Home / Resources / What is PCI compliance?
Payments 101If you take credit cards, you've almost certainly seen "PCI compliance" on your statement — sometimes attached to a fee. Here's what it actually is in 2026, whether a small business really has to bother with it, and the simplest way to satisfy it without turning your shop into a security project.
PCI compliance means following the Payment Card Industry Data Security Standard (PCI DSS) — a set of security rules every business must meet to accept Visa, Mastercard, Discover, or Amex. And yes, your small business almost certainly needs it: the standard applies to anyone who accepts, processes, stores, or transmits card data, with no exemption for being small. The good news is that most small merchants don't need a formal audit. You validate by completing a short Self-Assessment Questionnaire once a year and keeping a few basic security practices in place. Do it right and it's mostly paperwork; ignore it and it can cost you a monthly fee — or a great deal more if you're ever breached.
PCI DSS is a global security standard maintained by the major card networks, not a government law. As of 2026 the active version is PCI DSS v4.0.1, and the future-dated requirements that were "best practice" under v4.0 became mandatory on March 31, 2025 — so the rules you're held to today are stricter than they were a couple of years ago. The standard is built around 12 core requirements, grouped into common-sense buckets: build and maintain a secure network (firewalls, no default passwords), protect stored cardholder data, encrypt data in transit, use and update anti-malware, restrict access to card data on a need-to-know basis, track and monitor access, and maintain a written security policy. A newer emphasis in v4.0.1 is treating security as continuous rather than a once-a-year scramble — controls are expected to be in place and demonstrable all year, including managing the scripts on any e-commerce checkout page so card data can't be skimmed.
There's a stubborn myth that PCI is only for big retailers. It isn't. The standard sorts merchants into four levels by annual card-transaction volume: Level 1 is over 6 million transactions a year, Level 2 is 1 to 6 million, Level 3 is 20,000 to 1 million (e-commerce), and Level 4 is fewer than 20,000 e-commerce or up to 1 million total transactions a year. The vast majority of small businesses are Level 4 — which is the least burdensome tier, not an exemption. Level 4 merchants validate with an annual Self-Assessment Questionnaire and, where it applies, a quarterly network scan. So the real question isn't whether you need PCI compliance, but which short path applies to how you take payments.
Lowering what you pay to accept a card frees up money every month with no extra work and no new customers.
For most small merchants, "becoming PCI compliant" means completing a Self-Assessment Questionnaire (SAQ) — a checklist you fill out yourself, plus an Attestation of Compliance you submit to your acquiring bank or processor. There are several versions, and you use the one that matches how cards reach you. SAQ A is the shortest (around 22 questions) and is for e-commerce or phone-order businesses that fully outsource card handling to a compliant provider, so no card data ever touches their own systems. SAQ B-IP covers merchants using standalone, internet-connected card terminals. SAQ D is the long catch-all (hundreds of questions) for anyone who stores card data or doesn't fit the simpler categories. If a quarterly scan applies to your setup, it's run by an Approved Scanning Vendor (commonly a few hundred dollars a year). The lesson: the way you accept payments decides how much work PCI is — which is exactly the lever you can pull.
For a typical Level 4 shop, the direct cost of compliance is modest: the SAQ itself is free to complete, and a quarterly scan (only if your setup requires one) commonly runs in the low hundreds of dollars a year. What catches owners off guard is the PCI non-compliance fee — a recurring charge, often around $20 to $100 a month, that some acquirers add when a merchant hasn't submitted a current SAQ or scan. It's avoidable: file your attestation and the fee usually goes away. (If your statement already shows a "PCI fee," that's worth a closer look — see the hidden fees buried in your statement and how to read your merchant statement.) The far bigger number is what a data breach costs an unprotected, non-compliant business: forensic investigation, card-brand assessments, reissuance costs, and reputational damage that dwarf the price of doing it right. Compliance is simply the cheaper path.
Here's the move that makes PCI genuinely easy: handle as little card data as possible. If you use a validated processor, a hosted payment page for online sales, and modern terminals that encrypt the card the instant it's tapped or dipped (point-to-point encryption), then raw card numbers never live on your computers or network. That shrinks which requirements apply to you, often qualifies you for the shortest SAQ, and dramatically lowers your breach risk — because you can't lose data you never hold. The right equipment and a properly set-up processing account do most of this for you. Compare hardware options in Clover vs Square vs Valor vs PAX, and if a compliant zero-cost processing setup is a fit, we can build it on encrypted, validated hardware from day one.
On a free 15-minute review I'll look at how you take payments today, tell you which Self-Assessment Questionnaire applies, flag any "PCI fee" you may be paying unnecessarily, and show you the encrypted, validated setup that keeps compliance simple. Start with processing or browse the packages.
Yes. PCI DSS applies to every business that accepts, processes, stores, or transmits credit card data, regardless of size or transaction count. There's no exemption for small merchants. Most small businesses are Level 4 (under 20,000 transactions a year) and validate with a short Self-Assessment Questionnaire rather than a formal audit.
It's the form most small merchants use to validate PCI compliance. You answer a checklist of security questions and submit an Attestation of Compliance to your acquiring bank or processor. The version depends on how you take payments: SAQ A (about 22 questions) is for e-commerce that fully outsources card handling, SAQ B-IP is for standalone internet-connected terminals, and SAQ D is the long catch-all.
Your acquiring bank or processor can charge a recurring PCI non-compliance fee, commonly around $20 to $100 a month for small merchants who haven't submitted a current SAQ or scan. More importantly, if a breach happens while you're non-compliant, you can face far larger fines, forensic costs, and liability. Compliance is the cheaper path.
Reduce your scope. Use a validated processor, a hosted payment page, and modern point-to-point-encrypted terminals so raw card numbers never touch your own systems. The less card data your business handles, the shorter your SAQ and the smaller your risk. A free 15-minute review can map which setup gives you the simplest path.
Lowering what you pay to accept a card frees up money every month with no extra work and no new customers. The businesses that grow from there spend it on the three things that actually bring customers in: answering every call, a site that converts, and showing up on Google.
A free 15-minute review shows you which Self-Assessment Questionnaire applies, whether you're paying a PCI fee you don't need to, and the encrypted setup that keeps compliance painless.
Prefer to talk now? Call or text (305) 215-6132