
If you accept card payments, PCI DSS applies to your business, full stop. Your acquirer (the bank or processor that settles your card transactions) enforces validation, and ignoring it puts your merchant account, your reputation, and your business at risk.
Three actions cut your exposure immediately:
- Stop storing card data. If card numbers, CVVs, or magnetic-stripe data live anywhere on your systems, spreadsheets, email, paper logs, remove them now.
- Switch to a hosted or tokenized checkout, or a validated terminal. When card data never touches your systems, your compliance scope shrinks dramatically.
- Contact your acquirer this week. Ask which Self-Assessment Questionnaire (SAQ) type applies to your setup, confirm whether quarterly ASV scans are required, and enable multi-factor authentication (MFA) on every account that touches payment systems.
This week's single next step: Call or email your acquirer, confirm your SAQ type, and enable MFA on your payment portal logins. Everything else builds from there.
Roughly 60% of small and medium businesses that experience a data breach close within six months. PCI compliance is not a bureaucratic checkbox, it is one of the most direct levers you have to avoid becoming that statistic.
Key Takeaways
PCI DSS applies to every business that accepts card payments, and the fastest path to compliance is reducing scope so card data never touches your systems.
| Point | Details |
|---|---|
| Scope reduction first | Move to a hosted checkout or validated P2PE terminal before completing your SAQ, it can cut your question count from 329 to 22. |
| Most small businesses are Level 4 | Level 4 merchants self-attest with an SAQ and AOC; no QSA audit required unless your acquirer mandates one. |
| Annual compliance cost range | SAQ A paths typically cost, per year; SAQ D paths run $3,000, $5,000 or more. |
| Processors reduce scope, not obligation | Using Square or Stripe shrinks your SAQ type but you still must complete and submit annual validation paperwork. |
| Collett Systems LLC | Provides fixed-cost managed IT covering SAQ prep, ASV coordination, network segmentation, and ongoing compliance monitoring for small businesses. |
Table of Contents
- What PCI DSS is and why your small business can't ignore it
- Which merchants need PCI compliance and what level are you?
- How validation actually works: SAQs, ASV scans, and QSAs
- Your 30, 60 day action plan to get compliant
- What your payment processor actually covers, and what it doesn't
- Common mistakes that expand your scope and increase breach risk
- Where to get vetted help and official resources
- How a managed IT partner reduces your PCI workload
- The scope-first approach is the only one that actually works
- Collett Systems LLC handles the PCI compliance work you don't have time for
- Sources
What PCI DSS is and why your small business can't ignore it
PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of technical and operational requirements maintained by the PCI Security Standards Council (PCI SSC), a body founded by Visa, Mastercard, American Express, Discover, and JCB. The card brands themselves, Visa and Mastercard chief among them, set the validation rules and enforce them through your acquiring bank.
The standard covers 12 requirement domains: network security, access controls, encryption, monitoring, vulnerability management, and more. For a small business, the practical translation is simpler: protect card data, prove you did it annually, and report any breach promptly.
Why does it matter beyond the technical requirements?
- Contractual obligation. Your merchant agreement requires PCI compliance. Non-compliance can trigger fines from your acquirer, typically ranging from $5,000 to $100,000 per month depending on the card brand and severity.
- Breach liability. If you suffer a breach while non-compliant, you absorb the cost of forensic investigation, card replacement, and potential litigation, costs that can exceed the fines.
- Reputational damage. A publicized breach at a local business is hard to recover from, especially when customers learn the business was not compliant.
One important caveat: security experts treat PCI DSS as a baseline, not a complete security program. Passing your SAQ does not mean you are fully protected against modern threats. MFA, offsite backups, and email security controls are the next layer, and they are cheap relative to the cost of a breach.
Which merchants need PCI compliance and what level are you?
Any business that accepts, processes, stores, or transmits cardholder data is in scope, regardless of size, transaction volume, or how briefly card data passes through. Merchant levels determine how you validate, not whether you must.
The four levels are set by the card brands:
- Level 1: More than 6 million Visa or Mastercard transactions per year. Requires an annual on-site audit (Report on Compliance) by a Qualified Security Assessor (QSA).
