It is a questionnaire, not a certification
For almost every small merchant, PCI compliance means completing one annual self-assessment questionnaire and an attestation, plus a quarterly network scan if a public-facing system is in scope. That is the whole obligation.
Nobody audits a corner store. What happens instead is that your processor charges a monthly non-compliance fee until the questionnaire is filed — which is why so many merchants pay it for years without ever knowing what it was for.
Which questionnaire applies to you
It depends entirely on how card data flows through your business:
- SAQ A — cards only through a hosted page or iframe you do not control. Shortest form, no scan
- SAQ A-EP — your site controls the page that sends card data, even though it never receives it. Longer, scanning required
- SAQ B — standalone dial-out terminal, no electronic storage
- SAQ B-IP — IP-connected standalone terminal with validated point-to-point encryption
- SAQ C — a payment application connected to the internet
- SAQ C-VT — keying transactions into a web virtual terminal on one isolated computer
- SAQ D — everything else, and anyone who stores card data. This one is a project
What the requirements come down to
Strip out the enterprise language and the practical list for a small merchant is short: do not store card numbers you do not need, change default passwords, patch your systems, give each person their own login, restrict who can see card data, protect your network, and confirm annually that all of that is still true.
The two violations we find most often are card numbers written on paper order forms and one shared login used by the whole staff. Both are free to fix and both would matter enormously in a breach investigation.
Shrink the obligation instead of managing it
Every requirement applies only to systems that touch card data. Remove the touch points and the questionnaire gets shorter:
- Move online checkout to a hosted page or iframe so card fields never render on your domain
- Tokenize saved customers in the gateway instead of keeping numbers in a CRM or spreadsheet
- Use validated point-to-point encryption terminals so your network never sees readable card data
- Put payment devices on their own network segment, away from guest Wi-Fi and the back office
- Shred paper that ever had a card number on it, and stop generating more
What compliance does and does not do
It does not prevent a breach. What it does is limit what happens to you afterwards. An out-of-compliance merchant in a breach faces forensic costs, card-brand assessments, liability for fraud on exposed cards and potentially losing the ability to accept cards at all.
Treated as a fifteen-minute annual task with the right questionnaire, it is genuinely not a burden. Treated as a fee you pay to avoid paperwork, it is expensive twice.