Compliance
PCI DSS 4.0: What Changed and What Small Merchants Actually Need to Do
PCI DSS updates tend to sound alarming in headlines, but the actual practical impact on a small merchant using a modern point-of-sale or payment gateway is usually narrower than it first appears -- most of the heaviest new requirements target larger merchants processing at higher volumes or storing card data directly.
Why merchant level matters here
PCI compliance requirements scale with transaction volume and how card data is handled -- a merchant using a compliant, tokenized payment terminal that never actually stores card numbers has a meaningfully lighter compliance burden than one processing large volumes or storing data directly. Most small merchants fall into the lighter-burden category by virtue of how modern terminals already work.
What a small merchant should actually check
Confirm with your processor or gateway provider that your specific setup is PCI DSS 4.0 compliant (most modern providers handle this at the infrastructure level), complete your annual self-assessment questionnaire (SAQ) if required, and avoid ever storing card numbers in spreadsheets, email, or notes -- a habit that creates real compliance and security exposure regardless of PCI version.
The version number changed. For most small merchants using a modern, tokenized terminal, the practical checklist barely did.
Where this is not general advice
Merchants processing higher volumes, storing card data directly, or operating in industries with additional regulatory requirements should confirm their specific PCI DSS 4.0 obligations directly with their processor or a qualified security assessor -- this overview is general education, not a compliance determination for any specific business.
Confirm your setup is compliant
Check with our team whether your current terminal and processing setup meets PCI DSS 4.0 requirements.