Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

What Is PCI Compliance? A Plain-English Guide for Business Owners

July 14, 2026

What is PCI compliance? PCI compliance is the set of security standards that any business accepting, processing, storing, or transmitting credit card data must follow to protect cardholder information. It is not a government law, but rather a strict contractual requirement enforced by major card brands through your payment processor. If your business takes credit cards, you must prove you are actively protecting that sensitive data.

Many business owners only hear about PCI compliance when they receive a warning letter from their bank. Or they spot a non-compliance fee on their monthly merchant statement. Sorting through the acronyms and technical requirements can feel overwhelming. But understanding the basics helps protect your business from financial penalties and devastating data breaches.

This guide breaks down exactly what the standard is, who it applies to, what you actually have to do, and how to prove you are doing it.

What Is PCI Compliance? PCI DSS Explained

PCI DSS stands for the Payment Card Industry Data Security Standard. It is a comprehensive set of security requirements created and maintained by the PCI Security Standards Council.

The council was founded by the major card brands: Visa, Mastercard, American Express, Discover, and JCB. These organizations recognized that a unified approach to data security was necessary to protect consumers and businesses alike. Together, they created a baseline of security for cardholder data globally.

The primary goal of the standard is to protect specific types of payment information. Cardholder data includes four items: the primary account number (PAN), the cardholder name, the expiration date, and the service code. The standard dictates exactly how this information must be handled. The rules apply from the moment a card is swiped, dipped, or entered online.

Sensitive authentication data has one absolute rule: you may never store it after authorization. This category includes the CVV or CVC security code on the back of the card, full magnetic stripe data, track data, and PINs.

The rule applies even if the data is encrypted. If your business systems are found storing this data after a transaction is authorized, you are violating a core requirement of PCI DSS and putting your business at extreme risk.

The standard is not static. The rules are updated periodically to address new cybersecurity threats and evolving technology. Businesses must continuously align their security practices with the current standards to remain compliant.

PCI DSS 3.2.1 was retired on March 31, 2024. PCI DSS 4.0.1 is the current version, having superseded version 4.0. The future-dated requirements introduced with version 4.0 became mandatory on March 31, 2025.

Who Has to Comply

PCI DSS applies to any business that accepts, processes, stores, or transmits payment card data. It does not matter if you are a massive national retail chain or a single-location Chicagoland shop. Regardless of your company size or your annual transaction volume, if card data touches your business operations, the standard applies to you.

Using a payment processor does not erase your compliance obligation. Many business owners mistakenly believe that outsourcing payments to a third party removes their responsibility entirely. It does not. While outsourcing can shrink your security burden, you must still validate your compliance. You are still required to ensure that your internal practices and the vendors you choose meet the necessary security benchmarks.

It is also critical to understand the legal nature of these rules. PCI compliance is not a government law in the United States. Instead, it is a contractual obligation.

When you sign a merchant agreement to accept credit cards, you agree to follow the rules set by the card brands. This obligation is enforced directly by your acquiring bank or your payment processor. You will not face government fines for failing to meet the standard. But your processor will charge non-compliance fees. And a breach while non-compliant can cost far more.

What it Requires

The PCI DSS framework is organized into 12 specific requirements grouped under six broader security goals. These rules dictate exactly how your IT environment must be secured. Here is the quick-scan checklist, followed by the plain-English breakdown of each requirement.

  1. Install and maintain network security controls. You must have firewalls and secure network boundaries in place to protect card data from unauthorized access from the internet.
  2. Apply secure configurations. You must harden your systems and never keep vendor defaults. This means changing default passwords on routers, firewalls, and software immediately upon installation.
  3. Protect stored account data. If you have a legitimate business reason to store cardholder data, it must be protected. As noted earlier, you may never store sensitive authentication data like the CVV after authorization, even if it is heavily encrypted.
  4. Protect cardholder data with strong cryptography during transit. Card data must be encrypted when moving over open, public networks like the internet to prevent interception.
  5. Protect all systems against malware. You must use and regularly update antivirus software and anti-malware tools on all systems that interact with card data.
  6. Develop and maintain secure systems and software. You must apply security patches promptly to fix known vulnerabilities in your software and operating systems.
  7. Restrict access to system components and cardholder data by business need-to-know. Only employees who absolutely require access to card data to perform their daily job duties should have it.
  8. Identify users and authenticate access to system components. Every single user must have a unique ID. You must also require multi-factor authentication (MFA) for any access into the cardholder data environment.
  9. Restrict physical access to cardholder data. You must physically secure servers, paper records, and payment terminals to prevent unauthorized people from physically grabbing data.
  10. Log and monitor all access to system components and cardholder data. You must track exactly who accesses what systems and keep those logs available for review.
  11. Test security of systems and networks regularly. This includes internal testing, penetration testing, and, where applicable, quarterly external vulnerability scans performed by an Approved Scanning Vendor.
  12. Maintain an information security policy and program. You must have documented policies that clearly tell your staff how to handle security and maintain compliance year-round.

What Happens If You Are Not Compliant

Because PCI compliance is a contractual agreement, the consequences of non-compliance flow directly through your payment processor. The card brands do not fine your business directly. Instead, they penalize the acquiring bank, which then passes those costs down to you through your merchant agreement.

The most common immediate consequence is a monthly non-compliance fee. If you fail to submit your validation paperwork on time, your processor will add a recurring fee to your merchant account statement. This fee will continue every single month until you prove you are compliant.

