Back to Blog
    pci-compliance-costs-small-business
    pci-standards-for-businesses
    small-business-security
    pci-compliance-small-business
    pci-compliance-guide

    PCI Compliance for Small Business: Your 30, 60 Day Plan

    Dustin CollettAugust 10, 2026
    PCI Compliance for Small Business: Your 30, 60 Day Plan

    If you accept card payments, PCI DSS applies to your business, full stop. Your acquirer (the bank or processor that settles your card transactions) enforces validation, and ignoring it puts your merchant account, your reputation, and your business at risk.

    Three actions cut your exposure immediately:

    • Stop storing card data. If card numbers, CVVs, or magnetic-stripe data live anywhere on your systems, spreadsheets, email, paper logs, remove them now.
    • Switch to a hosted or tokenized checkout, or a validated terminal. When card data never touches your systems, your compliance scope shrinks dramatically.
    • Contact your acquirer this week. Ask which Self-Assessment Questionnaire (SAQ) type applies to your setup, confirm whether quarterly ASV scans are required, and enable multi-factor authentication (MFA) on every account that touches payment systems.

    This week's single next step: Call or email your acquirer, confirm your SAQ type, and enable MFA on your payment portal logins. Everything else builds from there.

    Roughly 60% of small and medium businesses that experience a data breach close within six months. PCI compliance is not a bureaucratic checkbox, it is one of the most direct levers you have to avoid becoming that statistic.


    Key Takeaways

    PCI DSS applies to every business that accepts card payments, and the fastest path to compliance is reducing scope so card data never touches your systems.

    PointDetails
    Scope reduction firstMove to a hosted checkout or validated P2PE terminal before completing your SAQ, it can cut your question count from 329 to 22.
    Most small businesses are Level 4Level 4 merchants self-attest with an SAQ and AOC; no QSA audit required unless your acquirer mandates one.
    Annual compliance cost rangeSAQ A paths typically cost, per year; SAQ D paths run $3,000, $5,000 or more.
    Processors reduce scope, not obligationUsing Square or Stripe shrinks your SAQ type but you still must complete and submit annual validation paperwork.
    Collett Systems LLCProvides fixed-cost managed IT covering SAQ prep, ASV coordination, network segmentation, and ongoing compliance monitoring for small businesses.

    Table of Contents

    What PCI DSS is and why your small business can't ignore it

    PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of technical and operational requirements maintained by the PCI Security Standards Council (PCI SSC), a body founded by Visa, Mastercard, American Express, Discover, and JCB. The card brands themselves, Visa and Mastercard chief among them, set the validation rules and enforce them through your acquiring bank.

    The standard covers 12 requirement domains: network security, access controls, encryption, monitoring, vulnerability management, and more. For a small business, the practical translation is simpler: protect card data, prove you did it annually, and report any breach promptly.

    Why does it matter beyond the technical requirements?

    • Contractual obligation. Your merchant agreement requires PCI compliance. Non-compliance can trigger fines from your acquirer, typically ranging from $5,000 to $100,000 per month depending on the card brand and severity.
    • Breach liability. If you suffer a breach while non-compliant, you absorb the cost of forensic investigation, card replacement, and potential litigation, costs that can exceed the fines.
    • Reputational damage. A publicized breach at a local business is hard to recover from, especially when customers learn the business was not compliant.

    One important caveat: security experts treat PCI DSS as a baseline, not a complete security program. Passing your SAQ does not mean you are fully protected against modern threats. MFA, offsite backups, and email security controls are the next layer, and they are cheap relative to the cost of a breach.


    Which merchants need PCI compliance and what level are you?

    Any business that accepts, processes, stores, or transmits cardholder data is in scope, regardless of size, transaction volume, or how briefly card data passes through. Merchant levels determine how you validate, not whether you must.

