Payments
PCI DSS
The card industry security standard governing how card data is handled. Most subscription businesses aim to stay in the lightest scope.
PCI DSS is the Payment Card Industry Data Security Standard. Scope depends on how card data touches your systems, and the practical goal for almost every software business is to minimise it.
Using a hosted payment field and storing only a token generally keeps you in the lightest self-assessment tier. Accepting a card number in your own form, or worse taking one over the phone into your own systems, escalates scope dramatically and permanently.
Compliance is an annual exercise, not a one-off, and the standard applies to your vendors as well, which is why sub-processor lists matter to procurement teams.