Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Basics of PCI Compliance

The Basics of PCI Compliance

Businesses today should be accepting card-based payments, regardless of their size. In addition to the convenience it offers to customers, it’s the most secure means you have of being paid. To protect consumers and their personal and financial information, many card providers have adopted a unified regulation that applies to businesses that accept these payments. Let’s review this regulation and how it impacts the average small-to-medium-sized business.

Understanding PCI

Established in 2006, the Payment Card Index Digital Security Standard (or PCI DSS) was sponsored by the members of the PCI Security Standards Council. This council was founded to help the credit card industry self-regulate and manage the standards for consumer privacy that businesses would be beholden to. You certainly have at least one of the council’s members in your wallet right now: Visa, Mastercard, American Express, and Discover.

The standards that this council established apply to any and all businesses that accept payment cards from their customers. If you process or store payment information or process digital payments, PCI compliance is mandatory.

To remain compliant, any business that accepts payment cards needs to: 

  1. Change passwords from system default
  2. Install sufficient network security tools (antivirus, firewalls, etc.) that will work to protect card data
  3. Encrypt transmission of card data across public networks
  4. Restrict the transmission of card and cardholder data to a “need to know” basis
  5. Assign user ID to all users with server or database access
  6. Make efforts to protect physical and digital access to card and cardholder data
  7. Monitor and maintain system security
  8. Test system security regularly
  9. Create written policies and procedures that address the importance of securing cardholder data
  10. Train staff on best practices of accepting payment cards

Any business, all businesses, each and every business of any kind that takes credit card payments needs to get these ten things done. Many businesses already accomplish these things as part of their typical routine… if you aren’t one of them, and accept card-based payments, your non-compliance could get you in serious trouble.

PCI and the Size of Your Business

The above checklist were the things that all businesses are responsible for, across the board. Based on what “level” of business you operate (according to the PCI Security Standards Council) there are other needs you must address. As the council defines them, there are four different levels you may fall into:

  • Merchant Level #1 - A business that processes over six million payment card transactions per year.
  • Merchant Level #2 - A business that processes between one million-to-six million payment card transactions per year.
  • Merchant Level #3 - A business that processes between 20,000-to-one million e-commerce payment card transactions per year.
  • Merchant Level #4 - A business that processes less than 20,000 e-commerce payment transactions, and fewer than one million overall payment card transactions per year.

As a level one breach will almost certainly have an impact to a larger number of consumers, the focus of the PCI regulatory body tends to be on these larger organizations. The means just aren’t there for every business to be checked constantly. However, that doesn’t mean that small businesses aren’t also facing severe risks. Here are some of the other requirements that businesses must fulfill, based on their Merchant Level:

Merchant Level #1

Considering the scale of these businesses and the reach that they have to consumers both online and in-store, these merchants have much greater responsibility. PCI compliance for Merchant Level 1 requires that merchants:

  • Complete a yearly Report on Compliance (ROC) through a Qualified Security Assessor (QSA)
  • Undergo a quarterly network scan by an Approved Security Vendor (ASV)
  • Complete the Attestation of Compliance Form for PCI Council records

Merchant Level #2

Standards relax as the number of transactions decreases, so Merchant Level 2 dictates that these merchants:

  • Perform a yearly Self-Assessment Questionnaire (SAQ)
  • Allow an ASV to complete a quarterly network scan
  • Complete the Attestation of Compliance Form for PCI Council records

Merchant Level #3

This is where most medium-sized businesses would classify, and also requires that merchants:

  • Perform a SAQ
  • Allow an ASV to complete a quarterly network scan
  • Complete the Attestation of Compliance Form for PCI Council records

Merchant Level #4

This level applies to the vast majority of small businesses. Like the prior two merchant levels, this level requires that all merchants:

  • Perform a SAQ
  • Allow an ASV to complete a quarterly network scan
  • Complete the Attestation of Compliance Form for PCI Council record

Noncompliant businesses can be reviewed, and are generally fined, watched more closely in the future, or even prohibited from accepting payment cards at all. Obviously, this isn’t something you want to happen to your business.

