Compliance guidance
PCI DSS for Small Business
Quick answer
PCI DSS concerns entities that store, process, or transmit payment account data, with responsibilities influenced by how payments are accepted and which providers are used.
Who this is for: Businesses accepting card payments or handling payment account data.
What to do
- 01Document the payment flows and systems involved.
- 02Ask your payment provider which responsibilities remain with your business.
- 03Reduce stored card data and restrict access to payment systems.
- 04Use the current PCI SSC materials or a qualified assessor for validation.
What this does not cover
This overview is not a compliance assessment and does not determine your validation level or SAQ.
This page is educational information, not legal advice or a professional security audit. Check the official requirements and get qualified help when your circumstances require it.
See how this applies to your businessContinue exploring