DFW Pay Pros logo
DFW Pay Pros
Merchant Services & Equipment
(817) 583-1169 info@dfwpaypros.com
Get My Free Savings Analysis
Compliance

PCI Compliance for Small Business: What You File and What You Pay

PCI compliance for small business comes down to one Self-Assessment Questionnaire a year, filed online through your processor’s portal. Most small businesses are Level 4 merchants, which means SAQ A or SAQ B-IP, the short ones. Your processor bills a small monthly PCI fee either way, plus a much bigger non-compliance fee if you never file.

Two PCI charges, and people mix them up. One is a few dollars a month. The other is what you pay for not doing paperwork.

Boring little line item. It’s been billing somebody since they signed the application.

What is PCI compliance, in plain terms?

PCI DSS stands for the Payment Card Industry Data Security Standard, written by the card brands through a body they own jointly, the PCI Security Standards Council, or PCI SSC. Congress had nothing to do with it. These security standards sit in the contract you signed to accept cards, and they bind you about as tightly as a law would.

The standard covers how cardholder data gets stored, moved and locked down. Firewalls, patching, who’s allowed to touch what, and the receipt with a card number on it. A big enterprise handles that with auditors. A coffee shop answers a questionnaire honestly.

Your acquirer is the party that cares. The acquiring bank owes the networks money if your business leaks credit card data, so your merchant bank pushes validation down to you. Nobody at Visa is auditing your quilt shop.

What counts as cardholder data, and what you must never store

Scope is the whole game.

Cardholder data means the primary account number (the credit card number itself) plus the cardholder name, the expiration date and the service code. Hold the number and the other three come into scope.

Sensitive authentication data is the tighter category: full stripe or chip track data, the CVV2 or CVC2 or CID, PINs. None of it may be stored once a transaction is authorized. Not in a spreadsheet, not in a booking note, not in a recording of a phone order. Nine times out of ten it’s a card number and security code on an order pad, in a drawer, for a year.

Fix that one first.

Never store, process or transmit cardholder data in readable form and your scope collapses to almost nothing. So does your questionnaire.

Who has to comply, and which merchant level are you?

Everyone accepting credit cards. No revenue floor, no small-business exemption. Any business handling credit card transactions is in, and if you process transactions on the major card brands the PCI standards attach to your account.

Size changes how you prove it. The card brands sort merchants into four levels by transaction volume, counted per brand per year, and each level carries different documentation requirements. Visa’s merchant levels:

Level Rough volume per year How you validate
Level 1 Over 6 million, or by designation. Qualified Security Assessor on site, plus scans.
Level 2 1 million to 6 million. Annual self assessment, plus quarterly scans.
Level 3 20,000 to 1 million e-commerce. Annual self assessment, plus scans.
Level 4 Under 20,000 e-commerce, or 1 million total. Annual Self-Assessment Questionnaire, plus scans if needed.

Nearly every independent restaurant, shop and clinic is Level 4. Questionnaire, not auditor. Though merchants get bumped up a level after a data breach.

The 12 PCI DSS requirements, in small business terms

People expect four or five broad ideas. The PCI compliance requirements are twelve numbered items under six objectives, and the current version is PCI DSS v4.0.1. Requirements 3 and 4 protect cardholder data directly.

Six payment security objectives, twelve requirements

  • 1. Install and maintain network security controls. Firewalls and segmentation.
  • 2. Apply secure configurations to all system components. Do not use vendor supplied defaults for system passwords and other security parameters.
  • 3. Protect stored account data. The only fully compliant electronic storage of a card number is no storage.
  • 4. Use strong cryptography when you transmit cardholder data across open, public networks. Your terminal handles this.
  • 5. Protect all systems and networks from malicious software.
  • 6. Develop and maintain secure systems and software. With no in-house code, that’s patching.
  • 7. Restrict access to system components and cardholder data by business need to know. Minimum people, minimum rights.
  • 8. Identify users and authenticate access. Named logins, strong passwords, multifactor into the cardholder data environment.
  • 9. Restrict physical access to cardholder data. Locked back office.
  • 10. Log and monitor access to system components and cardholder data, so if someone did gain access you’d know.
  • 11. Test your systems and networks regularly. Usually an external scan for known security vulnerabilities.
  • 12. Support payment security with policy. A written information security policy, staff trained yearly. Two pages is a policy. Nothing isn’t.

