Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Basics of PCI Compliance

The Basics of PCI Compliance

Businesses today should be accepting card-based payments, regardless of their size. In addition to the convenience it offers to customers, it’s the most secure means you have of being paid. To protect consumers and their personal and financial information, many card providers have adopted a unified regulation that applies to businesses that accept these payments. Let’s review this regulation and how it impacts the average small-to-medium-sized business.

Understanding PCI

Established in 2006, the Payment Card Index Digital Security Standard (or PCI DSS) was sponsored by the members of the PCI Security Standards Council. This council was founded to help the credit card industry self-regulate and manage the standards for consumer privacy that businesses would be beholden to. You certainly have at least one of the council’s members in your wallet right now: Visa, Mastercard, American Express, and Discover.

The standards that this council established apply to any and all businesses that accept payment cards from their customers. If you process or store payment information or process digital payments, PCI compliance is mandatory.

To remain compliant, any business that accepts payment cards needs to: 

  1. Change passwords from system default
  2. Install sufficient network security tools (antivirus, firewalls, etc.) that will work to protect card data
  3. Encrypt transmission of card data across public networks
  4. Restrict the transmission of card and cardholder data to a “need to know” basis
  5. Assign user ID to all users with server or database access
  6. Make efforts to protect physical and digital access to card and cardholder data
  7. Monitor and maintain system security
  8. Test system security regularly
  9. Create written policies and procedures that address the importance of securing cardholder data
  10. Train staff on best practices of accepting payment cards

Any business, all businesses, each and every business of any kind that takes credit card payments needs to get these ten things done. Many businesses already accomplish these things as part of their typical routine… if you aren’t one of them, and accept card-based payments, your non-compliance could get you in serious trouble.

PCI and the Size of Your Business

The above checklist were the things that all businesses are responsible for, across the board. Based on what “level” of business you operate (according to the PCI Security Standards Council) there are other needs you must address. As the council defines them, there are four different levels you may fall into:

  • Merchant Level #1 - A business that processes over six million payment card transactions per year.
  • Merchant Level #2 - A business that processes between one million-to-six million payment card transactions per year.
  • Merchant Level #3 - A business that processes between 20,000-to-one million e-commerce payment card transactions per year.
  • Merchant Level #4 - A business that processes less than 20,000 e-commerce payment transactions, and fewer than one million overall payment card transactions per year.

As a level one breach will almost certainly have an impact to a larger number of consumers, the focus of the PCI regulatory body tends to be on these larger organizations. The means just aren’t there for every business to be checked constantly. However, that doesn’t mean that small businesses aren’t also facing severe risks. Here are some of the other requirements that businesses must fulfill, based on their Merchant Level:

Merchant Level #1

Considering the scale of these businesses and the reach that they have to consumers both online and in-store, these merchants have much greater responsibility. PCI compliance for Merchant Level 1 requires that merchants:

  • Complete a yearly Report on Compliance (ROC) through a Qualified Security Assessor (QSA)
  • Undergo a quarterly network scan by an Approved Security Vendor (ASV)
  • Complete the Attestation of Compliance Form for PCI Council records

Merchant Level #2

Standards relax as the number of transactions decreases, so Merchant Level 2 dictates that these merchants:

  • Perform a yearly Self-Assessment Questionnaire (SAQ)
  • Allow an ASV to complete a quarterly network scan
  • Complete the Attestation of Compliance Form for PCI Council records

Merchant Level #3

This is where most medium-sized businesses would classify, and also requires that merchants:

  • Perform a SAQ
  • Allow an ASV to complete a quarterly network scan
  • Complete the Attestation of Compliance Form for PCI Council records

Merchant Level #4

This level applies to the vast majority of small businesses. Like the prior two merchant levels, this level requires that all merchants:

  • Perform a SAQ
  • Allow an ASV to complete a quarterly network scan
  • Complete the Attestation of Compliance Form for PCI Council record

Noncompliant businesses can be reviewed, and are generally fined, watched more closely in the future, or even prohibited from accepting payment cards at all. Obviously, this isn’t something you want to happen to your business.

