Compliance · 10 min read

The small business PCI compliance checklist

PCI-DSS is twelve requirements written for enterprise security teams. For a restaurant or retail owner it comes down to a much shorter list of practical tasks. Work through these and the monthly non-compliance fee disappears with them.

What you need to know

  • Scope first: every system that touches card data is in scope.
  • Segmentation is the cheapest way to shrink that scope.
  • Pick the right SAQ before answering a single question.
  • Change every default password on routers, switches and POS.
  • Quarterly ASV scans apply if anything is internet reachable.
  • Attest annually or the non-compliance fee keeps billing.

Start by drawing your cardholder data environment

Your cardholder data environment is every device that stores, processes or transmits card data, plus anything connected to it. In a typical restaurant that means the Clover terminals, the router, the switch, the back-office computer if it shares the same network, and the guest Wi-Fi if it is not isolated.

Most merchants dramatically underestimate scope because they forget the flat network. One unsegmented Wi-Fi access point pulls every laptop, tablet and smart TV in the building into the audit.

Segment the network before you answer any questionnaire

Put payment devices on their own VLAN with firewall rules that allow outbound processor traffic and nothing else. Guest Wi-Fi goes on a separate VLAN with client isolation. Office devices get a third.

Done properly, segmentation can move you from SAQ D with hundreds of questions to a far shorter SAQ, and it genuinely reduces breach risk. It is the single highest return item on this list.

The twelve requirements, translated

Install and maintain a firewall. Change vendor default passwords on every device. Protect stored card data, ideally by storing none at all. Encrypt data in transit. Run anti-malware on systems that support it. Patch and update regularly.

Restrict access to card data by job role. Give every user a unique ID, no shared logins. Control physical access to terminals and back-office systems. Log and monitor access. Test security regularly with scans. Maintain a written security policy your staff has actually read.

Physical terminal checks staff should run weekly

Card skimming still happens at the counter. Record each terminal's serial number and have a manager verify it weekly against the list. Check for loose overlays, mismatched keypads, unfamiliar cables or new USB devices.

Never allow a technician to service a terminal without a scheduled appointment and identification. Requirement 9 exists precisely because a confident stranger in a branded shirt is the easiest attack there is.

Attest, scan, and keep the evidence

Complete your SAQ annually and submit it through your processor's compliance portal. If you are scan-required, schedule ASV scans quarterly and remediate failures until you have a passing result on file.

Keep the evidence in one place: the signed attestation, the passing scan reports, your written policy, the network diagram and your terminal inventory. If a breach investigation ever happens, that folder is what protects you.

Frequently asked questions

Keep reading

Stop paying non-compliance fees

We scope your environment, segment the network, complete the right SAQ with you and run the quarterly scans, so compliance stops being an annual scramble.