PCI DSS compliance is the price of taking card payments. If your business stores, processes, or transmits cardholder data, the card brands want proof once a year, and your acquiring bank is the party that asks for it.
Most owners hit the same wall. The rules read like a bank wrote them for another bank. Meanwhile your processor emails a portal link with a deadline and no explanation of which form applies to you.
Here is the plain version: what PCI DSS 4.0 asks for now, which questionnaire matches your setup, who signs off, and where the real money goes.
The Short Answer
PCI DSS compliance requires meeting 12 requirements and proving it annually through a Self-Assessment Questionnaire or a Report on Compliance, with Level 1 merchants needing quarterly ASV scans and annual penetration testing. The new PCI DSS 4.0 mandates multi-factor authentication, longer passwords, script control on payment pages, authenticated internal vulnerability scans, and targeted risk analysis, all of which must be documented and reviewed yearly. Merchants are categorized into four levels based on transaction volume, with Level 1 requiring the most rigorous validation and testing. Evidence collection is challenging, as assessors may inspect parts of a business, and custom controls require additional evaluation and cost.
What PCI DSS compliance actually requires
PCI DSS compliance means meeting the 12 requirements of the Payment Card Industry Data Security Standard and proving it every year in a format your acquiring bank accepts. Proof takes one of two shapes: a Self-Assessment Questionnaire you sign yourself, or a Report on Compliance that a Qualified Security Assessor signs after testing your controls.
The 12 requirements fold into six goals. Build and keep a secure network. Protect stored account data. Run a vulnerability management program. Control who can reach what. Monitor and test your systems. Write down the policy and follow it.
None of that is exotic. Firewalls, encryption, patching, unique logins, multi-factor authentication, logging, scanning, and a policy people actually read. The hard part sits elsewhere. Evidence is the hard part, along with how much of your business an assessor gets to look at.
PCI DSS 4.0 and what changed in March 2025
Version 4.0 replaced 3.2.1, and the current text carries the number 4.0.1. Many of the new items sat in a best practice grace period until 31 March 2025. That date has passed. Those items now count as findings during an assessment, not as friendly advice.
Five changes catch smaller merchants off guard:
- Multi-factor authentication across the card environment. Not just remote access. Any account that reaches into the cardholder data environment needs a second factor, local admin logins included. Microsoft research puts the prevention rate for MFA at roughly 99% of account compromise attacks, which makes it one of the higher value items on the list.
- Longer passwords. Twelve characters wherever the system allows it, which quietly breaks a lot of old terminal and application defaults.
- Payment page script control. Merchants validating on SAQ A-EP or SAQ D must inventory every script on the checkout page, justify each one, and watch for unauthorized changes. Digital skimming drove the rule. In January 2025 the Council pulled these requirements out of SAQ A and replaced them with an eligibility attestation, so a fully outsourced checkout is off the hook.
- Authenticated internal vulnerability scans. Credentialed scanning now, not a blind sweep from outside the host.
- Targeted risk analysis. Several controls let you set your own frequency, but only if you document the reasoning and revisit it yearly.
Version 4.0 also introduced the customized approach, which lets a mature company meet an objective its own way. Small merchants almost never want it. Custom controls need an assessor to evaluate the design, and that review costs more than simply doing what the standard already spells out.
The four merchant levels and what each one owes
Card brands sort merchants into four levels, mostly by annual transaction volume. Thresholds vary a little between Visa, Mastercard, and the others, and a breach can push you up a level regardless of volume. Your acquirer makes the final call, so ask them in writing which level they have you in.
| Level | Rough annual volume | How you validate | Scanning and testing |
|---|---|---|---|
| Level 1 | Over 6 million card transactions, any channel | Report on Compliance from a QSA or a qualified internal assessor, plus a signed Attestation of Compliance | Quarterly ASV scans, annual internal and external penetration testing, segmentation testing |
| Level 2 | 1 million to 6 million | SAQ with AOC, though Mastercard wants a QSA involved or an ISA-credentialed employee completing it. A ROC if the brand or acquirer insists | Quarterly ASV scans, penetration testing where the SAQ type calls for it |
| Level 3 | Roughly 20,000 to 1 million e-commerce transactions | SAQ with AOC | Quarterly ASV scans on internet-facing systems in scope |
| Level 4 | Under 20,000 e-commerce, up to 1 million total | SAQ with AOC, on terms your acquirer sets | ASV scans if anything in scope faces the internet |
Two details trip people up. Quarterly scanning has to come from an Approved Scanning Vendor on the Council’s list, so your own scanner or your MSP’s tool does not substitute for it. Penetration testing is not purely a Level 1 chore either, because Requirement 11.4 rides along with the fuller questionnaires. Our walkthrough of quarterly ASV scanning covers the passing-scan process and what to do when a scan fails with three weeks left in the quarter.