    The four levels are set by the card brands:

    • Level 1: More than 6 million Visa or Mastercard transactions per year. Requires an annual on-site audit (Report on Compliance) by a Qualified Security Assessor (QSA).
    • Level 2: 1 million to 6 million transactions per year. Annual SAQ plus quarterly ASV scans.
    • Level 3: 20,000 to 1 million e-commerce transactions per year. Annual SAQ plus quarterly ASV scans.
    • Level 4: Fewer than 20,000 e-commerce transactions, or up to 1 million total transactions per year. Annual SAQ; ASV scans required if internet-facing systems are in scope.

    Most U.S. small businesses are Level 4. That means you self-attest using the correct SAQ rather than paying for a full QSA audit.

    Which SAQ fits your payment setup?

    Technician installing network firewall device

    Payment flowTypical SAQASV scan required?
    Hosted checkout (Stripe, Square redirect), card data never touches your serverSAQ ANo
    JavaScript-embedded payment form on your own pageSAQ A-EPYes
    Card-present terminal, no electronic data storageSAQ BNo
    Card-present terminal connected via IPSAQ B-IPYes
    Virtual terminal (keyed entry via browser)SAQ C-VTNo
    In-house processing or stored card dataSAQ DYes

    The gap between SAQ A (22 questions) and SAQ D (329 questions) is enormous. Choosing your architecture with SAQ type in mind is one of the highest-leverage decisions you can make.


    How validation actually works: SAQs, ASV scans, and QSAs

    Validation produces three possible outputs depending on your level and SAQ type: a completed SAQ, an Attestation of Compliance (AOC), and, when required, quarterly ASV scan reports.

    Key terms:

    • SAQ (Self-Assessment Questionnaire): A structured checklist you complete annually to document your compliance posture. Download all SAQ forms directly from the PCI SSC.
    • AOC (Attestation of Compliance): A signed declaration that accompanies your SAQ. Your acquirer typically requires this document annually.
    • ASV (Approved Scanning Vendor): A PCI SSC-approved company that runs external vulnerability scans against your internet-facing systems. Find the official ASV list at the PCI SSC site.
    • QSA (Qualified Security Assessor): A PCI SSC-certified firm that conducts on-site audits for Level 1 merchants or advises smaller merchants on complex environments.
    • ROC (Report on Compliance): The formal audit report produced by a QSA for Level 1 merchants. Most small businesses never need one.

    Which SAQ types require quarterly ASV scans?

    • SAQ A-EP: Yes
    • SAQ B-IP: Yes
    • SAQ C: Yes
    • SAQ D: Yes
    • SAQ A: No
    • SAQ B: No
    • SAQ C-VT: No

    Quarterly external vulnerability scans are required whenever internet-facing systems are in scope. Many payment providers bundle ASV scanning into their monthly fee, worth confirming before you pay separately.


    Your 30, 60 day action plan to get compliant

    This is a practical, timeboxed playbook. Work through it in order.

    Days 1, 7: Establish your baseline

    1. List every place card data enters your business: website checkout, physical terminal, phone orders, recurring billing.
    2. Contact your acquirer and confirm your merchant level and the correct SAQ type.
    3. Stop storing card data anywhere, delete spreadsheets, shred paper logs, disable any local database that holds card numbers.
    4. Enable MFA on every account that touches payment systems or cardholder data.

    Days 8, 28: Reduce scope and fix configurations

    1. Switch to a hosted payment page (redirect model) if you currently use an embedded JavaScript form. This alone can move you from SAQ A-EP to SAQ A.
    2. If you take card-present payments, confirm your terminal is on the PCI SSC validated device list. Deploy a validated P2PE solution if your acquirer supports it.
    3. Segment your payment network from your general office network. Guest Wi-Fi and point-of-sale systems must not share the same segment.
    4. Update all default passwords on routers, terminals, and payment software. Apply current firmware and patches.

    Days 29, 60: Complete validation and submit

    1. Run your required ASV scans (if applicable). Schedule these early, remediation and rescans take time.
    2. Complete your SAQ, answering every question accurately. Do not mark "yes" to controls you have not actually implemented.
    3. Sign the AOC and submit both documents to your acquirer by their deadline.
    4. Schedule quarterly ASV scans, monthly patch reviews, and annual staff security training going forward.

