Skip to content
English - United States
  • There are no suggestions because the search field is empty.

What Is PCI Compliance and Does My Business Need It?

If you accept cards, PCI DSS applies to you. What it requires and what compliance looks like.

PCI compliance means meeting the Payment Card Industry Data Security Standard (PCI DSS), a set of security requirements that applies to every business that stores, processes or transmits payment card data, regardless of size. It is not a law; it is a contractual obligation enforced through your card processor and the card brands, with fines and higher fees for non-compliance.

Who it applies to

Any business that accepts credit or debit cards: retail, restaurants, e-commerce, professional services that take card payments, nonprofits taking donations by card. If a card number touches your systems, your website, your phone lines or your paper forms, PCI DSS applies.

What the standard requires

PCI DSS (currently version 4.0.1) organizes its requirements into twelve areas, including:

  • Firewalls and secure network configuration.
  • No vendor default passwords.
  • Protecting stored cardholder data (and not storing it when you do not have to).
  • Encrypting card data in transit.
  • Anti-malware and secure systems, kept patched.
  • Restricting access to cardholder data on a need-to-know basis, with unique IDs and MFA.
  • Physical security for systems and media.
  • Logging and monitoring access.
  • Regular testing, including vulnerability scans and penetration tests.
  • A written security policy and staff training.

What compliance looks like for a smaller business

Most small and mid-sized merchants validate compliance by completing a Self-Assessment Questionnaire (SAQ) matched to how they take payments, passing quarterly external vulnerability scans from an approved vendor where required, and attesting annually. The simplest path is to keep card data out of your environment entirely by using a validated payment terminal or a hosted payment page, which shrinks the scope dramatically. See PCI compliance levels and SAQs.

Where IT comes in

Network segmentation to isolate payment systems (what is network segmentation), firewall configuration, patching, MFA, logging, scanning and penetration testing are IT controls, and they are most of the technical work. Costs are covered in how much PCI compliance costs.

Mentis Group provides PCI compliance consulting and IT support in Dallas-Fort Worth, helping businesses scope their environment, implement the technical controls, complete the SAQ and maintain compliance year to year. This article is a summary; the PCI Security Standards Council publishes the full standard.

Have a question about your own environment? Schedule a consultation with Mentis Group or call (866) 901-7808.