What Is PCI DSS? v4.0.1 Explained for Small Business

PCI DSS (Payment Card Industry Data Security Standard): The Rules Behind Every Card Swipe

If your business accepts, processes, stores or transmits credit or debit card data, PCI DSS is the security standard you agreed to follow when you started taking cards, whether or not anyone handed you a copy.

PCI DSS has been around since 2004, and it reaches more businesses than most owners realize. If you take Visa, Mastercard, American Express or Discover in person, online or over the phone, you are in scope. That includes retailers, restaurants, medical and dental practices, law firms and anyone with a point-of-sale system or online checkout.

What does PCI DSS stand for?

Payment Card Industry Data Security Standard. The major card brands (Visa, Mastercard, American Express, Discover and JCB) formed the PCI Security Standards Council (PCI SSC) in 2006 to manage it. The current version is PCI DSS v4.0.1, published in June 2024. Version 4.0 was retired at the end of 2024, and the requirements that v4 had marked as "future-dated" became mandatory on March 31, 2025.

PCI DSS isn't a law. It is a contractual requirement, enforced through your merchant agreement with your payment processor and acquiring bank. Nobody goes to jail over it, but a business can face fees and fines passed down by its processor, liability for fraud losses after a breach, and in serious cases the loss of its ability to accept cards.

The simple way to think about it

Think of the card brands as a landlord who lets you use their payment network, on the condition that you keep the building up to code. PCI DSS is the code. You agreed to it when you signed up to accept cards.

Who has to comply, and at what level?

The card brands sort merchants into levels by annual transaction volume, and the level decides how you prove compliance. Using Visa's thresholds as an example:

  • Level 1: more than 6 million transactions a year (or a merchant that has had a breach). Annual on-site assessment by a Qualified Security Assessor (QSA) and quarterly network scans.
  • Level 2: 1 to 6 million transactions a year. Annual self-assessment (or assessment as the acquirer requires) and quarterly scans.
  • Level 3: 20,000 to 1 million e-commerce transactions a year. Annual Self-Assessment Questionnaire (SAQ) and quarterly scans.
  • Level 4: fewer than 20,000 e-commerce transactions, or up to about 1 million total transactions. Annual SAQ, with scans as your processor requires.

Most small and midsize businesses are Level 3 or 4, so their main tool is the SAQ. There are several types (SAQ A, A-EP, B, B-IP, C, C-VT, P2PE and D), and the right one depends on exactly how you take and handle card data. Picking the wrong SAQ is a common mistake.

What PCI DSS requires

PCI DSS v4 is built around 12 principal requirements:

  1. Install and maintain network security controls.
  2. Apply secure configurations to all system components.
  3. Protect stored account data.
  4. Protect cardholder data with strong cryptography during transmission over open, public networks.
  5. Protect all systems and networks from malicious software.
  6. Develop and maintain secure systems and software.
  7. Restrict access to system components and cardholder data by business need to know.
  8. Identify users and authenticate access to system components.
  9. Restrict physical access to cardholder data.
  10. Log and monitor all access to system components and cardholder data.
  11. Test the security of systems and networks regularly.
  12. Support information security with organizational policies and programs.

Two v4 changes matter most for small businesses. First, multi-factor authentication (MFA) is now required for all access into the cardholder data environment, not just remote access. Second, v4 introduced a "customized approach" that lets organizations meet a requirement's objective in their own way, as long as they can show it works. Most small merchants will stick with the standard ("defined") approach.

The "we use a payment processor, so we're fine" myth

Using a processor such as Square, Stripe or Toast doesn't take you out of PCI DSS scope. It can shrink your scope a lot. If the processor handles card data entirely and you never see or store full card numbers, you'll likely have a short SAQ. You still have to complete it and meet the requirements that apply.

Scope grows the moment card data touches your own systems, even briefly: a payment terminal on the same network as your office computers, a phone order written on a notepad, a card number saved in a spreadsheet "just in case." Each one adds obligations.

Reducing scope is one of the most useful things an IT provider can do for a business that takes cards: separate the payment network from everything else, use hosted payment pages or validated point-to-point encryption, and get rid of stored card data you don't need.

What happens when PCI DSS is violated?

Consequences flow through your acquiring bank and processor, not a government regulator. They can include monthly non-compliance fees, fines passed down from the card brands, the cost of a required forensic investigation after a breach, liability for fraud losses and card reissuance, and in serious cases termination of your ability to accept cards. Being able to show you were compliant when a breach happened generally puts you in a much better position when costs are assigned.

Card data can also trigger state breach laws. In Florida, the Florida Information Protection Act (FIPA) is the data security and breach notification law that can apply alongside PCI DSS.

How PCI DSS connects to managed IT services

Much of PCI DSS overlaps with good everyday IT security, which is why a Managed Service Provider (MSP) can carry much of the technical load. That includes:

  • Network segmentation to keep point-of-sale systems apart from the rest of the network
  • Patch management through RMM
  • Access controls and MFA, with unique user IDs and least-privilege access
  • Logging and monitoring of access to systems in scope
  • Vulnerability scanning, including coordinating quarterly external scans by an Approved Scanning Vendor (ASV)
  • Malware protection, including EDR on in-scope devices

NerdSquad helps retailers, restaurants and professional offices in Southwest Florida put these controls in place and keep the documentation that supports their SAQ. Your processor and, where required, a QSA make the compliance determination.

How PCI DSS fits with other frameworks

  • Medical and dental practices that take cards may need to satisfy both HIPAA and PCI DSS.
  • Financial firms may face PCI DSS alongside GLBA, SEC rules and SOC 2 requests.
  • Any business with customers in several states may also face those states' breach and privacy laws.

The controls that support PCI DSS (access control, encryption, logging, patching, endpoint protection) are largely the same ones other frameworks expect, and many map to NIST frameworks. Build the foundation once and document it well, and each framework becomes much easier to handle.

Quick reference

  • PCI SSC: the council that maintains the standard.
  • Merchant levels: 1 to 4, by transaction volume.
  • SAQ: the self-assessment most small businesses complete.
  • QSA: an assessor required for Level 1 merchants and some other cases.
  • Scope: the systems, networks and people that touch card data. Smaller scope means simpler compliance.
  • Current version: v4.0.1; all v4 requirements mandatory since March 31, 2025.

NerdSquad is not a law firm; confirm your obligations with your compliance counsel and your payment processor.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: IT support for retail businesses