Blue Valley PaymentsBLUE VALLEY PAYMENTS

Home Blog PCI Compliance: What It Actually Is and What It Actually Requires

PCI Compliance: What It Actually Is and What It Actually Requires

Every few months a business owner asks me some version of this: “My processor said I’m PCI compliant. Does that mean I’m done?” And the answer is no, which is awkward, because whoever told them that probably made it sound like the end of a checklist.

PCI compliance is worth understanding clearly, because the consequences of getting it wrong land on you, not your processor.

What PCI DSS actually is

PCI DSS stands for Payment Card Industry Data Security Standard. It’s a set of security requirements created and maintained by the major card networks (Visa, Mastercard, and the rest) to protect cardholder data. It’s not a government regulation, but it is a contractual requirement that applies to any business that accepts card payments. There’s no opting out, and the obligation doesn’t disappear because your processor is compliant.

That last part trips people up. Your processor maintaining their own PCI compliance covers their systems. Your business is a separate entity with its own compliance obligations, even if you never touch a card number directly.

What it actually involves for a small business

The specific requirements depend on how your business handles card data. The PCI Security Standards Council assigns merchants to different “levels” and “types” based on transaction volume and processing method. Most small businesses fall into a category where compliance involves completing a Self-Assessment Questionnaire (SAQ) and, in some cases, running a network vulnerability scan through an approved vendor.

The SAQ is a series of yes/no questions about your security practices. How are card numbers stored (or, ideally, not stored)? Who has access to your payment systems? Are your passwords changed from the factory defaults? Are your systems patched and updated? The questions vary by which SAQ type applies to you, and there are several, because the risk profile of a business taking payments only through a hosted payment page is different from one running its own payment terminal software.

The honest answer is that the questionnaire is not difficult for a business running a straightforward setup. Most of the questions amount to: are you doing basic security hygiene? Don’t write card numbers on paper. Don’t use “password” as your password. Keep your software updated. If the answer to most of those is yes, the SAQ is mostly paperwork.

If the answer to some of those is no, that’s the more important thing to fix.

Where the fees come in

Processors often charge a monthly or annual PCI compliance fee. In exchange for this, they typically provide access to a compliance portal where you complete the SAQ and sometimes run a scan. That part is legitimate. What’s less legitimate is when a processor also charges a separate “PCI non-compliance fee” every month a merchant hasn’t completed their SAQ, sometimes without clearly explaining what the non-compliance fee is for or how to make it stop.

(The fee for not doing the thing is often higher than the fee for doing the thing. The industry does love a quiet incentive.)

If you’re seeing a PCI-related line item on your statement and you’re not sure what it’s for or whether you’re actually in compliance, that’s worth finding out. Completing the SAQ is usually the fix, and your processor’s portal is usually where you do it.

What happens if you’re not compliant

If a breach occurs and you’re found to be non-compliant, the card networks can fine you, and you can be held liable for fraud losses and forensic audit costs. The numbers involved in those scenarios are large enough that this is not an area to treat casually. PCI compliance won’t guarantee you never have a breach, but non-compliance removes the protections that would otherwise limit your liability.

If your business situation is at all complex, a conversation with your processor about exactly which SAQ type applies to you is a reasonable place to start. Rules can also vary based on how your specific setup works, so if anything is unclear, getting confirmation in writing is worth the extra step.

If you want a second opinion on your statement and what you’re actually paying for, including any PCI-related fees, I’ll look at it for free. The Cost Savings Analysis doesn’t cost anything, and it doesn’t come with a sales pitch attached.

Want a second opinion on your own merchant statement? We'll review it for free.

Request Your Free Cost-Savings Analysis