The short answer
PCI DSS is the card industry's security standard. Every merchant accepting cards must attest annually, usually through a self-assessment questionnaire matched to how card data flows through their business. Most small merchants qualify for the shortest version and can complete it in about twenty minutes with help.
Reduce scope before you fill anything in
Hosted payment fields, tokenisation and standalone terminals keep card data out of your systems, which is what puts you on the short questionnaire. Scope reduction is worth far more than any security product you can buy.
Compliance is not a one-off
Attestation is annual, and quarterly scanning applies to some environments. Diary it, or the non-compliance fee returns quietly.
Key takeaways
- Reduce scope first, then attest
- Most small merchants qualify for SAQ-A
- Annual renewal must be diarised
Want this checked against your own statement?
We are an independent agent — we shop every processor we work with and bring you the best deal for your profile. Free analysis, every fee named, back within 4 hours. Or call now and we will quote you on the phone.