- Level 2: 1 million to 6 million transactions per year. Annual SAQ plus quarterly ASV scans.
- Level 3: 20,000 to 1 million e-commerce transactions per year. Annual SAQ plus quarterly ASV scans.
- Level 4: Fewer than 20,000 e-commerce transactions, or up to 1 million total transactions per year. Annual SAQ; ASV scans required if internet-facing systems are in scope.
Most U.S. small businesses are Level 4. That means you self-attest using the correct SAQ rather than paying for a full QSA audit.
Which SAQ fits your payment setup?

| Payment flow | Typical SAQ | ASV scan required? |
|---|---|---|
| Hosted checkout (Stripe, Square redirect), card data never touches your server | SAQ A | No |
| JavaScript-embedded payment form on your own page | SAQ A-EP | Yes |
| Card-present terminal, no electronic data storage | SAQ B | No |
| Card-present terminal connected via IP | SAQ B-IP | Yes |
| Virtual terminal (keyed entry via browser) | SAQ C-VT | No |
| In-house processing or stored card data | SAQ D | Yes |
The gap between SAQ A (22 questions) and SAQ D (329 questions) is enormous. Choosing your architecture with SAQ type in mind is one of the highest-leverage decisions you can make.
How validation actually works: SAQs, ASV scans, and QSAs
Validation produces three possible outputs depending on your level and SAQ type: a completed SAQ, an Attestation of Compliance (AOC), and, when required, quarterly ASV scan reports.
Key terms:
- SAQ (Self-Assessment Questionnaire): A structured checklist you complete annually to document your compliance posture. Download all SAQ forms directly from the PCI SSC.
- AOC (Attestation of Compliance): A signed declaration that accompanies your SAQ. Your acquirer typically requires this document annually.
- ASV (Approved Scanning Vendor): A PCI SSC-approved company that runs external vulnerability scans against your internet-facing systems. Find the official ASV list at the PCI SSC site.
- QSA (Qualified Security Assessor): A PCI SSC-certified firm that conducts on-site audits for Level 1 merchants or advises smaller merchants on complex environments.
- ROC (Report on Compliance): The formal audit report produced by a QSA for Level 1 merchants. Most small businesses never need one.
Which SAQ types require quarterly ASV scans?
- SAQ A-EP: Yes
- SAQ B-IP: Yes
- SAQ C: Yes
- SAQ D: Yes
- SAQ A: No
- SAQ B: No
- SAQ C-VT: No
Quarterly external vulnerability scans are required whenever internet-facing systems are in scope. Many payment providers bundle ASV scanning into their monthly fee, worth confirming before you pay separately.
Your 30, 60 day action plan to get compliant
This is a practical, timeboxed playbook. Work through it in order.
Days 1, 7: Establish your baseline
- List every place card data enters your business: website checkout, physical terminal, phone orders, recurring billing.
- Contact your acquirer and confirm your merchant level and the correct SAQ type.
- Stop storing card data anywhere, delete spreadsheets, shred paper logs, disable any local database that holds card numbers.
- Enable MFA on every account that touches payment systems or cardholder data.
Days 8, 28: Reduce scope and fix configurations
- Switch to a hosted payment page (redirect model) if you currently use an embedded JavaScript form. This alone can move you from SAQ A-EP to SAQ A.
- If you take card-present payments, confirm your terminal is on the PCI SSC validated device list. Deploy a validated P2PE solution if your acquirer supports it.
- Segment your payment network from your general office network. Guest Wi-Fi and point-of-sale systems must not share the same segment.
- Update all default passwords on routers, terminals, and payment software. Apply current firmware and patches.
Days 29, 60: Complete validation and submit
- Run your required ASV scans (if applicable). Schedule these early, remediation and rescans take time.
- Complete your SAQ, answering every question accurately. Do not mark "yes" to controls you have not actually implemented.
- Sign the AOC and submit both documents to your acquirer by their deadline.
- Schedule quarterly ASV scans, monthly patch reviews, and annual staff security training going forward.