To find out more about PCI DSS standards and what you can do to ensure your compliance, give the IT professionals at Voyage Technology a call at 800.618.9844 today.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Tuesday, 31 March 2026

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Data Business Computing Business Productivity Software Innovation Cloud Hackers Hardware Efficiency Network Security User Tips Internet IT Services Malware IT Support Privacy Workplace Tips Google Email Computer Phishing Workplace Strategy Collaboration Hosted Solutions Small Business Backup Users Ransomware Managed Service Mobile Device Productivity Microsoft Quick Tips Passwords Saving Money AI Communication Cybersecurity Smartphone Data Backup Disaster Recovery Data Recovery Android Upgrade VoIP Business Management Smartphones Mobile Devices communications Windows Browser Social Media Managed IT Services Microsoft Office Current Events Network Tech Term Internet of Things Remote Information Automation Artificial Intelligence Facebook Miscellaneous Holiday Compliance Covid-19 Gadgets Cloud Computing Training Managed Service Provider Outsourced IT Remote Work Server IT Support Encryption Spam Employee/Employer Relationship Windows 10 Office Data Management Business Continuity Government Business Technology Windows 10 Bandwidth Virtualization Blockchain Wi-Fi Data Security Apps Vendor Managed Services Two-factor Authentication Mobile Office Mobile Device Management Tip of the week Chrome Gmail Budget WiFi Apple Networking App Employer-Employee Relationship BYOD Voice over Internet Protocol Office 365 Conferencing Managed IT Services How To BDR HIPAA Computing Hacker Physical Security Applications Information Technology Avoiding Downtime Access Control Marketing Help Desk Analytics Office Tips Augmented Reality Retail Storage Password Bring Your Own Device Big Data 2FA Operating System Computers Router Virtual Private Network Risk Management Website Healthcare Health Monitoring Firewall Document Management Free Resource Project Management Windows 7 Managed IT Service Microsoft 365 Telephone The Internet of Things Scam Data loss Solutions Social Cooperation Going Green Patch Management Save Money Windows 11 Remote Monitoring Vulnerability End of Support Customer Service Vendor Management Cybercrime Excel Display Printer Remote Workers Paperless Office Infrastructure iPhone Word Smart Technology Outlook Machine Learning Vulnerabilities Money Saving Time Data Privacy Humor Images 101 Multi-Factor Authentication Mobility Safety Maintenance Sports Downloads Antivirus Mouse Licensing Entertainment Administration Employees Integration Telephone System Robot Customer Relationship Management Cost Management Settings Holidays Printing Wireless Data Storage Content Filtering Supply Chain Hacking IT Management Presentation VPN YouTube Meetings Video Conferencing Managed Services Provider Virtual Machines Professional Services Cryptocurrency Wireless Technology User Tip Modem Processor Computer Repair Mobile Security Virtual Desktop Data storage LiFi Smartwatch Laptop Websites Mirgation IT Scams Hard Drives Windows 8 Domains Drones Nanotechnology Procurement Azure Hybrid Work Cyber security Tech Human Resources SharePoint Addiction Telework Electronic Medical Records Language CES Halloween Chatbots Communitications Cables Refrigeration Management Public Speaking Lenovo Screen Reader Supply Chain Management Writing Distributed Denial of Service Term Google Apps Lithium-ion battery Service Level Agreement FinTech Virtual Reality Computing Infrastructure Entrepreneur Scary Stories Private Cloud Identity IT Assessment IT Maintenance Hacks Server Management Superfish Bookmark Identity Theft Smart Tech Flexibility Fun Value Business Intelligence Shortcuts Deep Learning Download Organization Twitter Alerts Digital Security Cameras Error Smart Devices Ransmoware Undo Browsers Education Connectivity Remote Working Social Engineering Break Fix Memory Vendors Data Breach Google Play Be Proactive Upload Remote Computing Videos Electronic Health Records Multi-Factor Security Workforce Mobile Computing Social Network Tablet IoT Search Dark Web Wasting Time Threats Trend Micro Security Cameras Workplace Strategies Application Best Practice Trends Alert Buisness File Sharing Regulations Software as a Service Dark Data Google Calendar Meta Managed IT Customer Resource management IBM Legal Data Analysis IT solutions Star Wars How To Microsoft Excel Managing Costs Amazon eCommerce SSID Business Growth Gamification Notifications Staff Travel Social Networking Surveillance Legislation Virtual Assistant Outsource IT Media Techology Fileless Malware Google Maps Cortana Virtual Machine Environment Wearable Technology Medical IT Alt Codes Content Reviews Competition Health IT Downtime Unified Threat Management Motherboard Development Comparison Transportation Small Businesses Unified Threat Management Directions Hosted Solution Assessment Permissions Hypervisor Displays Optimization PowerPoint Typing Shopping Network Congestion Specifications Employer/Employee Relationships Outsourcing Navigation Google Drive User Error Microchip User Internet Exlporer PCI DSS Knowledge Fraud Workplace Username Gig Economy Point of Sale Internet Service Provider 5G Black Friday Teamwork Hiring/Firing Evernote Paperless IP Address Google Docs Unified Communications Database Regulations Compliance Experience Running Cable Tech Support IT Technicians Memes Co-managed IT Bitcoin Network Management Google Wallet Proxy Server Cookies Net Neutrality Monitors Cyber Monday SQL Server Technology Care History Business Communications Recovery Tactics Financial Data Hotspot

Blog Archive