Protect the account

    PCI is a questionnaire, not a mystery. And you should never pay a fee for not doing it.

    Every business that takes cards has a PCI obligation. For most small merchants it is one annual self-assessment and, in some cases, a quarterly network scan. We tell you which version applies, help you complete it, and keep it current so the non-compliance fee never triggers.

    • We identify the correct SAQ for how you take cards
    • Annual validation handled, not emailed to you as a PDF
    • Quarterly scanning arranged where it applies
    • No PCI non-compliance fee on our accounts

    PCI compliance — free setup review

    Three fields. Oussama calls you back within one business hour.

    No contract, no obligation. We use your statement only to build your comparison. Oussama calls you back within one business hour.

    What you get

    PCI compliance, set up properly.

    Six things that actually matter, and what each one does for your business.

    SAQ A

    For merchants who take cards only through a fully outsourced hosted page or an iframe, with no card data touching their systems. The shortest questionnaire and the reason hosted checkout is worth using.

    SAQ A-EP

    For e-commerce sites that do not receive card data but do control the page that sends it to the processor — a direct-post or JavaScript integration. Longer, and it requires quarterly scanning.

    SAQ B and B-IP

    For terminal-only merchants. B covers dial-out or standalone terminals with no electronic storage; B-IP covers IP-connected standalone terminals with validated point-to-point encryption.

    SAQ C and C-VT

    C is for payment applications connected to the internet. C-VT is for merchants keying transactions into a web-based virtual terminal on one isolated computer.

    SAQ D

    The long one, for merchants who store, process or transmit card data in their own environment, or who do not fit any other category. If you are on D, reducing scope is usually the single most valuable project available.

    Quarterly scanning

    Where a public-facing IP address is in scope, an approved scanning vendor runs a quarterly external scan. Failures need remediation before the next validation. We arrange it rather than leaving you to figure it out.

    What the standard actually asks for

    PCI DSS is a security standard published by the card brands. Strip out the enterprise language and the requirements a small merchant has to satisfy are mostly common sense: do not store card numbers you do not need, do not use default passwords, keep systems patched, restrict who can see cardholder data, use unique logins per person, protect your network, and check annually that all of that is still true.

    The paperwork is a self-assessment questionnaire plus an attestation of compliance. Which questionnaire you complete depends entirely on how card data flows through your business — which is why the first useful step is a five-minute conversation about your setup, not a 300-question form.

    The non-compliance fee is a choice your processor made

    Many processors charge a monthly PCI non-compliance fee — often $20 to $40 — when a merchant has not completed their annual validation. It is a real charge for a real obligation, and it is also one of the most profitable fees in the industry precisely because most merchants never complete the form.

    We treat validation as part of onboarding. You get the right questionnaire, help completing it, scanning arranged if it applies, and a reminder before it lapses. Done that way the fee has nothing to trigger on.

    Reducing your scope is the real win

    Every requirement applies to systems that touch card data. Remove the touch points and the obligation shrinks:

    • Move to hosted or iframe checkout so card fields never render on your domain
    • Tokenize stored customers instead of keeping card numbers in a CRM or spreadsheet
    • Use validated point-to-point encryption terminals so your network never sees readable card data
    • Segment payment devices onto their own network away from guest Wi-Fi and back-office machines
    • Stop writing card numbers on paper order forms — this is still the most common violation we find

    Accounts placed through our processor and banking network

    Electronic PaymentsCardConnectPaySafeShift4FiservNRSMaverick Payments

    Free statement analysis

    Let's get pci compliance right on your account.

    Send one recent statement and we will show you what changes, in writing, with the arithmetic on the page. No contract and no obligation either way.

    Terrab Solutions is a registered agent/ISO partner. Rates and approval subject to underwriting. Estimates are not a binding quote.

    PCI compliance — free review

    Oussama calls you back within one business hour.

    No contract, no obligation. We use your statement only to build your comparison. Oussama calls you back within one business hour.

    Straight answers

    PCI compliance questions

    Day to day, a monthly non-compliance fee from most processors. In a breach, the consequences are much larger: forensic investigation costs, card-brand assessments, liability for fraud on exposed cards, and potentially losing the ability to accept cards. Compliance does not prevent a breach — it limits what happens to you afterwards.

    All solutions