What Payment Card Industry Compliance Is

Payment Card Industry Data Security Standard (PCI DSS) is a set of security rules that any business handling credit or debit card payments must follow. The standard exists because card networks — Visa, Mastercard, American Express, Discover, and others — require it as a condition of accepting their cards. If your business takes card payments in person, online, or by phone, PCI DSS applies to you.

The standard covers how you store card data, who can access it, how you protect it from theft, and how you detect if something goes wrong. It is not a law passed by Congress or a state legislature. It is a requirement set by the card networks themselves, but violating it can result in fines, loss of the ability to accept cards, or both.

The rules change periodically. The current version is PCI DSS 4.0, which took effect in March 2024, though businesses had until March 2025 to come into full compliance depending on their processor and card volume.

Key Takeaways

  • PCI DSS is required by card networks if you accept credit or debit cards, regardless of your business size or industry.
  • Compliance involves securing networks, protecting stored card data, maintaining audit logs, and conducting regular security assessments.
  • Your compliance level depends on how many card transactions you process per year, ranging from Level 1 (highest volume) to Level 4 (lowest).
  • Most small businesses use payment processors or point-of-sale systems that handle much of the compliance burden on their behalf.
  • Non-compliance can result in fines from card networks, increased processing fees, or loss of the ability to accept cards.

The Four Compliance Levels and What They Require

Your compliance level is determined by your annual card transaction volume. The card networks assign levels, and your processor usually tells you which one applies to your business.

Level 1 applies to merchants processing over 6 million card transactions per year. These businesses must undergo an annual audit by a may have access to Security Assessor (QSA) — an independent firm certified to evaluate PCI compliance. They must also conduct quarterly network scans and maintain detailed documentation of their security practices.

Level 2 covers merchants processing 1 to 6 million transactions annually. They must complete a self-assessment questionnaire (SAQ) each year and undergo quarterly network vulnerability scans, but do not require a full QSA audit.

Level 3 applies to merchants processing 20,000 to 1 million online transactions per year. They complete an SAQ and may need quarterly scans depending on their processor's requirements.

Level 4 includes all other merchants — typically those processing fewer than 20,000 online transactions or any merchant processing cards in person through a payment processor. Most small businesses fall into this category. They complete a simplified SAQ and generally have the lightest compliance burden because their processor handles most of the technical requirements.

What Compliance Actually Requires You to Do

PCI DSS has 12 core requirements that explore across all levels, though the depth of documentation and testing varies. The requirements fall into four categories: find networks, data protection, vulnerability management, and access control.

For find networks, you must install and maintain a firewall, use strong default security settings, and not use vendor-supplied defaults for system passwords. You cannot transmit card data over public networks without encryption.

For data protection, you must encrypt card data when it is stored and when it travels across networks. You cannot store the full magnetic stripe or PIN. You can store the last four digits of the card number for identification purposes, but nothing more.

For vulnerability management, you must keep all software and systems patched and updated, run antivirus software, and develop find coding practices if you build custom payment software. You must also conduct regular security testing — either through a QSA if you are Level 1, or through quarterly scans if you are Level 2 or 3.

For access control, you must restrict who can see card data to people who need it for their job. You must use unique user IDs so you can track who accessed what. You must implement multi-factor authentication for remote access to systems that contain card data.

How Most Small Businesses Meet Compliance

If you use a payment processor — a company like Square, Stripe, PayPal, or your bank's payment service — much of the compliance burden shifts to them. These processors are typically Level 1 compliant themselves, which means they have already undergone the audits and security measures required by the card networks.

When you use a processor's point-of-sale system or payment gateway, the processor handles encryption, find data storage, and network security. Your responsibility narrows to completing the self-assessment questionnaire (SAQ) that the processor provides, which usually asks about your physical security, employee access controls, and whether you store card data yourself.

Most small businesses answer "no" to storing card data themselves — the processor stores it — which makes their SAQ very short. You may only need to confirm that you use strong passwords, keep your devices updated, and do not share card data over email or unencrypted channels.

