Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Basics of PCI Compliance

The Basics of PCI Compliance

Businesses today should be accepting card-based payments, regardless of their size. In addition to the convenience it offers to customers, it’s the most secure means you have of being paid. To protect consumers and their personal and financial information, many card providers have adopted a unified regulation that applies to businesses that accept these payments. Let’s review this regulation and how it impacts the average small-to-medium-sized business.

Understanding PCI

Established in 2006, the Payment Card Index Digital Security Standard (or PCI DSS) was sponsored by the members of the PCI Security Standards Council. This council was founded to help the credit card industry self-regulate and manage the standards for consumer privacy that businesses would be beholden to. You certainly have at least one of the council’s members in your wallet right now: Visa, Mastercard, American Express, and Discover.

The standards that this council established apply to any and all businesses that accept payment cards from their customers. If you process or store payment information or process digital payments, PCI compliance is mandatory.

To remain compliant, any business that accepts payment cards needs to: 

  1. Change passwords from system default
  2. Install sufficient network security tools (antivirus, firewalls, etc.) that will work to protect card data
  3. Encrypt transmission of card data across public networks
  4. Restrict the transmission of card and cardholder data to a “need to know” basis
  5. Assign user ID to all users with server or database access
  6. Make efforts to protect physical and digital access to card and cardholder data
  7. Monitor and maintain system security
  8. Test system security regularly
  9. Create written policies and procedures that address the importance of securing cardholder data
  10. Train staff on best practices of accepting payment cards

Any business, all businesses, each and every business of any kind that takes credit card payments needs to get these ten things done. Many businesses already accomplish these things as part of their typical routine… if you aren’t one of them, and accept card-based payments, your non-compliance could get you in serious trouble.

PCI and the Size of Your Business

The above checklist were the things that all businesses are responsible for, across the board. Based on what “level” of business you operate (according to the PCI Security Standards Council) there are other needs you must address. As the council defines them, there are four different levels you may fall into:

  • Merchant Level #1 - A business that processes over six million payment card transactions per year.
  • Merchant Level #2 - A business that processes between one million-to-six million payment card transactions per year.
  • Merchant Level #3 - A business that processes between 20,000-to-one million e-commerce payment card transactions per year.
  • Merchant Level #4 - A business that processes less than 20,000 e-commerce payment transactions, and fewer than one million overall payment card transactions per year.

As a level one breach will almost certainly have an impact to a larger number of consumers, the focus of the PCI regulatory body tends to be on these larger organizations. The means just aren’t there for every business to be checked constantly. However, that doesn’t mean that small businesses aren’t also facing severe risks. Here are some of the other requirements that businesses must fulfill, based on their Merchant Level:

Merchant Level #1

Considering the scale of these businesses and the reach that they have to consumers both online and in-store, these merchants have much greater responsibility. PCI compliance for Merchant Level 1 requires that merchants:

  • Complete a yearly Report on Compliance (ROC) through a Qualified Security Assessor (QSA)
  • Undergo a quarterly network scan by an Approved Security Vendor (ASV)
  • Complete the Attestation of Compliance Form for PCI Council records

Merchant Level #2

Standards relax as the number of transactions decreases, so Merchant Level 2 dictates that these merchants:

  • Perform a yearly Self-Assessment Questionnaire (SAQ)
  • Allow an ASV to complete a quarterly network scan
  • Complete the Attestation of Compliance Form for PCI Council records

Merchant Level #3

This is where most medium-sized businesses would classify, and also requires that merchants:

  • Perform a SAQ
  • Allow an ASV to complete a quarterly network scan
  • Complete the Attestation of Compliance Form for PCI Council records

Merchant Level #4

This level applies to the vast majority of small businesses. Like the prior two merchant levels, this level requires that all merchants:

  • Perform a SAQ
  • Allow an ASV to complete a quarterly network scan
  • Complete the Attestation of Compliance Form for PCI Council record

Noncompliant businesses can be reviewed, and are generally fined, watched more closely in the future, or even prohibited from accepting payment cards at all. Obviously, this isn’t something you want to happen to your business.

