If your business accepts, processes, stores or transmits credit or debit card data, PCI DSS is the security standard you agreed to follow when you started taking cards, whether or not anyone handed you a copy.
PCI DSS has been around since 2004, and it reaches more businesses than most owners realize. If you take Visa, Mastercard, American Express or Discover in person, online or over the phone, you are in scope. That includes retailers, restaurants, medical and dental practices, law firms and anyone with a point-of-sale system or online checkout.
Payment Card Industry Data Security Standard. The major card brands (Visa, Mastercard, American Express, Discover and JCB) formed the PCI Security Standards Council (PCI SSC) in 2006 to manage it. The current version is PCI DSS v4.0.1, published in June 2024. Version 4.0 was retired at the end of 2024, and the requirements that v4 had marked as "future-dated" became mandatory on March 31, 2025.
PCI DSS isn't a law. It is a contractual requirement, enforced through your merchant agreement with your payment processor and acquiring bank. Nobody goes to jail over it, but a business can face fees and fines passed down by its processor, liability for fraud losses after a breach, and in serious cases the loss of its ability to accept cards.
Think of the card brands as a landlord who lets you use their payment network, on the condition that you keep the building up to code. PCI DSS is the code. You agreed to it when you signed up to accept cards.
The card brands sort merchants into levels by annual transaction volume, and the level decides how you prove compliance. Using Visa's thresholds as an example:
Most small and midsize businesses are Level 3 or 4, so their main tool is the SAQ. There are several types (SAQ A, A-EP, B, B-IP, C, C-VT, P2PE and D), and the right one depends on exactly how you take and handle card data. Picking the wrong SAQ is a common mistake.
PCI DSS v4 is built around 12 principal requirements:
Two v4 changes matter most for small businesses. First, multi-factor authentication (MFA) is now required for all access into the cardholder data environment, not just remote access. Second, v4 introduced a "customized approach" that lets organizations meet a requirement's objective in their own way, as long as they can show it works. Most small merchants will stick with the standard ("defined") approach.
Using a processor such as Square, Stripe or Toast doesn't take you out of PCI DSS scope. It can shrink your scope a lot. If the processor handles card data entirely and you never see or store full card numbers, you'll likely have a short SAQ. You still have to complete it and meet the requirements that apply.
Scope grows the moment card data touches your own systems, even briefly: a payment terminal on the same network as your office computers, a phone order written on a notepad, a card number saved in a spreadsheet "just in case." Each one adds obligations.
Reducing scope is one of the most useful things an IT provider can do for a business that takes cards: separate the payment network from everything else, use hosted payment pages or validated point-to-point encryption, and get rid of stored card data you don't need.
Consequences flow through your acquiring bank and processor, not a government regulator. They can include monthly non-compliance fees, fines passed down from the card brands, the cost of a required forensic investigation after a breach, liability for fraud losses and card reissuance, and in serious cases termination of your ability to accept cards. Being able to show you were compliant when a breach happened generally puts you in a much better position when costs are assigned.
Card data can also trigger state breach laws. In Florida, the Florida Information Protection Act (FIPA) is the data security and breach notification law that can apply alongside PCI DSS.
Much of PCI DSS overlaps with good everyday IT security, which is why a Managed Service Provider (MSP) can carry much of the technical load. That includes:
NerdSquad helps retailers, restaurants and professional offices in Southwest Florida put these controls in place and keep the documentation that supports their SAQ. Your processor and, where required, a QSA make the compliance determination.
The controls that support PCI DSS (access control, encryption, logging, patching, endpoint protection) are largely the same ones other frameworks expect, and many map to NIST frameworks. Build the foundation once and document it well, and each framework becomes much easier to handle.
NerdSquad is not a law firm; confirm your obligations with your compliance counsel and your payment processor.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.
Related: IT support for retail businesses