If a data breach occurs while you are non-compliant, the financial fallout is severe. Hackers steal credit card numbers from your systems. You then face a cascade of costs:

  • A mandatory and expensive forensic investigation to determine exactly how the breach happened and what data was lost
  • Significant card-brand assessments passed through your acquirer
  • Card reissuance costs, meaning you pay to replace the compromised credit cards of every affected customer

Following a breach, your processor will likely move you to a higher processing rate. This reflects the increased risk your business now poses. In the worst case, your acquiring bank may drop your account entirely. You lose the ability to accept credit cards. For most businesses, that is a fatal blow.

What PCI compliance means: protect card data, secure your network, validate annually

How Compliance Is Validated

Proving that you meet the 12 requirements is an ongoing process. Compliance validation operates on an annual cycle. How you validate depends entirely on how many transactions you process and how your technical environment is set up.

Becoming and staying compliant generally follows four steps:

  1. Identify your merchant level. The card brands tier you into Level 1 through Level 4 based on your annual transaction volume, and your level determines how you validate.
  2. Complete your validation. Most small and mid-size businesses (Level 4) complete a Self-Assessment Questionnaire (SAQ) annually. Level 1 merchants instead undergo an intensive on-site assessment by a Qualified Security Assessor (QSA).
  3. Complete quarterly vulnerability scans if required. Some merchant profiles must have an Approved Scanning Vendor scan their external network boundaries every quarter.
  4. Scope and segment your cardholder data environment (CDE). Isolating the CDE with network segmentation shrinks how many systems must meet the full standard.

Here is each piece in more detail. The card brands tier merchants into four levels based on annual transaction volume, structured under the merchant-level system Visa uses to match the risk profile of the business. Exact thresholds and validation requirements are ultimately set by each card brand and your specific acquirer.

Merchant LevelAnnual Transaction VolumeValidation Path
Level 1Over six million transactions per yearIntensive on-site assessment by a Qualified Security Assessor (QSA), resulting in a formal Report on Compliance (ROC)
Level 2One million to six million transactions per yearSet by the card brand and your acquirer
Level 320,000 to one million e-commerce transactions per yearSet by the card brand and your acquirer
Level 4Fewer than 20,000 e-commerce transactions, or up to one million total transactions across all channelsSelf-Assessment Questionnaire (SAQ), completed annually (most small and mid-size businesses)

Most small and mid-size businesses fall into Level 4. The SAQ is a detailed checklist where you attest that you are meeting the required security controls for your specific payment setup. There are multiple SAQ versions, and choosing the right one is critical for an accurate assessment:

SAQ TypeWho it Is For
SAQ ACard-not-present merchants where all payment processing is fully outsourced to a validated third party
SAQ A-EPE-commerce sites where the website itself affects the security of the payment page, even if the payment is processed by a third party
SAQ BMerchants using imprint machines or standalone dial-out terminals with absolutely no electronic storage of card data
SAQ B-IPMerchants using standalone IP-connected terminals
SAQ CMerchants with payment application systems connected to the internet
SAQ C-VTMerchants who manually enter single transactions via a virtual terminal
SAQ P2PEMerchants using validated point-to-point encryption solutions
SAQ DEveryone else. This is the longest form and is also the version used by service providers

Compliance is ultimately about your cardholder data environment (CDE). The CDE is every system, person, and process that touches cardholder data or sensitive authentication data, plus anything connected to those systems.

Network segmentation shrinks your compliance burden. By isolating the CDE from the rest of your business network, fewer systems must meet the full PCI DSS requirements. A smaller CDE means a shorter SAQ and less work each year.

See Where You Stand

Free 2-minute PCI self-check: 8 plain-English questions, your risk level and the exact gaps to fix. No sign-up to see your result. free 2-minute PCI DSS self-assessment

Frequently Asked Questions

Is PCI compliance required by law?

PCI compliance is not a government law in the United States. It is a contractual obligation enforced by the major card brands through your acquiring bank or payment processor. If you sign an agreement to accept credit cards, you are contractually required to follow these data security standards.

Who needs to be PCI compliant?

The standard applies to any business that accepts, processes, stores, or transmits payment card data. Your business size or annual transaction volume does not matter. If cardholder data touches your business systems in any way, you must validate your compliance.

What happens if I am not PCI compliant?

The immediate consequence is typically a monthly non-compliance fee added to your merchant statement by your processor. If a data breach occurs while you are non-compliant, you face severe penalties including forensic investigation costs, card-brand assessments, card reissuance expenses, and potentially losing the ability to accept credit cards entirely.

How do I prove PCI compliance?

Most small and mid-size businesses prove compliance annually by completing a Self-Assessment Questionnaire (SAQ). Some merchant profiles also require quarterly external vulnerability scans performed by an Approved Scanning Vendor. Large businesses processing over six million transactions require an on-site assessment by a Qualified Security Assessor.

What is the cardholder data environment?

The cardholder data environment, or CDE, includes all the systems, people, and processes that store, process, or transmit cardholder data. It also includes any network systems connected to them. Businesses use network segmentation to isolate the CDE, which reduces the number of systems that must meet the strict security standards.

Secure Your Business and Maintain Compliance

LeadingIT is a Chicagoland managed it and cybersecurity provider that has helped Illinois businesses since 2010. We serve roughly 200 organizations and over 2,500 users from our offices in Woodstock and Manteno.

Our team operates the technical half of PCI compliance as part of our managed cybersecurity services. That covers network segmentation, MFA enforcement, patch management, logging, and scan remediation. We also help clients complete their annual SAQ correctly.

LeadingIT is not a QSA or ASV and does not certify PCI compliance, but we help you become and stay compliant. If you need expert guidance, explore LeadingIT’s PCI compliance services. You can also book a call or contact us directly at 815-788-6041 to discuss your security needs.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.