Compliance
PCI compliance for small business: what you actually have to do this year
PCI-DSS gets explained in the abstract constantly. This is the short, concrete list of what a small merchant realistically has to do, in order.
If you want the full explanation of what PCI-DSS is and who created it, our PCI compliance guide covers that. This post skips the background and goes straight to the four things a small merchant using a modern smart terminal actually needs to do this year.
1. Complete your annual Self-Assessment Questionnaire (SAQ)
Most small merchants using PCI-validated, point-to-point encrypted hardware qualify for a short-form SAQ rather than a full technical audit. Your processor or acquiring bank typically provides this annually — it's usually a matter of minutes to complete, not a security engagement. If you've been seeing a recurring PCI non-compliance fee on your statement, this is almost always the reason, and completing the SAQ is the fix.
2. Never key in, write down, or store raw card numbers
The single biggest compliance risk for a small business isn't a technical vulnerability — it's a staff member writing a card number on a sticky note, or keying in a number from a phone call into an unsecured system. Using your terminal's built-in tap/dip/swipe capture (or a secure card-not-present flow for phone orders, if your processor offers one) keeps raw card data out of your hands entirely, which removes most of the actual risk this whole standard exists to prevent.
3. Confirm your hardware is still PCI-validated and encrypted end-to-end
Point-to-point encryption (P2PE) means card data is encrypted the instant it's captured and stays encrypted until it reaches the processor — your terminal itself never has access to readable card numbers. Confirm with whoever supplied your terminal that it's on a current, PCI-validated hardware and software version; if you're using older or unsupported hardware, that's worth addressing before it becomes a bigger compliance gap.
4. Limit who can access payment devices and any related systems
Basic access control — not sharing terminal admin logins, not leaving a terminal logged into an unlocked back-office account, and knowing who on staff can access transaction history or refunds — covers the access-control piece of PCI-DSS for most small merchants. This doesn't require a formal IT policy for a five-person shop; it just means being deliberate about who can touch payment-related settings.
A quick note on how this applies if you take phone or online orders
The four items above assume most of your volume comes through a physical terminal. If you also take phone orders or sell online, the same core principle still applies — never write down or store a customer's card number in a spreadsheet, email, or notepad. Ask your processor whether they offer a secure card-not-present entry method or a virtual terminal built for this purpose, so a phone order goes through the same encrypted path as an in-person tap instead of being keyed in from a handwritten note.
That's the realistic list
For a merchant using compliant, encrypted hardware and not storing card data manually, these four items are genuinely the bulk of what PCI compliance requires in practice — not a year-round technical program. If your SAQ is current and your hardware is validated, you're covering the vast majority of what the standard asks of a business your size.
Is completing the SAQ actually required, or optional?
Do I need a full security audit as a small merchant?
What's the single biggest compliance mistake small merchants make?
What does point-to-point encryption (P2PE) actually protect against?
Ready to see your own numbers?
Run your real card volume through the calculator or apply in about two minutes.