teams know they're working from older guidance.
The broader lesson: compliance friction compounds. Every extra step between a compliance professional and authoritative guidance increases the likelihood they'll use unofficial sources, outdated information, or personal interpretation. For a global standards body, reducing that friction isn't just user experience, it's risk management.



