Compliance
PCI compliance, explained without the jargon
PCI-DSS gets mentioned constantly and explained rarely. Here's what it actually is, who requires it, and what it means for a small business owner.
PCI-DSS (Payment Card Industry Data Security Standard) is a set of security requirements created by the major card networks, covering how businesses handle, process, and store cardholder data. It applies to any business that accepts credit or debit cards, regardless of size.
Who created it, and who enforces it
PCI-DSS is maintained by the PCI Security Standards Council, founded by Visa, Mastercard, American Express, Discover, and JCB. It isn't a government regulation — enforcement happens through the card networks and, practically speaking, through your payment processor or acquiring bank, who require merchants to demonstrate compliance as a condition of processing cards.
What it requires, at a high level
Secure networks
Firewalls and secure configurations protecting any system that touches card data.
Protected cardholder data
Encryption in transit and at rest; never storing full card numbers or security codes unnecessarily.
Access control
Limiting who can see or touch card data, and monitoring/testing systems regularly.
What this means for a small merchant, practically
If you use a modern, PCI-validated payment terminal with point-to-point encryption and never key in or store raw card numbers on your own computer or paper, most of the technical burden is handled by the hardware and processor. Small merchants typically satisfy their obligation by completing a short annual Self-Assessment Questionnaire (SAQ) — not a full technical audit. Ask your processor which SAQ level applies to how you accept payments.
Is PCI compliance a law?
What happens if my business isn't PCI compliant?
Do I need to do anything if I use a modern smart terminal?
Ready to see your own numbers?
Run your real card volume through the calculator or apply in about two minutes.