The future-dated v4 items stopped being optional on 31 March 2025. Most compliance requirements still come back not applicable for one standalone terminal.

Which SAQ do most small merchants file?

SAQ is the Self-Assessment Questionnaire. Which one you file depends on how card payments reach your processor. Not revenue, not industry. Plumbing.

SAQ type Who it fits Effort
SAQ A E-commerce or phone orders, fully outsourced. Short. You attest to what you don’t do.
SAQ A-EP Never receives card data but controls the payment page. Much longer.
SAQ B Dial-up or imprint terminal. No internet, no electronic storage. Short.
SAQ B-IP Standalone PTS-approved terminal on an IP connection. Short to moderate.
SAQ C-VT Virtual terminal, manually keyed. Moderate.
SAQ C Payment application online, not segmented. Network questions get real.
SAQ P2PE Terminal running validated point-to-point encryption. Short.
SAQ D Everyone else, including anyone storing cardholder data. Hundreds of requirements.

The form feels brutal mostly when you’ve been routed to SAQ D by answering the scoping questions badly. Getting the right one is most of the work.

Validated P2PE shortens it dramatically: the credit card data is encrypted at the tap and your systems never see it readable. Worth caring which dual pricing terminal you’re on.

Every SAQ, the attestations and the other validation tools sit in the PCI SSC document library, free. You pay your processor for a portal and a scan.

Where SAQ A merchants get caught

The SAQ A to SAQ A-EP line is the most misread boundary in PCI DSS compliance. Redirect to your gateway’s hosted page and you’re usually SAQ A. Control the scripts where a customer types a credit card number and you’ve drifted toward SAQ A-EP. Version 4 added rules about monitoring payment page scripts. The trade-off isn’t subtle: the more you customize the checkout experience, the more of the standard you inherit.

Why does my processor charge a monthly PCI fee?

Because they’re paying a vendor for the platform, and marking it up. Your acquirer contracts with a compliance vendor who hosts the questionnaire and runs external scans. The vendor bills the processor. The processor bills you.

Part of the fee is defensible. The markup is where you push back, and it’s one line to check against what you’re really paying. Run it through the effective rate calculator. For example, $10 a month on $12,000 of volume is eight basis points. On $4,000, twenty-five.

PCI fee vs PCI non-compliance fee

Two charges, printed under confusingly similar names. The second is where the real money is.

PCI compliance fee PCI non-compliance fee
What triggers it Having a merchant account, validated or not. SAQ not on file, expired, or a failed scan.
Typical size Small monthly or annual line. Several times the compliance fee, monthly.
How you stop it Negotiate, or switch processors. Complete the questionnaire. It usually drops off next cycle.
Retroactive? n/a Ask. Some credit a recent month.

Processors say it offsets the risk of an unvalidated merchant. Some truth in that. It also prints money off everyone who never opened the enrollment email.

How do I complete the questionnaire and get the fee removed?

Less painful than its reputation. You need the portal’s name (ask your rep, or check your statement), your merchant ID, and a clear picture of how cards reach you. That last one matters most. How your terminal connects, whether your POS stores anything, whether anyone writes a card number down, whether your website touches payment data.

Then you log in, answer the scoping questions, land on the right SAQ and attest. A failed scan is the usual sticking point, usually a port left open or a router on its original firmware.

Expect the fee off your next statement or the one after. If it isn’t, call. And if the processor says it stays regardless of your compliance status, that tells you something.

Credit card security habits that matter more than the form

Four practices, paperwork aside:

  • Card numbers on paper are the one that gets people. Order pads, sticky notes, the notes field in your booking software. Shred them.
  • Change the default passwords. Router, POS admin, anything shipped as admin and admin. Strong passwords, one login per person.
  • Your payment device should not share network resources with the guest wifi. Segmenting it is an afternoon’s work and shrinks your scope for good.
  • Train whoever works the counter. Staff who handle payment information properly, and who recognise a phishing email from “your processor”, do more for payment security than the questionnaire does.

None of it costs money. Most of it is one Tuesday afternoon with the router manual open.

