What you need to know
- Scope first: every system that touches card data is in scope.
- Segmentation is the cheapest way to shrink that scope.
- Pick the right SAQ before answering a single question.
- Change every default password on routers, switches and POS.
- Quarterly ASV scans apply if anything is internet reachable.
- Attest annually or the non-compliance fee keeps billing.
Start by drawing your cardholder data environment
Your cardholder data environment is every device that stores, processes or transmits card data, plus anything connected to it. In a typical restaurant that means the Clover terminals, the router, the switch, the back-office computer if it shares the same network, and the guest Wi-Fi if it is not isolated.
Most merchants dramatically underestimate scope because they forget the flat network. One unsegmented Wi-Fi access point pulls every laptop, tablet and smart TV in the building into the audit.
Segment the network before you answer any questionnaire
Put payment devices on their own VLAN with firewall rules that allow outbound processor traffic and nothing else. Guest Wi-Fi goes on a separate VLAN with client isolation. Office devices get a third.
Done properly, segmentation can move you from SAQ D with hundreds of questions to a far shorter SAQ, and it genuinely reduces breach risk. It is the single highest return item on this list.
The twelve requirements, translated
Install and maintain a firewall. Change vendor default passwords on every device. Protect stored card data, ideally by storing none at all. Encrypt data in transit. Run anti-malware on systems that support it. Patch and update regularly.
Restrict access to card data by job role. Give every user a unique ID, no shared logins. Control physical access to terminals and back-office systems. Log and monitor access. Test security regularly with scans. Maintain a written security policy your staff has actually read.
Physical terminal checks staff should run weekly
Card skimming still happens at the counter. Record each terminal's serial number and have a manager verify it weekly against the list. Check for loose overlays, mismatched keypads, unfamiliar cables or new USB devices.
Never allow a technician to service a terminal without a scheduled appointment and identification. Requirement 9 exists precisely because a confident stranger in a branded shirt is the easiest attack there is.
Attest, scan, and keep the evidence
Complete your SAQ annually and submit it through your processor's compliance portal. If you are scan-required, schedule ASV scans quarterly and remediate failures until you have a passing result on file.
Keep the evidence in one place: the signed attestation, the passing scan reports, your written policy, the network diagram and your terminal inventory. If a breach investigation ever happens, that folder is what protects you.
Frequently asked questions
Keep reading
Credit card processing fees, explained line by line
Interchange, assessments and markup are three different things. Here is how to read your statement, find the padding and calculate your true effective rate.
Read moreHow to switch payment processors without a single lost sale
A day-by-day switching plan covering early termination fees, Clover device reprogramming, batch cutover timing and what to verify before your first live batch.
Read more