Skip to content

service // pci

PCI DSS

PCI DSS made simple — know your SAQ, shrink your scope

PCI DSS applies to any business that accepts card payments — there's no revenue threshold and no exemption. The good news: for most small businesses it's a 30-60 minute annual questionnaire, not a project. The catch: only if your setup keeps card data out of your environment. I help you get there.

What's included

Common questions

Does PCI DSS really apply to small businesses?

Yes. PCI DSS applies to any business that accepts, stores, processes, or transmits cardholder data — no revenue threshold and no exemption. Most small businesses are Level 4 merchants, which means validation is a Self-Assessment Questionnaire (SAQ) filed annually.

Which SAQ do I need?

It depends on how you accept payments. If you outsource all card processing (for example a hosted payment page), you likely qualify for the shortest SAQ. If your systems store card data, you face a much longer questionnaire. Scope reduction is the single biggest lever — don’t store card numbers.

How long does PCI compliance take?

For a small business with the right setup, the annual SAQ takes roughly 30-60 minutes plus a quarterly scan if required by your SAQ. The upfront work is configuring your payment environment so card data never touches your systems.

Am I overpaying for PCI?

Many processors bundle a PCI fee into your statement that is far above the actual cost of compliance — which can be $0-30 per year for a small merchant. If you’re paying $200+/year for a "PCI fee," it’s worth a second look.

Talk it through

A free 30-minute call to see whether PCI DSS applies to you and what the first step looks like.

book the call