The mistakes that catch small businesses

Scope gets underestimated first. Merchants assume the terminal is the whole story, then remember the tablet that takes phone orders. Anything touching credit card information is in.

Third parties get forgotten next. If your web developer or IT contractor can reach your payment environment, their security is your problem. Payment processors and service providers have to confirm their own compliance status, so ask.

Then there’s point-in-time thinking. An attestation is one day’s snapshot, so staying PCI compliant means monitoring and updating your security practices. New employee, replaced router, a plugin dropped into the checkout.

Worst of all is remote administration of your POS or gateway with a password alone. Failed requirement, and the likeliest way you get hit.

Does a dual pricing or cash discount program change my PCI obligations?

No. Pricing and data security are separate tracks. A cash discount program at a 4% differential doesn’t move your SAQ. You still take cards, so you still validate.

Plumbing is what changes your SAQ, and because swapping a virtual terminal on a shared office PC for a standalone PTS-approved device can take you from SAQ C-VT to SAQ B-IP and cut the form down a lot, and because that swap tends to happen during a pricing change, merchants often credit the program for the simpler questionnaire. The device did that.

On pricing, cash discount vs surcharge has the models and Visa’s cash discount rules has the card brand requirements. Your signage doesn’t decide whether a program is a surcharge or a cash discount. The POS configuration does. 2026 is a Visa high-enforcement year, first-offense fines around $1,000 per location.

What happens if there’s a breach and I was never compliant?

Processors stay vague here, so plainly: a validated SAQ is one day’s claims, and it won’t shield you. If card data leaves your business, the forensic investigation looks at what was really going on.

A confirmed compromise can bring forensic investigator costs, card reissuance, fraud losses, legal fees, network fines assessed through your acquiring bank, and reputational damage that outlasts it. Merchants generally carry the costs of a data breach in their own environment, and non compliance makes it worse, because you’ve broken your merchant agreement too.

One terminal, no card storage, low odds, and the questionnaire really is just paperwork. Run an e-commerce cart or networked POS, or store credit card data for recurring billing, and it earns its time.

What it does for customer data

Customers won’t ask whether you’re PCI DSS compliant. What they notice is a letter saying their customer data walked out the door, and a business that never sends one keeps the confidence it already had. The standard exists to cut the odds of payment data being stolen.

Common questions about PCI

Do I have to redo it every year? Yes. The attestation expires annually, and the non-compliance fee comes back if you let it lapse. Re-attesting is quick if nothing changed.

Can I do this myself, or do I need to hire someone? A Level 4 merchant on a short SAQ can do it alone, because the self assessment is built for you to answer about your own environment. Hire help for SAQ D or A-EP.

Can I get PCI compliance for free? The questionnaires and validation tools are free from PCI SSC, and most of the security work costs nothing. Your processor’s portal fee usually isn’t, though some don’t charge one.

How do I know if I’m compliant right now? Log into the portal and look for a current attestation, then check your statement for a non-compliance fee. Those two answers cover it.

My POS company says they’re PCI compliant, so am I covered? No. Their validation may narrow your scope, but your merchant account needs its own attestation.

I use Square, do I need to do this? Aggregators handle validation differently and generally don’t bill a separate PCI fee. Part of the appeal, and part of why the economics diverge at volume. More in Square vs a merchant account.

Where DFW Pay Pros sits on this

DFW Pay Pros is an independent sales organization, selling merchant services on behalf of larger nationwide processors, in all 50 states.

On fees we’re blunt. No monthly fees of any kind. No contract, month to month, no early termination fee, cancel any time at no cost. First terminal’s free for most businesses. Hardware runs from the Valor VL550 to the Clover Station, Mini, Compact and Flex, plus PIN pads, printers, scanners and cash drawers.

We’ll point you at the right portal and the right SAQ. Scoping it correctly is the difference between a short form and a long one.

Send a recent statement and we’ll tell you which PCI line you’re paying and which you shouldn’t be. Approval can take as little as 24 hours with three months of statements. And if you’re moving, the switching process is duller than people expect.

Have us check your PCI fees

Send a recent statement and we’ll tell you what you’re being charged and why.

← All payments guides
Call Us Text Us