Skip to content

PCI compliance: what it actually means in a small shop

August 28, 20263 min read

It isn't a law, it isn't an audit, and your provider doesn't handle it alone. What is actually being asked of you, and where to start.

Retail shop with a payment terminal at the counter

An email arrives from your processing provider: you need to "complete your PCI compliance." No explanation of what that is, a link to a multi-page form, and a deadline. The most common reaction is to click through until it goes away.

Bad idea, and not only on principle. Here is what the exercise is really asking, and why it deserves one serious hour rather than ten distracted minutes.

What it is, and what it isn't

PCI DSS is a security standard published by the PCI Security Standards Council, the body set up by the major card networks. It applies to any business that accepts, processes, stores or transmits payment card data.

It is not a Canadian or Quebec law. It is a contractual requirement: it binds you because your processing agreement says so, not because an inspector can show up at your door. The distinction matters for knowing who you answer to, which is your acquirer rather than a government department.

Your provider does not take care of it single-handedly either. A compliant terminal installed in a shop whose router password has never been changed does not make that shop secure. The standard covers your environment, not just your device.

Which questionnaire depends on how you take payment

For a small business, validation almost always runs through a self-assessment questionnaire, what the Council calls an SAQ. There are several versions, and the right one depends entirely on how money reaches you.

A few of the merchant types:

  • SAQ A covers card-not-present merchants, whether e-commerce, mail or telephone order, who have fully outsourced all cardholder data functions to compliant third-party providers and never store, process or transmit that data themselves.
  • SAQ A-EP covers e-commerce merchants who outsource payment processing but whose website can affect the security of the transaction.
  • SAQ C-VT covers merchants who key transactions in one at a time through a virtual terminal provided by a compliant third party, with no electronic cardholder data storage.
  • SAQ D is the catch-all: it applies to merchants who don't meet the criteria for any other type, including those who store cardholder data.

If you aren't sure which one applies, the Council itself points you to your acquiring bank or card brand. That is a fair question to ask, and the answer should be in writing.

Filling in the wrong questionnaire doesn't make you compliant. It makes you attest to things that don't describe your business.

The basics, without the jargon

The Council publishes a guide aimed specifically at small merchants, the Guide to Safe Payments, which reduces the essentials to concrete actions. The ones that matter most in a neighbourhood business:

  • Never write a card number down, whether on paper, in a notebook, on an order form or in an email, and destroy whatever already exists.
  • Change every default password: router, register, camera system, admin accounts.
  • Keep the guest Wi-Fi separate from the network your terminals use.
  • Physically inspect your terminals: a tampered reader, an added enclosure, an unfamiliar cable. It is rare, but it is visible to the naked eye.
  • Give each employee their own login rather than a shared account, and remove access when people leave.
  • Install updates on your devices and on the back-office computer.

The questions to ask your vendors

The Council also publishes a short list of questions for the vendors your security actually rests on: the point-of-sale supplier, the website developer, the person who fixes the computer, whoever manages the network.

The idea is simple. Most small businesses don't run their own security, they buy it. Knowing who is responsible for what is therefore half the work. Ask, in writing, who has remote access to your systems, under which account, and how that access is protected.

Where to start on Monday

Do one thing first: map how card data moves through your business. Where does the number enter, through which device, to which provider, and is anything kept anywhere? If you can't draw that path on one sheet of paper, no questionnaire will be filled in correctly.

Then ask your processing provider which questionnaire applies to your situation and how often it has to be redone. Those two answers head off half the unpleasant surprises.

Get Started

Ready to Start Saving?

Smart payment terminals at the lowest rates in Canada. Get a free personalized quote today.

Get a Quote