PCI compliance doesn’t have to be a headache. The process can actually be broken down into four manageable steps.

If you’re a small business owner like me, you’re likely a jack-of-all-trades out of necessity, not out of actual interest. This can make annual PCI compliance requirements a stressful task, especially if you’re new to the PCI DSS.
To make this easy, I talked with Marcus Clawson (Senior Product Manager at SecurityMetrics) and Jameson Olsen (Product Marketing Manager at SecurityMetrics) to see what SMB owners actually need to know about PCI to give you a simplified, four-step path to securing your small business.
Make no mistake, just because your business isn’t dealing with the amount of revenue of, say, a Fortune 500 organization, does not mean you’re not a target for malicious threat actors. In fact, threat actors often target small businesses specifically because they’re typically easier to breach.
Did you know that 43% of all cyberattacks target SMBs? SMBs are often targets because they lack the resources to protect themselves as larger, more established companies can.
This poses a significant financial risk to a small business, with the average breach costing from a couple of thousand dollars up to hundreds of thousands of dollars. However, the highest cost is often customer trust. Olsen pointed out that “the loss of trust with customers if their data is leaked because you failed to protect it can have a huge impact on the reputation of your business."
PCI DSS is a security standard established by major card brands (e.g., Visa, Mastercard=) to standardize protections for cardholder data. Clawson explains that “all merchants that accept payment data or credit cards, payment cards need to comply with PCI."
Because the current threats drive the PCI standard, it needs to evolve (like the recent swap to version 4) to keep up with bad actors. These changes aren't meant to complicate your life.
In fact, Clawson says, "the Council looks at these requirements and realizes that they can be made more efficient... These changes are always evolving for the better. Better protection, more efficiency.”
If you fail to protect your customers’ data, card companies can take action in the form of costly non-compliance fees or the card brands can even prevent you from processing their credit cards at all at your business.
PCI compliance doesn’t have to be a headache. The process can actually be broken down into four manageable steps.
The complexity of your compliance effort depends entirely on how you handle card data. The PCI Council uses Self-Assessment Questionnaires (SAQs) to group businesses into categories with applicable requirements. Clawson explains that an SAQ is "a way of grouping you into a category with a certain set of requirements, so you know what applies to you."
First, determine exactly what you do as an organization and how you handle card data (e.g., swiping at a kiosk, e-commerce, taking cards over the phone). Then, identify our SAQ type:
See More: Which PCI SAQ Is Right For My Business? Blog
Once your scope is defined, your provider will give you the appropriate questions and requirements for your business.
Keep in mind, the SAQ is a series of questions. Once you have met the requirements listed, you attest to that fact, then you receive a certificate that shows you are compliant for the year.
Answering questions is only part of the process. Depending on your SAQ type, you will need to apply security tools and testing to validate your security posture:
Once you've met all your requirements and attested to your compliance, you are issued a certificate of compliance. The next steps include:
PCI compliance can be a big task for any small business owner. That’s why I like that SecurityMetrics is focused on making the experience simple while still protecting your business.
When you choose a PCI compliance provider for your business, choose someone with 24/7, 365-day-a-year expert customer support. This will help you get the answers you need right away instead of spending hours on Google or Reddit trying to get niche answers to specific problems.
You can also use free educational resources found on the SecurityMetrics blog and through the SecurityMetrics Academy. As Olsen reminds us, SecurityMetrics is “here to make sure that you can take care of the things you need to take care of on your cybersecurity front and get back to running your business."
Need a PCI partner who understands small business requirements? Speak to an expert today.