    Estimated effort and cost by path:

    The fastest, lowest-cost path is to route card data entirely to a compliant provider, qualifying you for SAQ A. Every hour you spend simplifying your payment architecture pays back in reduced annual compliance effort.


    What your payment processor actually covers, and what it doesn't

    This is the most common misconception in small-business PCI compliance: "I use Square (or Stripe), so I'm covered." Payment processors reduce your technical scope, but they do not remove your contractual obligation to validate compliance and submit annual paperwork.

    Here is what hosted and tokenized processors actually do:

    • Hosted checkout: Card data is entered directly on the processor's page and never touches your server. Your scope shrinks to SAQ A, but you still must complete and submit that SAQ annually.
    • Tokenization: The processor replaces card numbers with a token your system stores instead. You can charge the token for recurring billing without ever handling the real card number.
    • P2PE (Point-to-Point Encryption): Card data is encrypted at the terminal before it reaches any network. A validated P2PE solution can reduce card-present scope to SAQ B-IP or lower.

    What processors cover vs. what you still own:

    AreaProcessor responsibilityMerchant responsibility
    Card data encryption in transitYesConfirm processor is PCI-certified
    Secure storage of card numbersYes (tokenization)Do not store raw card data locally
    Annual SAQ completionNoMerchant completes and submits
    AOC submission to acquirerNoMerchant signs and submits
    Network security around the checkoutNoMerchant segments and secures
    Staff access controls and passwordsNoMerchant enforces
    Incident response planPartialMerchant must have own plan

    Do you need to be PCI compliant if you use Square or Stripe? Yes. Both Square and Stripe are PCI-certified service providers, and using them dramatically reduces your scope. But you still must complete the annual SAQ, sign the AOC, and confirm that your environment around the processor is secure. Simplify your setup rather than assume the processor handles everything.


    What your payment processor actually covers, and what it doesn't, overview diagram

    Common mistakes that expand your scope and increase breach risk

    Most small-business PCI failures trace back to a handful of avoidable errors. Here is where businesses get into trouble, and how to fix each one.

    • Storing card data in spreadsheets or paper logs. This is the single most common mistake and the one most likely to cause a breach. Fix: delete all stored card data, confirm deletion with your IT provider, and switch to tokenized recurring billing.

    • Flat networks where guest Wi-Fi shares scope with payment systems. If a customer on your guest network can reach the same segment as your point-of-sale terminal, your entire network is in scope. Fix: segment the POS network with a VLAN or separate router. Effort: 2, 4 hours for a qualified technician.

    • Default or weak passwords on terminals and routers. Factory-default credentials are the first thing attackers try. Fix: change every default password, enforce a minimum 12-character policy, and document the change. Effort: under an hour.

    • Embedded JavaScript payment forms without proper controls. An SAQ A-EP environment requires you to monitor the integrity of your payment scripts. A compromised script (Magecart-style attack) can silently skim card data. Fix: move to a hosted redirect checkout to drop to SAQ A, or implement script integrity monitoring.

    • Skipping quarterly ASV scans. Many small businesses complete their SAQ but forget the scan requirement. Fix: schedule all four scans at the start of the year, or confirm your payment provider bundles scanning.

    Pro Tip: If your SAQ feels overwhelming, that is a signal your payment architecture is too complex. Simplify first: redirect to a hosted payment page, remove any local card storage, and deploy a validated P2PE terminal for in-person sales. Most small businesses can reach SAQ A or SAQ B-IP with one afternoon of configuration changes, and those SAQs are manageable without outside help.


    Where to get vetted help and official resources

    Start with the PCI SSC's official resources, they are free, authoritative, and regularly updated.

    Official resources to bookmark:

    • SAQ forms and instructions: Download directly from the PCI SSC merchants page. Each SAQ includes a guidance document explaining every question.
    • PCI SSC Small Merchant Guide: A plain-language PDF covering device selection, vendor questions, and incident contacts. Print it and keep it with your compliance documentation.
    • ASV list: Search the PCI SSC site for "Approved Scanning Vendors" to find a current, vetted list of scan providers.
    • QSA directory: If your environment is complex or you are unsure which SAQ applies, a QSA can advise you without conducting a full audit. Search the PCI SSC QSA company list.
    • Validated payment device list: Confirm your terminal is on the PCI SSC's list of approved PIN Transaction Security (PTS) devices before deploying it.
    • Visa and Mastercard registries: Both card brands publish lists of registered service providers. Confirm your processor appears on the Visa Global Registry of Service Providers or the Mastercard SDP Program list before signing a contract.

