PCI DSS isn't regulation. It's a standard promulgated by a private LLC (the Payment Card Industry Security Standards Council).
HIPAA would be a much better example of regulation that is material w/ respect to software development.
HIPAA would be a much better example of regulation that is material w/ respect to software development.