Estimated effort and cost by path:
The fastest, lowest-cost path is to route card data entirely to a compliant provider, qualifying you for SAQ A. Every hour you spend simplifying your payment architecture pays back in reduced annual compliance effort.
What your payment processor actually covers, and what it doesn't
This is the most common misconception in small-business PCI compliance: "I use Square (or Stripe), so I'm covered." Payment processors reduce your technical scope, but they do not remove your contractual obligation to validate compliance and submit annual paperwork.
Here is what hosted and tokenized processors actually do:
- Hosted checkout: Card data is entered directly on the processor's page and never touches your server. Your scope shrinks to SAQ A, but you still must complete and submit that SAQ annually.
- Tokenization: The processor replaces card numbers with a token your system stores instead. You can charge the token for recurring billing without ever handling the real card number.
- P2PE (Point-to-Point Encryption): Card data is encrypted at the terminal before it reaches any network. A validated P2PE solution can reduce card-present scope to SAQ B-IP or lower.
What processors cover vs. what you still own:
| Area | Processor responsibility | Merchant responsibility |
|---|---|---|
| Card data encryption in transit | Yes | Confirm processor is PCI-certified |
| Secure storage of card numbers | Yes (tokenization) | Do not store raw card data locally |
| Annual SAQ completion | No | Merchant completes and submits |
| AOC submission to acquirer | No | Merchant signs and submits |
| Network security around the checkout | No | Merchant segments and secures |
| Staff access controls and passwords | No | Merchant enforces |
| Incident response plan | Partial | Merchant must have own plan |
Do you need to be PCI compliant if you use Square or Stripe? Yes. Both Square and Stripe are PCI-certified service providers, and using them dramatically reduces your scope. But you still must complete the annual SAQ, sign the AOC, and confirm that your environment around the processor is secure. Simplify your setup rather than assume the processor handles everything.

Common mistakes that expand your scope and increase breach risk
Most small-business PCI failures trace back to a handful of avoidable errors. Here is where businesses get into trouble, and how to fix each one.
-
Storing card data in spreadsheets or paper logs. This is the single most common mistake and the one most likely to cause a breach. Fix: delete all stored card data, confirm deletion with your IT provider, and switch to tokenized recurring billing.
-
Flat networks where guest Wi-Fi shares scope with payment systems. If a customer on your guest network can reach the same segment as your point-of-sale terminal, your entire network is in scope. Fix: segment the POS network with a VLAN or separate router. Effort: 2, 4 hours for a qualified technician.
-
Default or weak passwords on terminals and routers. Factory-default credentials are the first thing attackers try. Fix: change every default password, enforce a minimum 12-character policy, and document the change. Effort: under an hour.
-
Embedded JavaScript payment forms without proper controls. An SAQ A-EP environment requires you to monitor the integrity of your payment scripts. A compromised script (Magecart-style attack) can silently skim card data. Fix: move to a hosted redirect checkout to drop to SAQ A, or implement script integrity monitoring.
-
Skipping quarterly ASV scans. Many small businesses complete their SAQ but forget the scan requirement. Fix: schedule all four scans at the start of the year, or confirm your payment provider bundles scanning.
Pro Tip: If your SAQ feels overwhelming, that is a signal your payment architecture is too complex. Simplify first: redirect to a hosted payment page, remove any local card storage, and deploy a validated P2PE terminal for in-person sales. Most small businesses can reach SAQ A or SAQ B-IP with one afternoon of configuration changes, and those SAQs are manageable without outside help.
Where to get vetted help and official resources
Start with the PCI SSC's official resources, they are free, authoritative, and regularly updated.
Official resources to bookmark:
- SAQ forms and instructions: Download directly from the PCI SSC merchants page. Each SAQ includes a guidance document explaining every question.
- PCI SSC Small Merchant Guide: A plain-language PDF covering device selection, vendor questions, and incident contacts. Print it and keep it with your compliance documentation.
- ASV list: Search the PCI SSC site for "Approved Scanning Vendors" to find a current, vetted list of scan providers.
- QSA directory: If your environment is complex or you are unsure which SAQ applies, a QSA can advise you without conducting a full audit. Search the PCI SSC QSA company list.
