Security

PCI compliance for small business, without the jargon

8 min read

Card payment terminal cabled behind a small retail counter next to a locked cash drawer

Quick answer

PCI compliance means following the card industry's rules for handling card data. For most small businesses it comes down to filling out a short annual questionnaire, running a scan if you take payments online, using up-to-date equipment, and never writing card numbers down. Finishing the questionnaire also removes the monthly non-compliance fee many processors charge.

Key takeaways

  • Most small businesses only need a self-assessment questionnaire, not an audit.
  • The monthly "PCI non-compliance fee" on your statement usually just means paperwork is unfinished.
  • Never store card numbers on paper, in email, in texts or in a spreadsheet.
  • Modern terminals and hosted checkout pages shrink your responsibility dramatically.
  • Redo the questionnaire every 12 months — it expires.

What PCI compliance means in practice

PCI DSS stands for Payment Card Industry Data Security Standard. It's not a law — it's a set of rules the card brands agreed on so that businesses handling card numbers do it safely. If you accept Visa, Mastercard, Discover or American Express, you agreed to follow it when you signed your processing agreement. The good news is that the version that applies to a small shop is much lighter than the version that applies to a national chain.

In everyday terms, compliance means three things: you use equipment and software that protects card data, you don't keep card numbers lying around, and once a year you confirm both of those in writing. That's the whole shape of it.

Which level are you?

PCI merchant levels by annual card transaction count
LevelAnnual transactionsWhat's required
Level 4Under 20,000 e-commerce or under 1 million totalSelf-assessment questionnaire, plus a scan if you take cards online
Level 320,000 – 1 million e-commerceSelf-assessment questionnaire and quarterly scans
Level 21 – 6 million totalQuestionnaire or on-site review, quarterly scans
Level 1Over 6 million totalAnnual audit by a qualified assessor

Nearly every independent restaurant, salon, clinic, contractor and retail shop in the country is Level 4. If someone is trying to sell you an expensive audit and you run one location, ask them which level they think you are and why.

Picking the right questionnaire

There are several versions of the self-assessment questionnaire (SAQ), and the one you need depends on how you take payments. Choosing the right one saves a lot of unnecessary questions.

Common SAQ types for small businesses
If you...You likely needRoughly how many questions
Only use a standalone dial-up or cellular terminalSAQ B~40
Use a terminal with point-to-point encryptionSAQ B-IP or P2PE~30
Take payments online through a hosted checkout pageSAQ A~30
Take online payments with fields on your own siteSAQ A-EP~190
Use a POS system connected to the internetSAQ C~160

The pattern is worth noticing: the less card data touches your own systems, the shorter the questionnaire. If your website's payment form is hosted by your payment provider rather than built into your own pages, you can go from nearly 200 questions to about 30. That's a real reason to choose hosted checkout when you set up online payment processing.

That non-compliance fee on your statement

Look at your last statement for a line like "PCI non-compliance" or "PCI program fee" — often $9.95 to $39.95 a month. Nine times out of ten it means nobody ever logged into the compliance portal and finished the questionnaire. It is not a fine from Visa. Finish the paperwork and, in most cases, the fee stops and some processors will credit a month or two back if you ask.

The twelve requirements, translated

  • Use a firewall — for most shops this is the business-grade router your internet provider or POS installer set up.
  • Change default passwords on everything: router, terminal admin, POS manager accounts, back-office Wi-Fi.
  • Don't store card data. If you never keep it, most of the standard stops applying to you.
  • Encrypt data in transit — modern terminals and hosted checkout do this automatically.
  • Keep anti-malware running on any computer that touches payments.
  • Install updates on your POS, tablets and terminals when they're released.
  • Limit who can see what: your seasonal cashier doesn't need manager-level reporting access.
  • Give each employee their own login. No shared "staff" account with the PIN taped to the till.
  • Physically secure equipment: locked back office, cameras over the register, terminals not left loose overnight.
  • Keep logs — your POS does this for you; just don't turn it off.
  • Test your setup: run the scan if you take online payments, and check for rogue Wi-Fi devices.
  • Write down your basic security rules so staff can follow them.
Tablet point-of-sale system in use on a busy shop counter with cables and receipt printer
Keeping the POS updated and giving each employee their own login covers a surprising share of the standard.

The five habits that cause almost all small business problems

1. Writing card numbers on paper

Phone orders and deposits tempt staff to jot a number on a notepad "just for a minute." That notepad is now the single biggest liability in your building. Take the payment while the customer is on the phone, or send them a secure payment link instead.

2. Accepting card numbers over email or text

Email and SMS are not secure and the number sits in your inbox indefinitely. If a customer sends one anyway, process it, then delete the message from your inbox and your trash and tell them how to pay next time.

3. Sharing the guest Wi-Fi with the register

Your payment devices should be on a separate network from customer Wi-Fi. Any decent router can do this. It's a ten-minute setup that keeps a stranger's laptop off the same network as your POS.

4. Old, unpatched equipment

A terminal from 2013 or a POS running an unsupported operating system can fail compliance and, more importantly, can actually be exploited. If your hardware no longer receives updates, replace it. Our card machine guide covers current options.

5. Never checking the terminal for tampering

Skimming overlays are still a thing, especially at unattended or high-traffic counters. Give terminals a quick look each morning: loose casing, an odd extra slot, unfamiliar cables, a serial number that doesn't match your records.

Countertop card terminal being inspected for tampering at the start of a shift
A ten-second look at the terminal each morning catches most physical tampering.

What happens if you ignore it

The monthly fee is the mild version. If card data is stolen from a business that wasn't compliant, the costs can include forensic investigation, card brand fines passed through your processor, the cost of reissuing customer cards, higher processing rates, and in serious cases losing the ability to accept cards. For a small business, the reputational damage in a tight-knit local market often hurts longer than the invoice.

A simple annual routine

  1. 1Log into your processor's compliance portal and note the expiration date on your attestation.
  2. 2Complete the correct SAQ for how you actually take payments today, not how you did two years ago.
  3. 3If you take online payments, run the quarterly scan the portal offers.
  4. 4Confirm every employee has their own POS login and remove anyone who's left.
  5. 5Check that all terminals, tablets and POS software are on current versions.
  6. 6Verify the non-compliance fee has dropped off your next statement.

That's genuinely it for most businesses — an hour or two once a year. If you're setting up payments for the first time, start from our guide to accepting credit card payments and choose a hosted, encrypted setup from day one so compliance stays easy.

Help for Minnesota businesses

We sit down with owners across Minneapolis, St. Paul and the rest of Minnesota and finish the questionnaire together — screen shared, on the phone, done in one sitting. If you've been paying a non-compliance fee for a year, that's usually the first thing we fix.

Want a hand with yours? Book a walkthrough or call 763-280-3155.

Frequently asked questions

Sources and references

Want this checked against your own statement?

Send us a recent processing statement and we'll mark it up line by line — what you're paying now, and what you'd pay with us. No pressure.

Keep reading

Send us your last statement

Email us a recent processing statement and we'll show you, line by line, what you're paying now and what you'd pay with us. No pressure, no sales pitch.