PCI compliance for small business, minus the jargon

What PCI-DSS actually requires from a small merchant, the SAQ in plain English, and the shortcuts that keep you compliant by default.

PCI compliance sounds like an enterprise problem, but every business that touches a card number — even one — signed up for it. The good news: for most small merchants it's far simpler than the acronyms suggest, and modern equipment does most of the work.

What PCI actually is

PCI-DSS is the card industry's security standard: a set of rules about how card data is handled, stored and transmitted. It applies to every merchant, scaled by volume. Small businesses mostly self-certify once a year via a questionnaire (the SAQ) — you're attesting that your setup handles cards safely.

The one rule that matters most

Don't store card numbers. Anywhere. Ever. Not in a spreadsheet, not in the notes field of your CRM, not on a sticky note for "regulars." If you need cards on file, use tokenization — the gateway vaults the card and hands you a token that's useless to a thief. Every gateway we carry (Next2Pay, FluidPay, NMI, Authorize.net and the rest) includes a proper vault.

Compliance by default

What non-compliance costs

Processors bill a monthly non-compliance fee until your SAQ is on file — pure waste. A breach while non-compliant is the real risk: fines, card replacement costs and forensic audits land on the merchant. The questionnaire is annoying; the alternative is worse.

Ten minutes with your processor's compliance portal usually clears the SAQ. If you're a NextPay merchant, ask us — we'll walk it with you.

Questions about whether your current setup stores anything it shouldn't? Talk to a specialist — it's a five-minute check.

Back to all articlesTake the Quiz
Put it into practice

Get a setup that fits your business

Two minutes of questions, a human on the other end, and match-or-beat processing on everything we carry.