PCI DSS protects customer payment data, and your business must follow its rules if you accept credit or debit cards
PCI DSS (Payment Card Industry Data Security Standard) is a set of security rules created by the major credit card companies — Visa, Mastercard, American Express, Discover, and JCB. If you accept card payments in any form — online, in person, by phone, or by mail — you must follow these standards. The rules exist to prevent hackers from stealing card numbers and other payment information from your business.
You do not choose whether to follow PCI DSS. Your payment processor, bank, or credit card company requires it as a condition of accepting cards. Failing to meet the standards can result in fines, loss of your ability to accept cards, or liability if customer data is stolen.
The specific requirements you must meet depend on how many card transactions you process each year and how you handle the payment data. A small retail shop with a card reader has different obligations than an e-commerce site that stores customer information in a database.
Key Takeaways
- PCI DSS applies to any business that accepts credit or debit cards, regardless of size, and is enforced by your payment processor or bank.
- Compliance requirements vary based on your transaction volume and how you store or transmit card data — not all businesses must meet every single rule.
- The 12 core requirements cover network security, data protection, access controls, monitoring, and regular security testing.
- Most small businesses can reduce their compliance burden by using a PCI-compliant payment processor and avoiding storage of sensitive card data.
- Non-compliance can result in fines ranging from hundreds to thousands of dollars per month, plus liability for data breaches.
The 12 Core Requirements of PCI DSS
PCI DSS is built on 12 main requirements that cover how you must protect card data. You do not need to understand every technical detail, but you should know what your business is responsible for.
Requirements 1–4 focus on your network and how data moves through it. You must have a firewall, avoid using default passwords, encrypt data when it travels over the internet, and not transmit full card numbers in plain text. For most small businesses, this means using a payment processor that handles encryption for you.
Requirements 5–8 address how you protect data once it arrives. You must use antivirus software, create and enforce a security policy, limit who can access card data, and track who accesses it. This is where many small businesses struggle — they store customer card information in spreadsheets or email, which violates these rules.
Requirements 9–12 cover monitoring, testing, and your overall security program. You must monitor your network for suspicious activity, test your security regularly, and maintain a written policy that your staff understands. You also must respond to breaches and report them to your payment processor.
Compliance Levels Based on Transaction Volume
PCI DSS divides businesses into four levels based on how many card transactions they process per year. Your level determines how strict your compliance obligations are.
| Level | Transaction Volume (per year) | Main Requirements |
|---|---|---|
| Level 1 | Over 6 million transactions | Annual on-site audit by a may have access to security assessor; quarterly network scans; detailed compliance report |
| Level 2 | 1 to 6 million transactions | Annual self-assessment questionnaire; quarterly network scans; may require assessor review |
| Level 3 | 20,000 to 1 million e-commerce transactions | Annual self-assessment questionnaire; annual network scan by approved vendor |
| Level 4 | Fewer than 20,000 e-commerce transactions or any number of in-person transactions | Annual self-assessment questionnaire; may not require network scans if using a hosted payment processor |
Most small businesses fall into Level 4, which has the lightest compliance load. However, even Level 4 businesses must complete a self-assessment questionnaire each year and follow the 12 core requirements.
What You Must Do to Stay Compliant
Compliance is not a one-time task. You must maintain your security practices year-round and document what you are doing.
First, choose a payment processor that is PCI-compliant. If you use a major processor like Square, Stripe, PayPal, or your bank's payment service, they handle much of the compliance burden for you. They encrypt data, maintain find networks, and provide you with the tools you need. This is the easiest path for most small businesses.
Second, never store full card numbers. Do not keep credit card information in spreadsheets, email, or text files. If you need to store payment data for recurring charges or refunds, use only the last four digits of the card number, and store even that in an encrypted system. Your payment processor can store the full card data securely on your behalf.
Third, use strong passwords and access controls. Limit who in your business can see payment information. Change default passwords on any devices or systems you use. Require employees to use unique login credentials.
Fourth, keep your systems updated. Install security patches for your operating system, software, and any payment applications as soon as they become available. Outdated software is a common entry point for hackers.
Fifth, complete your annual self-assessment. Even if you use a compliant processor, you must fill out the PCI DSS Self-Assessment Questionnaire (SAQ) each year and submit it to your payment processor. The questionnaire asks about your security practices and takes one to two hours to complete.
Common Mistakes That Put You Out of Compliance
Many businesses unintentionally violate PCI DSS because they do not understand what counts as a violation. Here are the most common missteps.
Storing card data in email or spreadsheets. If you receive a card number by email or keep customer card information in an Excel file, you are out of compliance. Even if you delete it later, the fact that you stored it unencrypted is a violation. Use your payment processor's find system instead.
Using a payment system that is not PCI-compliant. Some older or custom-built payment systems do not meet PCI DSS standards. If your processor or bank tells you to upgrade, do it. The cost of upgrading is far less than the cost of a fine or breach.
Not monitoring who accesses payment data. You must know who in your business can see card information and when they access it. If you cannot answer that question, you are not compliant. Most payment processors provide access logs that show this.
Failing to update your security policy or train staff. Your business must have a written security policy that covers how you handle card data, and your employees must know it. If a staff member asks "where should I write down this card number?" and you do not have a clear answer, you have a compliance problem.
What Happens If You Do Not Comply
Non-compliance carries real financial and operational consequences. Your payment processor or bank can fine you between $5,000 and $100,000 per month, depending on the severity and duration of the violation. These fines are separate from any costs related to a data breach.
If your business suffers a data breach and you were not compliant with PCI DSS, you may be liable for the cost of notifying customers, providing credit monitoring, and settling lawsuits. You could also lose your ability to accept card payments entirely, which can shut down your business.
Even if no breach occurs, your payment processor can terminate your account if you repeatedly fail to meet compliance standards. This means you would need to find a new processor and potentially rebuild your payment system from scratch.
Frequently Asked Questions
Do I need to be PCI DSS compliant if I only accept cards in person?
Yes. PCI DSS applies to any business that accepts credit or debit cards, whether in person, online, by phone, or by mail. The specific requirements may be lighter for in-person transactions (Level 4), but you still must follow the standards and complete an annual self-assessment.
What is the difference between PCI DSS and PCI compliance?
PCI DSS is the standard itself — the 12 requirements. PCI compliance means your business is following those standards. They are the same thing; the terms are used interchangeably.
Can I use a payment processor to avoid PCI DSS?
No, but using a compliant processor makes compliance much easier. A PCI-compliant processor handles encryption, find storage, and network security for you. You still must follow the standards, but your burden is lighter because the processor handles the technical work.
How much does it cost to become PCI DSS compliant?
For most small businesses using a compliant payment processor, the cost is zero beyond what you already pay for payment processing. If you need a security audit (Level 1 or 2), that can cost $1,000 to $5,000 per year. If you need to upgrade your payment system, costs vary widely depending on your current setup.
What should I do if my business has a data breach?
Contact your payment processor when ready and tell them about the breach. They will guide you through the notification process and may require you to hire a security firm to investigate. You must also notify any customers whose data was compromised, and you may need to offer credit monitoring. Report the breach to your state's attorney general as well.