If your business takes card payments, PCI DSS applies to you, whether you process one card a week or thousands. It sounds like a job for a big IT department, but for most small businesses it comes down to a questionnaire and a few sensible habits. This guide explains what PCI DSS is, what you actually have to do, and what happens if you ignore it.
In short. PCI DSS is the card industry security standard that every business taking cards must follow. For most small firms, compliance means completing a yearly self assessment questionnaire and following basic security steps. Skipping it does not just risk a breach, it can also mean a non compliance fee from your provider every month.
PCI DSS stands for the Payment Card Industry Data Security Standard. It is a set of security requirements created by the major card schemes to protect cardholder data from theft and fraud. It is not a law, but it is a condition of being allowed to take card payments, written into your agreement with your provider, so in practice it is not optional.
The standard is built around a set of goals, from protecting stored data and encrypting transmissions to controlling who can access systems and testing security regularly. How much of it applies to you depends on how you take payments.
For most small businesses the practical requirement is a Self Assessment Questionnaire, or SAQ, completed once a year. Which SAQ you complete depends on how you handle card data.
SAQ A. For businesses that outsource all card handling, such as an online shop using a hosted payment page. The shortest and simplest.
SAQ B. For businesses using standalone card machines with no electronic storage of card data. Common for shops and trades.
SAQ C. For businesses with payment systems connected to the internet, such as an integrated till.
SAQ D. The most detailed, for businesses that store card data or do not fit the simpler categories.
Whichever questionnaire you complete, the underlying steps are practical.
✓ Never write down or store full card numbers, and never send them by email.
✓ Use strong, unique passwords and change any default ones on card devices and systems.
✓ Keep terminals, tills and software up to date and patched.
✗ Storing card details in a spreadsheet, notebook or inbox, a common and serious mistake.
✗ Sharing one login across all staff, which removes any trail if something goes wrong.
The obvious reason is security. A card data breach is expensive, damaging to trust, and can bring fines. But there is a second reason that catches businesses out. Many providers charge a monthly non compliance fee if you have not completed your PCI assessment, quietly added to your statement until you sort it. That fee is pure waste, paid for doing nothing, and it is entirely avoidable by completing the questionnaire your provider gives you.
Check your card processing statement for a PCI or non compliance charge. If you see one, it usually means your yearly assessment has lapsed. Completing it removes the fee and, more importantly, confirms you are handling card data safely.
1. Find your provider portal. Most acquirers give you an online PCI portal with the right questionnaire for how you take payments.
2. Complete the SAQ. Answer honestly, and use it as a checklist to fix anything that is not yet in place.
3. Fix the basics. Change default passwords, stop storing card numbers, keep devices updated, and limit access.
4. Renew every year. PCI compliance is annual, so diarise it, and check your statement to confirm any non compliance fee has gone.
Behind the questionnaire, PCI DSS is organised around a set of control goals, and it helps to know what they cover even if a portal walks you through them. In broad terms you are asked to protect the network your payments run on, protect any cardholder data you hold, guard against malware and keep software patched, restrict access to card data to the people who need it, and monitor and test your security regularly.
For a small shop taking cards on a standalone terminal, most of this is handled by the terminal and the provider, which is why your questionnaire is short. The moment you start storing card details, integrating a till with other systems, or taking payments through your own website, more of those goals fall to you, and the questionnaire gets longer to match. Understanding that link between how you take payments and how much you must do is the key to keeping compliance simple.
Yes. Any business that takes card payments must comply, regardless of size. The difference is that smaller firms usually only need to complete a self assessment questionnaire.
A Self Assessment Questionnaire. It is the yearly form that confirms how you take card payments and that you follow the required security steps. The version you use depends on your setup.
It is not a law, but it is written into your agreement with your card provider, so taking cards without complying breaches that contract and can bring fees.
A monthly charge some providers add when your PCI assessment has not been completed. It is avoidable by finishing your questionnaire, so check your statement for it.
Every year. Compliance is not one and done, so set a reminder to renew your assessment annually and keep the underlying habits in place year round.
The card schemes set the standard and your provider enforces it through your agreement, rather than a government regulator. In practice that means non compliance fees while your assessment lapses, and potential penalties from the schemes if a breach exposes card data you should have protected.