To find out more about PCI DSS standards and what you can do to ensure your compliance, give the IT professionals at Voyage Technology a call at 800.618.9844 today.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Wednesday, 04 February 2026

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Efficiency Hardware Network Security User Tips Internet Malware IT Support Privacy IT Services Email Google Workplace Tips Computer Phishing Collaboration Hosted Solutions Workplace Strategy Users Ransomware Small Business Mobile Device Backup Productivity Microsoft Managed Service Quick Tips Saving Money Passwords Communication Cybersecurity Data Backup Smartphone AI Data Recovery Android Upgrade Disaster Recovery Business Management Smartphones VoIP Mobile Devices communications Windows Browser Social Media Managed IT Services Microsoft Office Network Current Events Tech Term Remote Internet of Things Automation Information Artificial Intelligence Facebook Miscellaneous Holiday Training Covid-19 Gadgets Cloud Computing Managed Service Provider Remote Work Server Compliance IT Support Outsourced IT Employee/Employer Relationship Spam Encryption Windows 10 Office Data Management Business Continuity Government Business Technology Blockchain Windows 10 Bandwidth Virtualization Wi-Fi Two-factor Authentication Vendor Apps Data Security Mobile Office Mobile Device Management Gmail Tip of the week Chrome Budget WiFi Apple Networking Employer-Employee Relationship App Managed Services Voice over Internet Protocol BYOD Access Control Office 365 HIPAA Applications How To BDR Conferencing Hacker Computing Avoiding Downtime Information Technology Marketing Health Analytics Office Tips Augmented Reality Router Retail Storage Big Data Password Bring Your Own Device Managed IT Services 2FA Help Desk Computers Operating System Healthcare Website Virtual Private Network Risk Management Printer Cooperation Free Resource Project Management Paperless Office Windows 7 Infrastructure Firewall Microsoft 365 Document Management Solutions The Internet of Things Social Scam Data loss Windows 11 Monitoring Excel Going Green Patch Management Customer Service Save Money Remote Monitoring Vulnerability End of Support Remote Workers Vendor Management Cybercrime Telephone Physical Security Display Data Privacy Computer Repair Word Virtual Desktop Images 101 Data storage LiFi Mobility Telephone System Multi-Factor Authentication Cost Management Outlook Machine Learning Money Safety Humor Employees Integration Maintenance Sports User Tip Antivirus Modem Mouse Mobile Security Processor Holidays Administration Data Storage Smart Technology Supply Chain Customer Relationship Management Video Conferencing Managed Services Provider Virtual Machines Professional Services Robot Saving Time Hacking Settings Presentation Printing Managed IT Service Wireless Content Filtering Downloads Wireless Technology IT Management VPN YouTube Meetings iPhone Licensing Cryptocurrency Vulnerabilities Entertainment Hard Drives Google Docs Trends Supply Chain Management Unified Communications Experience Running Cable Tech Support Google Calendar Term Google Apps Domains Customer Resource management FinTech Bitcoin Network Management Regulations Google Wallet Star Wars IT Assessment Microsoft Excel IT Maintenance Monitors Data Analysis Refrigeration Gamification Flexibility Staff Value Business Intelligence Laptop Websites Legislation Shortcuts Public Speaking Organization Windows 8 Social Networking Drones Smart Devices Ransmoware Lithium-ion battery Fileless Malware Digital Security Cameras Entrepreneur SharePoint Content Remote Working Wearable Technology Memory Vendors Electronic Medical Records Halloween Comparison Google Play Be Proactive Health IT Motherboard Data Breach Lenovo Assessment Electronic Health Records Permissions Workforce Writing Directions Videos Undo Wasting Time Threats Virtual Reality Scary Stories Private Cloud Specifications Security Cameras Workplace Strategies Hacks Server Management Trend Micro Superfish Internet Exlporer Software as a Service Identity Theft Fraud Meta Fun Microchip Username Deep Learning Managing Costs Amazon Twitter Error Black Friday SSID eCommerce Database Surveillance Education Virtual Assistant Outsource IT Social Engineering Application IT Technicians Virtual Machine Environment Remote Computing Media Cyber Monday Medical IT IBM Proxy Server Reviews Mobile Computing Cookies Tactics Development Tablet Hotspot Transportation Small Businesses Search Best Practice Mirgation Hypervisor Displays Alert Buisness File Sharing PowerPoint Dark Data Shopping Managed IT Nanotechnology Optimization Legal Addiction IT solutions Language Employer/Employee Relationships Outsourcing How To Competition Management PCI DSS Business Growth Chatbots Notifications Navigation Screen Reader Travel Distributed Denial of Service Workplace Gig Economy Techology Service Level Agreement Internet Service Provider Google Maps Computing Infrastructure Teamwork Hiring/Firing Cortana Evernote Paperless Regulations Compliance Alt Codes Identity Smart Tech Memes Downtime Unified Threat Management Co-managed IT User Bookmark Unified Threat Management Download Net Neutrality Hosted Solution Alerts SQL Server Technology Care Business Communications Financial Data Typing History Connectivity IT Break Fix Scams IP Address Network Congestion Browsers Smartwatch Google Drive User Error Upload Procurement Azure Hybrid Work Knowledge Multi-Factor Security Tech Human Resources Social Network Telework Cyber security IoT Communitications Point of Sale Dark Web Cables 5G Recovery CES

Blog Archive