Skip to content
farel-logo
Blog
News

PCI DSS compliance for airlines: certified for another year

Farel team
Written by Farel team

4 min read

Farel's PCI DSS Level 1 certificate of compliance for version 4.0.1, issued by ControlCase on 12 September 2026 and valid to 11 September 2027.

Key takeaways

  • Farel, a cloud-native airline operating system, was certified PCI DSS Level 1 against version 4.0.1 for the second year running, assessed by ControlCase, a Qualified Security Assessor certified by the PCI Security Standards Council. The Report on Compliance is dated 12 September 2026.
  • The certificate runs to 11 September 2027. Level 1 has to be revalidated every year by an outside assessor, not self-assessed.
  • PCI DSS (Payment Card Industry Data Security Standard) is the rule set for how card data is stored, processed and moved.
  • Card storage and processing for airlines on Farel sit inside Farel's audited environment, so the assessment scope sits with Farel.
  • Because card data stays inside that environment, Farel's payment form is embedded directly in the booking flow on the website and mobile apps, with no redirect to a payment provider.
  • Airline partners pay nothing for it. Recertification is part of running the platform.

Every airline that sells direct has a card data question it can't hand off by accident. If the platform behind your booking flow isn't independently certified, the evidence gathering, the assessor invoice and the awkward part of the conversation with your acquirer all land on your team.

Farel passed its PCI DSS Level 1 assessment for the second year in a row. ControlCase issued the Report on Compliance on 12 September 2026, against version 4.0.1 of the standard. The certificate is valid to 11 September 2027.

What does PCI DSS compliance for airlines actually cover?

Level 1 is the top validation tier, and the only one that requires an on-site audit by an external Qualified Security Assessor every year rather than a self-assessment questionnaire. The assessor tests the whole cardholder data environment: encryption, key handling, access control, logging, vulnerability management, and the payment pages themselves.

Version 4.0.1 is now the only active version of the standard, and the 51 future-dated requirements introduced in v4.x stopped being best practice and became mandatory on 31 March 2025. That includes multi-factor authentication on every account that touches the cardholder data environment, script inventories on payment pages, and tamper detection. Any assessment after that date scores them in full, with no grace period.

Why does it matter which company holds the certificate?

Because PCI scope follows the card data. Tokenized cards, 3-D Secure, PSP connections and stored cards for returning passengers all run inside Farel's payments module, which means that environment is what gets audited. Airlines selling direct on Farel, like Asman Airlines, don't stand up their own card vault or commission their own Level 1 assessment of it.

What does holding the certificate let an airline's checkout do?

Keep the card form inside the booking flow. Because card data is handled inside Farel's certified environment, the payment form sits on the booking details page of the airline's website and mobile apps. No handoff to a payment provider's page, no return trip, no third-party design in the middle of your checkout.

Farel's card payment form embedded in the booking details page, with card number, expiry, CVC and name fields and a PCI DSS compliance badge under the pay button.

Every redirect is a place to lose a passenger. A new domain, a page that loads slowly, a banking app that opens and doesn't come back. Airlines running direct sales on Farel convert 11-14% of bookings, several times the usual direct-booking rate in the industry.

There is nothing dramatic in a second-year assessment, and that's the point of it. The first Level 1 audit is the expensive one, where you build the controls. The second is mostly proving nothing quietly drifted over twelve months: logs, screenshots, policy documents and evidence requests, and then a PDF. The certificate expires on 11 September 2027, so the next round starts roughly now. The day PCI compliance gets interesting for an airline is the day something has already gone wrong.

Second certification we've written up this year. The first one took 18 builds and a wall of airport printers. This one took spreadsheets.

If you're comparing platforms, ask every vendor for their current certificate or Attestation of Compliance and check two things: the version of the standard, and the date. Plenty of documents in circulation are validated against a version that no longer exists. Book a demo and we'll walk you through ours.

Share

The Latest & Greatest

We love sharing our journey with you. Here, we regularly share our insights, Farel happenings, customer success stories, challenges, and all things to help airlines grow and succeed.