    Questions to ask every service provider:

    • Are you a PCI DSS Level 1 certified service provider?
    • Do you provide an AOC or Responsibility Matrix I can share with my acquirer?
    • Does your service include ASV scanning, or do I arrange that separately?
    • What is your incident notification process if a breach affects my data?

    How a managed IT partner reduces your PCI workload

    A managed IT partner does not replace your obligation to validate, but it handles the technical heavy lifting so you can focus on running your business. Here is what a qualified partner delivers:

    Ongoing deliverables:

    • SAQ preparation and evidence collection (network diagrams, access logs, policy documentation)
    • ASV scan scheduling and remediation coordination
    • Terminal management and P2PE deployment for card-present environments
    • Network segmentation design and implementation
    • MFA rollout across all in-scope accounts (see why MFA matters for the technical case)
    • Log retention and patch management to satisfy PCI Requirements 10 and 6
    • Incident response plan templates and annual tabletop exercises

    What the recurring engagement looks like:

    A managed IT contract with fixed per-user pricing covers the recurring tasks, quarterly ASV scheduling, monthly patching, log review, and annual SAQ prep, as predictable line items rather than surprise invoices. That pricing model matters for compliance: you know exactly what you are spending, and nothing falls through the cracks between billing cycles.

    How to validate a partner's PCI experience:

    • Ask for a sample network diagram or SAQ evidence package they have produced for a similar client.
    • Confirm they have worked with your acquirer's specific validation process.
    • Check whether they maintain relationships with an ASV or QSA for referrals.
    • Ask how they handle small-business cyber threats beyond PCI scope, incident response and breach notification are equally important.

    The first step is typically a paid IT and security assessment that maps your current payment flows, identifies scope, and produces a prioritized remediation roadmap. Some partners offer a free risk score as an entry point before committing to a full assessment.


    The scope-first approach is the only one that actually works

    Most small businesses approach PCI compliance the wrong way: they download the SAQ, feel overwhelmed by the question count, and either guess at answers or hire someone to do the same. Neither approach fixes the underlying problem.

    The businesses we work with that get through compliance fastest share one trait: they simplified their payment architecture before they touched the SAQ. Moving from an embedded JavaScript checkout to a hosted redirect takes an afternoon. Deploying a validated P2PE terminal for card-present sales takes a day. Those two changes can move a business from SAQ D territory to SAQ A or SAQ B-IP, cutting the question count from 329 to 22 or 61, and eliminating the penetration test requirement entirely.

    The other thing worth saying plainly: PCI compliance is the floor, not the ceiling. We see businesses that pass their annual SAQ and then get hit by a phishing attack or an ACH diversion scheme that PCI never addressed. The standard covers card data. It does not cover your email, your banking credentials, or your backup strategy. Treat compliance as the starting point and build from there.


    Collett Systems LLC handles the PCI compliance work you don't have time for

    PCI compliance for a small business does not have to mean months of confusion and surprise costs. Collett Systems LLC delivers a fixed-cost managed IT engagement that covers SAQ preparation, ASV scan coordination, network segmentation, MFA deployment, and ongoing log and patch management, everything your acquirer needs to see, documented and ready.

    Collett Systems LLC

    The first step is a paid IT and Security Assessment that maps your payment flows, identifies your SAQ type, and produces a clear remediation roadmap with timeline and cost estimates. No guesswork, no open-ended hourly billing. For businesses that already have internal IT staff, our co-managed IT services let your team handle day-to-day support while we own the compliance and security layer.

    Book your assessment or take our 60-second IT risk score to see where your biggest gaps are before your next acquirer deadline.


    Sources

    Bookmark these official and high-value resources as you work through your compliance plan:

    This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.