Which SAQ matches your setup
Choosing the wrong questionnaire is the most common self-inflicted wound in this whole process. Start with one question: does a card number ever touch a system you own or control? Everything else follows from the answer.
| SAQ type | Who it fits | Effort | Watch out for |
|---|---|---|---|
| SAQ A | E-commerce or mail order that fully outsources payment to a validated third party, with no electronic storage of card data | Shortest form | Full redirect or a processor-hosted iframe only. A form on your page that posts card data onward does not qualify. |
| SAQ A-EP | E-commerce where your own page shapes how the payment happens, such as direct post or scripted hosted fields | Several times longer than SAQ A | Script inventory, change detection, ASV scanning on the site itself, and an annual penetration test under Requirement 11.4 |
| SAQ B, B-IP, C-VT, C | Card-present terminals with no internet connection (B), IP-connected standalone terminals (B-IP), web-based virtual terminals (C-VT), and internet-connected payment applications (C), none of them storing card data electronically | Moderate | The terminal or till must not share a flat network with office PCs and guest Wi-Fi |
| SAQ P2PE | Merchants using a validated point-to-point encryption solution end to end | Very short | Only a solution from the Council’s validated list counts. Encryption alone is not P2PE. |
| SAQ D | Everyone else, including anyone who stores card data, plus every service provider | All requirements | Penetration testing, log review, formal policies, and the widest scope |
Run a store on a hosted cart, never see a card number, and you are probably an SAQ A shop with a short form and a small bill. Add one custom checkout page and you can land in A-EP, which asks several times as many questions and drags your website into scope. That single design decision moves your cost more than any product you will ever buy for this. For the line-by-line version, work through our PCI DSS checklist before you open the portal and start clicking yes.
Scope reduction beats spending
Every requirement applies to the cardholder data environment: systems that store, process, or transmit account data, plus anything connected to them. Shrink that set and the entire program shrinks with it. Let it sprawl and you pay for scanning, logging, patching, and testing on machines that never needed to sit in scope.
Three moves do most of the work:
- Segmentation. Put payment systems on their own VLAN behind firewall rules that deny everything by default. Your accounting laptop and the break room tablet drop out of scope the day they can no longer reach the till.
- Tokenization and hosted payment fields. Let the processor hold the card number and hand your systems a token. No card data on your servers means far fewer controls to prove.
- Validated P2PE terminals. Encryption starts inside the card reader, so the retail network carries nothing readable. This turns a nasty SAQ D into a short one.
Segmentation only counts if you can prove it. An assessor will ask for testing that confirms the boundary holds, at least once a year, and more often for service providers. Draw the network diagram and the data flow diagram first. Both documents come up in nearly every assessment anyway, and drawing them usually reveals two or three systems nobody realized were touching card data.
What a fair PCI compliance quote looks like
This work rarely arrives as one invoice. Price it in pieces, then compare quotes line against line.
| Line item | Typical small business band | What moves the number |
|---|---|---|
| Quarterly ASV scanning | An annual subscription, usually the smallest line on the list | Number of external IPs and whether rescans cost extra |
| Annual penetration test | $5,000 to $20,000 per project | Network only versus web application, internal plus external, segmentation testing, retest included or not |
| Endpoint protection (EDR) | $8 to $15 per device per month | Device count, server pricing, term length |
| Managed detection and response (MDR) | $15 to $25 per device per month | Log retention, 24/7 coverage, whether daily log review evidence comes with it |
| Consultant-guided SAQ | A project fee, often a few thousand dollars | SAQ type, number of locations, policy writing, evidence gathering |
| QSA-led Report on Compliance | Five figures for most mid-market merchants | Scope size, number of sites, remediation cycles before sign-off |
Two sanity checks before you sign anything. A full penetration test quoted at a few hundred dollars is a vulnerability scan wearing a nicer cover page, and no assessor will treat it as Requirement 11.4 evidence. Any subscription that promises certification for a flat monthly fee deserves one question: who signs the Attestation of Compliance? Software cannot sign it, and neither can a badge on your footer.
How to choose a PCI compliance provider
Five questions separate a real partner from a portal reseller:
- Which SAQ do you think applies, and why? A useful answer describes your payment flow back to you. Hedging means they have not looked yet.
- Do you employ QSAs, work with a QSA firm, or only prepare clients? All three models work. Confusion about which one you bought does not.
