PCI compliance sounds like an enterprise problem, but every business that touches a card number — even one — signed up for it. The good news: for most small merchants it's far simpler than the acronyms suggest, and modern equipment does most of the work.
What PCI actually is
PCI-DSS is the card industry's security standard: a set of rules about how card data is handled, stored and transmitted. It applies to every merchant, scaled by volume. Small businesses mostly self-certify once a year via a questionnaire (the SAQ) — you're attesting that your setup handles cards safely.
The one rule that matters most
Don't store card numbers. Anywhere. Ever. Not in a spreadsheet, not in the notes field of your CRM, not on a sticky note for "regulars." If you need cards on file, use tokenization — the gateway vaults the card and hands you a token that's useless to a thief. Every gateway we carry (Next2Pay, FluidPay, NMI, Authorize.net and the rest) includes a proper vault.
Compliance by default
- Modern terminals (PAX, Dejavoo, Clover, Valor) encrypt card data at the moment of tap or dip — the number never touches your systems in usable form
- Hosted pay pages and pay links keep online card entry on the gateway's certified page, not your website
- Virtual terminals beat writing numbers down for phone orders — key it straight in, vault it, shred nothing because you wrote nothing
What non-compliance costs
Processors bill a monthly non-compliance fee until your SAQ is on file — pure waste. A breach while non-compliant is the real risk: fines, card replacement costs and forensic audits land on the merchant. The questionnaire is annoying; the alternative is worse.
Questions about whether your current setup stores anything it shouldn't? Talk to a specialist — it's a five-minute check.