- Validated payment device list: Confirm your terminal is on the PCI SSC's list of approved PIN Transaction Security (PTS) devices before deploying it.
- Visa and Mastercard registries: Both card brands publish lists of registered service providers. Confirm your processor appears on the Visa Global Registry of Service Providers or the Mastercard SDP Program list before signing a contract.
Questions to ask every service provider:
- Are you a PCI DSS Level 1 certified service provider?
- Do you provide an AOC or Responsibility Matrix I can share with my acquirer?
- Does your service include ASV scanning, or do I arrange that separately?
- What is your incident notification process if a breach affects my data?
How a managed IT partner reduces your PCI workload
A managed IT partner does not replace your obligation to validate, but it handles the technical heavy lifting so you can focus on running your business. Here is what a qualified partner delivers:
Ongoing deliverables:
- SAQ preparation and evidence collection (network diagrams, access logs, policy documentation)
- ASV scan scheduling and remediation coordination
- Terminal management and P2PE deployment for card-present environments
- Network segmentation design and implementation
- MFA rollout across all in-scope accounts (see why MFA matters for the technical case)
- Log retention and patch management to satisfy PCI Requirements 10 and 6
- Incident response plan templates and annual tabletop exercises
What the recurring engagement looks like:
A managed IT contract with fixed per-user pricing covers the recurring tasks, quarterly ASV scheduling, monthly patching, log review, and annual SAQ prep, as predictable line items rather than surprise invoices. That pricing model matters for compliance: you know exactly what you are spending, and nothing falls through the cracks between billing cycles.
How to validate a partner's PCI experience:
- Ask for a sample network diagram or SAQ evidence package they have produced for a similar client.
- Confirm they have worked with your acquirer's specific validation process.
- Check whether they maintain relationships with an ASV or QSA for referrals.
- Ask how they handle small-business cyber threats beyond PCI scope, incident response and breach notification are equally important.
The first step is typically a paid IT and security assessment that maps your current payment flows, identifies scope, and produces a prioritized remediation roadmap. Some partners offer a free risk score as an entry point before committing to a full assessment.
The scope-first approach is the only one that actually works
Most small businesses approach PCI compliance the wrong way: they download the SAQ, feel overwhelmed by the question count, and either guess at answers or hire someone to do the same. Neither approach fixes the underlying problem.
The businesses we work with that get through compliance fastest share one trait: they simplified their payment architecture before they touched the SAQ. Moving from an embedded JavaScript checkout to a hosted redirect takes an afternoon. Deploying a validated P2PE terminal for card-present sales takes a day. Those two changes can move a business from SAQ D territory to SAQ A or SAQ B-IP, cutting the question count from 329 to 22 or 61, and eliminating the penetration test requirement entirely.
The other thing worth saying plainly: PCI compliance is the floor, not the ceiling. We see businesses that pass their annual SAQ and then get hit by a phishing attack or an ACH diversion scheme that PCI never addressed. The standard covers card data. It does not cover your email, your banking credentials, or your backup strategy. Treat compliance as the starting point and build from there.
Collett Systems LLC handles the PCI compliance work you don't have time for
PCI compliance for a small business does not have to mean months of confusion and surprise costs. Collett Systems LLC delivers a fixed-cost managed IT engagement that covers SAQ preparation, ASV scan coordination, network segmentation, MFA deployment, and ongoing log and patch management, everything your acquirer needs to see, documented and ready.
The first step is a paid IT and Security Assessment that maps your payment flows, identifies your SAQ type, and produces a clear remediation roadmap with timeline and cost estimates. No guesswork, no open-ended hourly billing. For businesses that already have internal IT staff, our co-managed IT services let your team handle day-to-day support while we own the compliance and security layer.
Book your assessment or take our 60-second IT risk score to see where your biggest gaps are before your next acquirer deadline.
Sources
Bookmark these official and high-value resources as you work through your compliance plan:
- PCI Security Standards Council, Merchants
- PCI DSS Compliance for Small Business: Requirements Guide (2026), SmallBizHandbook
- PCI compliance for small business, Paytia
- What Is PCI Compliance and Does My Small Business Need It?, COMNEXIA
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
