Payments Basics · 8 min read

What is PCI compliance?

PCI DSS is the card industry's security standard. For most small businesses, complying means answering a questionnaire honestly once a year and using equipment that already handles the hard parts for you.

Why it exists

Card data is valuable to criminals. The standard sets minimum requirements for how businesses handle it so a breach at one shop doesn't compromise thousands of cardholders whose information passed through it.

What you actually have to do

For a typical small merchant using standard, modern POS hardware, the obligations are modest and manageable.

  • Complete an annual self-assessment questionnaire
  • Use approved, up-to-date payment hardware and software
  • Never write down or store full card numbers anywhere
  • Use strong, individual staff logins rather than shared passwords
  • Secure your network and change default router and device passwords

Modern POS shrinks your scope

When card data is encrypted at the reader and tokenized immediately, it never reaches your systems in a readable form. That dramatically reduces what you're personally responsible for securing, compared to older systems that touched raw card numbers.

The fee people ignore

Many processors charge a monthly PCI non-compliance fee if you haven't completed the questionnaire. It's one of the easiest recurring charges to eliminate — simply do the questionnaire once a year, usually a fifteen-minute process.

SAQ types, briefly

Not every business fills out the same questionnaire. The type depends on how you accept cards — a business using a fully integrated, encrypting terminal generally qualifies for a shorter form than one that keys in cards through software on a computer.

What a breach actually costs

Beyond fines, a breach can mean forensic investigation costs, notification requirements, and real damage to customer trust. The self-assessment questionnaire and basic hygiene steps are a small price for avoiding that outcome.

Common mistakes that create exposure

Writing down card numbers for phone orders, emailing card details internally, storing them in a spreadsheet for repeat customers, or letting staff use one shared login are among the most common ways small businesses unintentionally increase their risk.

How to actually complete the questionnaire

Your processor's portal typically hosts it, walks you through relevant questions based on your setup, and confirms completion. It's worth putting a yearly reminder on the calendar rather than waiting for a fee to show up on a statement.

Common questions

What happens if I ignore it?

Monthly non-compliance fees, and far worse exposure if you're ever breached.

Is it hard?

The questionnaire for a standard card-present merchant is manageable. Your processor provides the portal and guidance.

Can I store a card for a repeat customer?

Not on paper or in a spreadsheet. Use the card-on-file feature in your POS, which tokenizes it properly.

Which SAQ type applies to me?

It depends on how you accept cards. A fully integrated, encrypting terminal typically qualifies for a shorter questionnaire than manual entry through a computer.

Does PCI compliance cost extra with Digital Harvest?

We'll walk you through the annual questionnaire as part of ongoing support so you're not paying an avoidable non-compliance fee.

Still not sure?

Two minutes on the phone usually beats another hour of reading. We'll tell you what fits and what doesn't.