PCI compliance for small business, explained
If you take cards, you are already in the PCI system. Nobody may have told you that. Here is the good news. For most small businesses it is a short questionnaire once a year. And there is a fee on your statement you can probably make go away by finishing it.
What PCI compliance actually is
PCI stands for Payment Card Industry. PCI compliance means following the card industry's security standard. That standard is the PCI DSS. It covers how you handle cardholder data. The card brands wrote it. It applies to every business that accepts cards. That runs from a one-terminal coffee shop to a chain. No government agency enforces it. The card networks do, through your processor.
For most small businesses this is far less scary than it sounds. Say you take cards on a modern terminal or POS that encrypts the data. Then you are not storing card numbers yourself. Proving compliance is mostly a yearly questionnaire that says so.
The fee hiding on your statement
Here is the part that costs real money. It is the PCI non-compliance fee. When your compliance paperwork is not done, many processors quietly add a monthly charge. It runs $10 to $40, sometimes more. It is one of the most common junk fees we find when we read a statement. Merchants often pay it for years. They do not know what it is, or that finishing a form makes it go away.
Worth being clear: that fee is not the cost of being secure. It's a charge for not having turned in your homework. Complete the assessment and it should come off the next statement.
How to become compliant, step by step
Find your SAQ.SAQ is short for Self-Assessment Questionnaire. There is more than one, and the right one depends on how you take cards. A swipe-only countertop terminal gets a much shorter form. A website that handles card numbers gets a longer one. Your processor's compliance portal points you to yours.
Answer it accurately and run a scan if needed. Most small businesses that take cards in person fill out a short questionnaire and are done. Do you key cards into a computer? Do you run your own online checkout? Then you may also need a quarterly network scan. The portal can run that scan for you.
Shrink your scope with the right equipment. The best single move is using terminals and a setup that encrypt card data right at the point of sale. Card numbers then never touch your computers or your network. Less exposure means a shorter questionnaire and less to worry about.
Where a broker fits
None of this needs a broker. But it is the kind of small, annoying task that quietly costs you until someone handles it. When we read your statement, the PCI non-compliance fee is one of the first things we look for. We put you on equipment that keeps card data out of your systems. We point you to the right questionnaire and help you get it done. Then we check that the fee drops off. It is a small thing. It is easy to ignore and easy to fix.
Fair questions
What is PCI compliance, in plain English?
It is a set of card industry security rules. The full name is the PCI Data Security Standard. Everyone who takes cards has to follow it. You prove it each year with a self-assessment questionnaire. Some businesses also run a network scan.
Is PCI compliance actually required?
Yes. The card brands require it. That means Visa, Mastercard and the rest. It applies to any business that takes their cards. It is not optional. For most small merchants it is also not complicated.
What is the 'PCI non-compliance fee' on my statement?
It is a monthly fee, often $10 to $40. A processor charges it when you have not finished your compliance paperwork. Finish the questionnaire and that fee should come off. Run a scan too if your setup needs one. Many merchants pay this fee for years. Most never learn they can stop it.
What do I have to do to get compliant?
Fill out the Self-Assessment Questionnaire, or SAQ. Pick the one that matches how you take cards. Run a quarterly network scan if your setup needs one. Use equipment that keeps card data out of your systems. A good processor gives you the portal and walks you through it.
Does becoming compliant cost extra?
Usually no. The compliance program is normally part of what you already pay. The thing that costs you is the non-compliance fee. That is the charge for not finishing. Get compliant and you stop paying it.
Can a broker help with PCI?
Yes. We put you on equipment that shrinks your PCI scope. We point you to the compliance portal. We help you answer the questionnaire accurately. Then we check that the non-compliance fee comes off.
Send one statement. Plain-English answer in 24 hours.