PCI DSS for Small Merchants
PCI DSS for Small Merchants
Summary
If you accept credit or debit cards—even occasionally—you must follow the Payment Card Industry Data Security Standard (PCI DSS). The good news: most requirements are common-sense security practices you should be doing anyway, and the PCI Council provides free guides and tools specifically for small businesses.
What You Need to Know
The Six PCI DSS Requirements (Simplified)
- Build and maintain a secure network — Change default passwords on your router and payment terminal. Use a firewall.
- Protect cardholder data — Don’t store full credit card numbers on your computer or in email. Encrypt data when possible.
- Maintain a vulnerability management program — Install software updates promptly. Use antivirus on computers that handle card data.
- Implement strong access control — Each person should have their own login (no shared passwords). Give people access only to the systems they need. Enable MFA for admin accounts.
- Regularly monitor and test — Keep logs of who accesses card data. Run vulnerability scans quarterly.
- Maintain an information security policy — Document your security procedures. Have an incident response plan.
The Top 3 Causes of Payment Data Breaches
- Weak or default passwords (~30% of breaches) — Change all default passwords, use unique passwords, enable MFA
- Insecure remote access (~25% of breaches) — Disable remote access when not needed, use MFA, never share remote access credentials
- Unpatched software (~20% of breaches) — Enable auto-updates, patch promptly
Which SAQ You Need
| Your Situation | Self-Assessment Questionnaire |
|---|---|
| E-commerce website using a third-party payment processor (Shopify, PayPal, etc.) | SAQ A — simplest, shortest form |
| E-commerce where you collect card data on your own site | SAQ A-EP |
| Payment card present (chip card reader) with no electronic storage | SAQ P |
| All other situations | SAQ D — the full questionnaire |
Take Action Today
- Change default passwords on your router, payment terminal, and any payment software.
- Enable MFA on your payment processor account, email, and any admin portals.
- Download the free PCI DSS Quick Reference Guide — it explains the requirements in plain language with practical examples.
Free PCI Resources
- Guide to Safe Payments (PDF) — Step-by-step guidance for small merchants
- Common Payment Systems (PDF) — Identify what type of payment system you use
- Questions to Ask Your Vendors (PDF) — Evaluate third-party payment providers
- Data Security Essentials Evaluation Tool — Quick online assessment of your security posture
Related Pages
- cisa-cyber-essentials — The four essential practices align with PCI DSS requirements
- password-management — Weak passwords are the #1 PCI breach cause
- sba-cybersecurity — Basic awareness to get started
- cyber-resource-center — Master page with all resources