PCI compliance is one of those terms that sounds like it requires a lawyer and an IT department. In reality, for most small businesses, it comes down to an annual questionnaire and a few sensible security habits — and skipping it costs you real money in monthly fees and real risk if card data is ever compromised.
Here's what PCI actually is, what you're actually required to do, and how to stop paying non-compliance fees you never needed to pay.
What PCI compliance actually is
PCI DSS (Payment Card Industry Data Security Standard) is a set of security rules created by the card networks — Visa, Mastercard, American Express, and Discover — that applies to every business that accepts cards, no matter how small. It's not a government law; it's a contractual requirement that comes with your merchant account.
The goal is simple: keep cardholder data from being stolen. The rules cover how card numbers are processed, stored, and transmitted — and the single most important principle for a small business is to never store card data yourself at all.
What you're actually required to do
For the vast majority of small businesses, compliance means one thing: completing a Self-Assessment Questionnaire (SAQ) once a year. Which version you fill out depends on how you take payments:
Card-present with a modern terminal
If you use a standalone chip-and-tap terminal that connects directly to your processor, you likely qualify for the shortest questionnaire — a couple dozen yes/no questions.
Online payments through a hosted page
If your website hands customers off to a processor-hosted payment page or uses embedded secure fields, your scope stays small because card data never touches your systems.
Keyed-in payments on a virtual terminal
Typing cards into a browser-based terminal keeps you in a middle tier — the questionnaire is longer, but still very manageable without outside help.
The habits that keep you compliant
Never write down full card numbers — not on order forms, not in notebooks, not in email. If a customer emails you a card number, delete it and call them for the details instead.
Use current hardware. Modern terminals encrypt card data the instant it's read, which does most of the compliance work for you.
Change default passwords on anything connected to payments — terminals, routers, back-office software.
Keep your payment network separate from public Wi-Fi. Your terminal should never share a network with your customers' phones.
The non-compliance fee you're probably paying
Here's the part that annoys business owners most: if you haven't completed your annual questionnaire, most processors charge a monthly "PCI non-compliance fee" — typically $30 to $100. Over a year, that's real money for a form that takes under an hour.
Check your statement for it (our merchant statement guide shows you where to look). If it's there, completing the SAQ through your processor's compliance portal usually removes it within a billing cycle.
What happens if you ignore it
Beyond the monthly fees, the real exposure is a data breach while non-compliant: card networks can levy fines that flow through your processor to you, and you can be liable for fraud losses and card-reissuance costs. For a small business, that's an existential risk — over paperwork that takes an afternoon.
If PCI feels like a chore your current processor left you to figure out alone, that's fixable. Reach out to Scale Payments — we walk our merchants through compliance step by step, so the questionnaire gets done, the fees come off, and you get back to work.