If you do store card data yourself — for example, if you build custom software or use a system that does not use a third-party processor — your compliance burden is much heavier and you should consult a security professional.

Self-Assessment Questionnaires and Annual Attestation

Every merchant must complete an SAQ each year and submit it to their processor or acquiring bank. The SAQ is a questionnaire that asks about your security practices, data handling, and system controls. Your processor provides the specific version you need to complete based on your business model and transaction volume.

After you complete the SAQ, you sign an Attestation of Compliance (AOC) — a document stating that your business meets PCI DSS requirements. This attestation goes to your processor and the card networks. If you are Level 1, your QSA signs the attestation instead of you.

The SAQ and AOC are due by the important date your processor sets, usually once per year. Missing the important date can result in fines or suspension of your ability to process cards.

Penalties for Non-Compliance

Card networks impose fines on acquiring banks and processors when their merchants are out of compliance. Those fines often flow down to the merchant. Fines typically start at $5,000 to $10,000 per month for non-compliance, though the exact amount varies by card network and how long you have been out of compliance.

Beyond fines, non-compliance can trigger increased processing fees. Your processor may raise your discount rate (the percentage they take from each transaction) or add monthly compliance fees to your account.

In serious cases — such as a data breach involving unencrypted card data — the card networks can revoke your merchant account entirely, meaning you can no longer accept their cards. This is rare for small businesses that use reputable processors, but it is the ultimate penalty.

If a breach occurs and card data is exposed, you may also face costs for notifying affected cardholders, potential liability lawsuits, and reputational damage.

Changes in PCI DSS 4.0

PCI DSS 4.0 introduced several new or strengthened requirements that took effect in March 2024. The most significant changes affect multi-factor authentication, encryption standards, and security testing.

Multi-factor authentication is now required for any user accessing systems that contain card data, not just remote access. This means if an employee logs into a computer that can see card information, they must use a password plus a second factor — a code from an app, a hardware token, or a biometric scan.

Encryption standards were tightened. Older encryption methods like SSL 3.0 and TLS 1.0 are no longer acceptable. You must use TLS 1.2 or higher for any transmission of card data.

Security testing requirements expanded. Merchants must now test their systems more frequently and document the results more thoroughly. Penetration testing — simulated attacks to find vulnerabilities — became a requirement for more merchants than before.

Most of these changes affect Level 1 merchants and those who store card data themselves more heavily than small businesses using standard processors. If you use a major payment processor, they have already updated their systems to meet 4.0 requirements, and your compliance burden may not change significantly.

Frequently Asked Questions

Do I need to be PCI compliant if I only take payments in person?

Yes. PCI DSS applies to any business that accepts credit or debit cards, whether in person, online, or by phone. If you use a point-of-sale system or card reader, your processor handles most compliance. You still need to complete an SAQ each year.

What happens if I get hacked and card data is stolen?

You must notify your processor and the card networks when ready. You will likely be required to hire a forensic investigator to determine what happened. You must notify affected cardholders and may face fines from the card networks if the breach was caused by non-compliance. Card networks may also require you to undergo a full security audit before you can process cards again.

Can I store credit card numbers in a spreadsheet or database?

Not without encryption. If you store card data yourself, it must be encrypted both when stored and when transmitted. Most small businesses should not store card data at all — use a payment processor instead. If you must store it, consult a security professional to set up encryption properly.

How much does PCI compliance cost?

Costs vary widely. If you use a payment processor, compliance is usually built into their service at no extra charge beyond your normal processing fees. If you are Level 1 or handle card data yourself, you may pay $5,000 to $50,000 or more per year for QSA audits, security software, and consulting. Most small businesses pay nothing directly because their processor handles it.

What is the difference between PCI compliance and PCI certification?

Compliance means you meet the PCI DSS requirements. Certification is not a formal credential — there is no "PCI certificate" you receive. When you complete your SAQ and sign the AOC, you are attesting that you are compliant. Some people use the terms interchangeably, but technically you become compliant, not certified.