- Who runs the ASV scan, and do rescans cost extra? Failed scans happen. Paying per rescan turns a cheap subscription expensive.
- Does the penetration test include segmentation testing? Assessors ask for it, and many quotes quietly exclude it.
- What does year two cost? Some firms discount the first engagement and recover it at renewal.
Watch for three traps. First, the compliant badge sold by a scanning vendor, which proves a scan ran and nothing more. Second, a consultant who scopes your whole network in rather than helping you carve it down, because a bigger scope bills better. Third, an all-in-one platform that collects evidence beautifully but leaves you to find an assessor at the end. Merchants who also sell software to enterprise buyers usually end up running a SOC 2 program alongside this one, and both lean on the same annual penetration test.
The cheap route is genuinely fine more often than vendors admit. A single-location shop on a validated P2PE terminal, or a small store on a hosted checkout, can complete SAQ A honestly in an afternoon plus a scan subscription. Pay for help when the picture gets messy: several locations, phone orders taken by staff, custom checkout code, or a service provider role you did not realize you had. That messy middle is where PCI compliance consulting earns its fee.
We hold agreements with 58 providers that handle vulnerability management, and plenty of them could run your scans well. Honestly, we do not care which one you pick. Our job is to match three of them to your size, industry, and scope, then step back while you decide. Vendors pay us. You never do.
Frequently Asked Questions
Is PCI DSS compliance a legal requirement?
Not a federal law in the United States for most merchants. PCI DSS lives in the contract you signed with your acquiring bank, so the consequences arrive as fees, higher transaction rates, or a lost merchant account rather than a government fine. A few states reference the standard in statute, and after a breach your card brand liability follows the same contract. Practically speaking, treat it as mandatory. That is a general description rather than legal advice, so check your state and your merchant agreement with counsel.
How much does PCI DSS compliance cost a small business?
A small SAQ A merchant might spend a few hundred dollars a year, mostly on scanning. Mid-sized merchants with a custom checkout or several locations usually land in the low five figures once you add a penetration test at $5,000 to $20,000, endpoint protection, and consulting help. Scope drives all of it. Shrinking the card environment cuts more cost than negotiating any single vendor down.
Do I need a QSA, or can I assess myself?
Level 1 merchants and most Level 1 service providers need a Report on Compliance signed by a QSA or a trained internal assessor. Everyone else may self-assess, sign the SAQ and Attestation of Compliance, and submit them to the acquirer, with one catch: Mastercard requires Level 2 merchants to involve a QSA or use an ISA-trained employee. Signing it yourself is perfectly legitimate. Trouble starts when you sign something you do not understand, because that signature carries weight after an incident.
Does using Stripe, Square, or PayPal make me PCI compliant?
No, though it makes the job far smaller. Those processors handle their own compliance for their systems, not yours. You still validate annually, usually on SAQ A if the checkout redirects or uses a processor-hosted iframe. Customize that checkout with your own scripted fields and you move to SAQ A-EP, where your website comes into scope along with page script monitoring.
What happens if we fail a quarterly scan?
Nothing dramatic on day one. Fix the findings and rescan until you get a passing result inside the same quarter, which is why rescan pricing matters. Failing to submit any passing scan puts you out of compliance with your acquirer, and that surfaces during renewals, insurance applications, or a breach investigation. Chronic failures also signal patching problems worth solving on their own merit.
How long does PCI DSS compliance take?
A clean SAQ A takes an afternoon plus scan setup. SAQ D from a standing start typically runs three to six months, because policies, logging, MFA rollout, and segmentation work all take real calendar time. A first ROC often runs longer. Build the network and data flow diagrams early, since almost every later step depends on knowing where card data actually goes.
Written by Russ Herman, founder of Defend My Business. We are a technology broker, like a mortgage broker but for business security, internet, and voice. We hold agreements with 400+ vetted providers. Vendors pay us, you never do. See exactly how we make money. Questions: 1-877-453-8759 or [email protected].
Get a Tailored PCI DSS Shortlist
3 vetted vendors matched to your size, industry, and budget. Free, vendor-neutral, 24-hour turnaround.
Get a Quote →Want help getting your compliance program right?
Defend My Business helps SMBs cut through the marketing and get their compliance program right for their environment, budget, and compliance needs — then deploy and manage it. Through our 400+ vendor network we can often secure better pricing and terms than buying direct, and we stay vendor-neutral, so the recommendation fits you, not a sales quota. Want a second opinion? Pair this with our compliance services or talk it through with an advisor.
Book a free call with a DMB advisor →