PayWavez PayWavez
Apply Now

Compliance

PCI compliance, explained without the jargon

PCI-DSS gets mentioned constantly and explained rarely. Here's what it actually is, who requires it, and what it means for a small business owner.

PCI-DSS (Payment Card Industry Data Security Standard) is a set of security requirements created by the major card networks, covering how businesses handle, process, and store cardholder data. It applies to any business that accepts credit or debit cards, regardless of size.

Who created it, and who enforces it

PCI-DSS is maintained by the PCI Security Standards Council, founded by Visa, Mastercard, American Express, Discover, and JCB. It isn't a government regulation — enforcement happens through the card networks and, practically speaking, through your payment processor or acquiring bank, who require merchants to demonstrate compliance as a condition of processing cards.

What it requires, at a high level

Secure networks

Firewalls and secure configurations protecting any system that touches card data.

Protected cardholder data

Encryption in transit and at rest; never storing full card numbers or security codes unnecessarily.

Access control

Limiting who can see or touch card data, and monitoring/testing systems regularly.

What this means for a small merchant, practically

If you use a modern, PCI-validated payment terminal with point-to-point encryption and never key in or store raw card numbers on your own computer or paper, most of the technical burden is handled by the hardware and processor. Small merchants typically satisfy their obligation by completing a short annual Self-Assessment Questionnaire (SAQ) — not a full technical audit. Ask your processor which SAQ level applies to how you accept payments.

Is PCI compliance a law?
No. PCI-DSS is an industry security standard created and enforced by the major card networks (Visa, Mastercard, Discover, Amex, JCB) through the PCI Security Standards Council — not a government law. Non-compliance can still carry real financial consequences through your processor or acquiring bank.
What happens if my business isn't PCI compliant?
Consequences vary by processor and circumstance, but can include monthly non-compliance fees, higher liability in the event of a data breach, and in serious cases, the loss of card-processing privileges.
Do I need to do anything if I use a modern smart terminal?
Using PCI-validated, point-to-point encrypted hardware and never storing raw card numbers on your own systems removes most of the burden. Most small merchants using compliant hardware only need to complete a short annual Self-Assessment Questionnaire (SAQ) provided by their processor or acquiring bank.

Ready to see your own numbers?

Run your real card volume through the calculator or apply in about two minutes.

See your savings Apply Now