PCI Compliance Isn't Optional โ But It Doesn't Have to Be Hard
If your business accepts credit cards, you're required to comply with the Payment Card Industry Data Security Standard (PCI DSS). That sounds like something only enterprise companies worry about, but it applies to every single merchant โ from a one-person salon to a multi-location retail chain.
The good news: for most small businesses, compliance is straightforward. The bad news: many processors charge inflated "PCI compliance fees" or "non-compliance fees" that have nothing to do with actual security.
Let's separate the real requirements from the money grabs.
What PCI DSS Actually Requires
PCI DSS has 12 core requirements organized into six categories. For a small business that uses a payment terminal or hosted payment page (meaning you never see or store raw card numbers), most of these are already handled by your processor and equipment.
The 12 Requirements (Simplified)
- Install and maintain a firewall โ If you use a router at your business, you likely already have one.
- Don't use vendor default passwords โ Change the default password on your router, POS terminal, and any network equipment.
- Protect stored cardholder data โ If you don't store card numbers (and you shouldn't), this is automatic.
- Encrypt card data in transit โ Your terminal and payment gateway handle this.
- Use antivirus software โ Required on any computer connected to your payment network.
- Develop secure systems โ Keep software and firmware updated.
- Restrict access to cardholder data โ Only employees who need access should have it.
- Assign unique IDs to users โ Each employee gets their own login, no shared passwords.
- Restrict physical access โ Don't leave terminals unattended in public areas.
- Track and monitor access โ Keep logs of who accesses what.
- Test security systems regularly โ Run vulnerability scans if applicable.
- Maintain an information security policy โ Document your security practices.
SAQ: The Form You Actually Need to Fill Out
Most small businesses complete a Self-Assessment Questionnaire (SAQ). There are several types, but the two most common are:
SAQ A
For businesses that outsource all card processing (e-commerce with a hosted payment page, no card data touches your systems).
- Questions: ~22
- Difficulty: Easy
SAQ A-EP
For e-commerce businesses where the payment page is on their website but card data goes directly to the processor.
- Questions: ~139
- Difficulty: Moderate
SAQ B
For businesses using standalone terminals (dial-up or IP) with no electronic card data storage.
- Questions: ~41
- Difficulty: Easy
SAQ C
For businesses with payment applications connected to the internet but no electronic card data storage.
- Questions: ~160
- Difficulty: Moderate
SAQ D
For businesses that store card data or don't fit other categories.
- Questions: ~329
- Difficulty: Complex โ consider hiring a QSA (Qualified Security Assessor).
Most brick-and-mortar small businesses fall under SAQ B or SAQ C. If you use a modern terminal from your processor and don't store card numbers, you're looking at 41โ160 questions, many of which are simple yes/no.
The PCI Fee Scam
Here's where it gets frustrating. Many processors charge:
- PCI compliance fee: $79โ$149/year (sometimes monthly)
- PCI non-compliance fee: $19โ$99/month if you haven't completed your SAQ
The compliance fee should cover access to the SAQ portal and any required vulnerability scans. But some processors charge the fee and don't provide any tools or support. They're just padding your statement.
What a legitimate PCI fee includes:
- Access to an SAQ completion portal
- Quarterly vulnerability scans (if required for your SAQ type)
- Breach protection insurance
- Support for completing your assessment
Red flags:
- PCI fee over $120/year with no portal access
- Monthly "non-compliance" charges with no instructions on how to become compliant
- Separate charges for vulnerability scans on top of the PCI fee
Check your statement for hidden PCI fees โ
Common PCI Mistakes Small Businesses Make
1. Storing Card Numbers on Paper
Writing down card numbers for phone orders or recurring charges violates PCI. Use your terminal's card-on-file feature or a virtual terminal instead.
2. Using Unsecured Wi-Fi for Transactions
Your payment terminal should be on a separate, password-protected network โ not your guest Wi-Fi.
3. Ignoring Software Updates
Outdated POS software and terminal firmware create vulnerabilities. Set up automatic updates when possible.
4. Sharing Employee Logins
Every person who accesses your POS or payment system needs their own credentials. Shared logins make it impossible to trace issues.
5. Never Completing the SAQ
Many merchants don't know they need to complete an annual SAQ. If you haven't done yours, contact your processor for access to their compliance portal.
What Happens If You're Not Compliant?
- Monthly non-compliance fees from your processor ($19โ$99/month)
- Increased liability if a data breach occurs โ you could be responsible for fraudulent charges
- Fines from card brands ranging from $5,000 to $100,000 per month
- Loss of your merchant account in severe cases
The fines are rare for small businesses, but the liability exposure is real. Completing your SAQ annually is the simplest way to protect yourself.
How to Get and Stay Compliant
- Ask your processor for access to their PCI compliance portal
- Determine your SAQ type based on how you accept cards
- Complete the questionnaire โ most take 30โ60 minutes
- Schedule quarterly scans if required for your SAQ type
- Renew annually โ PCI compliance isn't one-and-done
Bottom Line
PCI compliance is a basic cost of doing business if you accept credit cards. For most small businesses, it's a yearly questionnaire and some common-sense security practices. Don't let processors use it as an excuse to pad your statement, and don't ignore it hoping it goes away.
The merchants who take 30 minutes once a year to complete their SAQ save themselves from monthly non-compliance fees and real security risk.
Get a free statement review to check for PCI fee overcharges โ

Chase James
CEO, Payment USA
Chase James is the founder and CEO of Payment USA, a merchant services company built on transparency and fair pricing. With over 15 years in the payments industry, Chase has helped thousands of businesses uncover hidden processing fees and switch to honest, interchange-plus pricing.
Contact Chase โ