Wiki

PCI DSS for Small Merchants

PCI DSS for Small Merchants

Summary

If you accept credit or debit cards—even occasionally—you must follow the Payment Card Industry Data Security Standard (PCI DSS). The good news: most requirements are common-sense security practices you should be doing anyway, and the PCI Council provides free guides and tools specifically for small businesses.

What You Need to Know

The Six PCI DSS Requirements (Simplified)

  1. Build and maintain a secure network — Change default passwords on your router and payment terminal. Use a firewall.
  2. Protect cardholder data — Don’t store full credit card numbers on your computer or in email. Encrypt data when possible.
  3. Maintain a vulnerability management program — Install software updates promptly. Use antivirus on computers that handle card data.
  4. Implement strong access control — Each person should have their own login (no shared passwords). Give people access only to the systems they need. Enable MFA for admin accounts.
  5. Regularly monitor and test — Keep logs of who accesses card data. Run vulnerability scans quarterly.
  6. Maintain an information security policy — Document your security procedures. Have an incident response plan.

The Top 3 Causes of Payment Data Breaches

  1. Weak or default passwords (~30% of breaches) — Change all default passwords, use unique passwords, enable MFA
  2. Insecure remote access (~25% of breaches) — Disable remote access when not needed, use MFA, never share remote access credentials
  3. Unpatched software (~20% of breaches) — Enable auto-updates, patch promptly

Which SAQ You Need

Your SituationSelf-Assessment Questionnaire
E-commerce website using a third-party payment processor (Shopify, PayPal, etc.)SAQ A — simplest, shortest form
E-commerce where you collect card data on your own siteSAQ A-EP
Payment card present (chip card reader) with no electronic storageSAQ P
All other situationsSAQ D — the full questionnaire

Take Action Today

  1. Change default passwords on your router, payment terminal, and any payment software.
  2. Enable MFA on your payment processor account, email, and any admin portals.
  3. Download the free PCI DSS Quick Reference Guide — it explains the requirements in plain language with practical examples.

Free PCI Resources

Sources