To find out more about PCI DSS standards and what you can do to ensure your compliance, give the IT professionals at Voyage Technology a call at 800.618.9844 today.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Thursday, 31 July 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security User Tips Hardware Efficiency Internet Malware IT Support Privacy Google Email Computer Workplace Tips Phishing IT Services Hosted Solutions Collaboration Users Mobile Device Workplace Strategy Ransomware Small Business Quick Tips Cybersecurity Microsoft Backup Communication Passwords Data Backup Saving Money Smartphone Android Managed Service Business Management VoIP Smartphones Mobile Devices communications Upgrade Disaster Recovery Data Recovery Browser Social Media Productivity Microsoft Office Windows Managed IT Services Current Events AI Network Remote Tech Term Internet of Things Facebook Automation Artificial Intelligence Gadgets Cloud Computing Covid-19 Holiday Miscellaneous Information Remote Work Training Server Managed Service Provider Outsourced IT Compliance Encryption Spam Employee/Employer Relationship Office Windows 10 Government Business Continuity Data Management Virtualization Blockchain Wi-Fi Business Technology IT Support Bandwidth Windows 10 Data Security Apps Vendor Two-factor Authentication Mobile Office Networking Apple App Employer-Employee Relationship BYOD Chrome Mobile Device Management Managed Services Voice over Internet Protocol Budget Gmail WiFi How To BDR HIPAA Computing Applications Hacker Information Technology Avoiding Downtime Access Control Office 365 Marketing Tip of the week Conferencing Bring Your Own Device Managed IT Services Big Data Operating System Router Computers Virtual Private Network Risk Management Health Website Help Desk Analytics Office Tips Augmented Reality Retail Storage Healthcare Password Scam Data loss The Internet of Things Cooperation Free Resource Project Management Windows 7 Social Patch Management Going Green Microsoft 365 Save Money Remote Monitoring End of Support Vulnerability Solutions Vendor Management Cybercrime Customer Service Physical Security Display Printer Windows 11 Paperless Office Infrastructure Monitoring 2FA Excel Document Management Firewall Remote Workers Telephone iPhone Safety Mouse Licensing Administration Vulnerabilities Entertainment Data Privacy Images 101 Mobility Robot Telephone System Multi-Factor Authentication Cost Management Settings Wireless Customer Relationship Management Printing Content Filtering IT Management VPN Employees YouTube Meetings Integration Hacking Cryptocurrency Presentation User Tip Modem Mobile Security Computer Repair Processor Wireless Technology Holidays Virtual Desktop LiFi Data storage Data Storage Smart Technology Supply Chain Outlook Video Conferencing Word Managed Services Provider Machine Learning Virtual Machines Professional Services Saving Time Money Humor Managed IT Service Maintenance Downloads Antivirus Sports Connectivity IT Education Break Fix Scams Social Engineering Browsers Smartwatch Upload Procurement Azure Hybrid Work Remote Computing Undo Multi-Factor Security Tech Human Resources Social Network Telework Mobile Computing Cyber security Tablet IoT Communitications Dark Web Cables Search CES Trends Supply Chain Management Best Practice Alert Google Calendar Term Google Apps Dark Data Managed IT Customer Resource management FinTech Regulations Buisness File Sharing Star Wars IT Assessment IT solutions Microsoft Excel IT Maintenance How To Application Data Analysis Legal Gamification Flexibility Business Growth Staff Value Business Intelligence Notifications Legislation Shortcuts IBM Organization Social Networking Travel Google Maps Smart Devices Ransmoware Cortana Techology Fileless Malware Digital Security Cameras Content Remote Working Alt Codes Wearable Technology Memory Vendors Comparison Google Play Be Proactive Health IT Motherboard Data Breach Downtime Unified Threat Management Assessment Electronic Health Records Hosted Solution Permissions Workforce Unified Threat Management Directions Videos Typing Wasting Time Threats Competition Specifications Security Cameras Workplace Strategies Network Congestion Trend Micro Internet Exlporer Software as a Service Fraud Meta Knowledge User Error Microchip Google Drive Username Managing Costs Amazon Black Friday SSID 5G User eCommerce Point of Sale Database Surveillance Unified Communications Virtual Assistant Outsource IT Experience Google Docs Network Management Bitcoin IT Technicians Virtual Machine Environment Running Cable Tech Support Media Cyber Monday Medical IT Monitors IP Address Proxy Server Reviews Google Wallet Cookies Tactics Development Hotspot Transportation Small Businesses Windows 8 Mirgation Hypervisor Displays Laptop Websites PowerPoint Recovery Shopping Drones Nanotechnology Optimization SharePoint Addiction Language Employer/Employee Relationships Outsourcing Electronic Medical Records Hard Drives Management PCI DSS Chatbots Halloween Navigation Domains Screen Reader Distributed Denial of Service Workplace Writing Lenovo Gig Economy Service Level Agreement Internet Service Provider Computing Infrastructure Teamwork Hiring/Firing Virtual Reality Refrigeration Evernote Paperless Public Speaking Server Management Regulations Compliance Hacks Identity Scary Stories Private Cloud Identity Theft Smart Tech Memes Co-managed IT Fun Lithium-ion battery Superfish Bookmark Entrepreneur Download Net Neutrality Deep Learning Alerts SQL Server Technology Care Twitter Business Communications Financial Data History Error

Blog Archive