PCI DSS
Also known as: PCI compliance, Payment Card Industry Data Security Standard
The security standard every business handling card data must follow.
PCI DSS is the card industry's security standard for storing, processing, and transmitting cardholder data. Compliance requirements scale with volume (Levels 1 to 4). Using a hosted checkout or tokenization shifts most of the burden to your processor and shrinks your compliance scope.
How it works
Look at your statement first. Many processors charge a PCI non-compliance fee, commonly in the region of $20 to $40 a month, and it runs until you complete the questionnaire and attestation in their portal. Some also charge a smaller PCI service fee whether you validate or not. For a merchant with a fully outsourced checkout the questionnaire is short, so that monthly charge is buying nothing except your own inertia. Compliance itself is mostly an admin cost. Non-compliance is a line item.
Your level comes from annual card volume across every channel you sell through. Level 1 sits above six million Visa or Mastercard transactions a year and brings a formal annual assessment, normally by a Qualified Security Assessor, plus quarterly scans by an approved scanning vendor. Below that you usually self-assess, using whichever Self-Assessment Questionnaire matches how the card data reaches you: SAQ A if the checkout is fully outsourced, SAQ A-EP if you host the page and it posts to a gateway, SAQ D for anything that touches card data directly.
Outsourcing shrinks your scope. It does not end your obligation, and you still validate and attest every year. Version 4.0 of the standard, in full effect since 2025, also tightened the rules on scripts running on payment pages, so ask your provider what it now expects from you. Watch two habits in particular: taking card numbers over the phone or by email drags you into a heavier questionnaire, and a call recording that captures a spoken security code is a breach of the standard.
Worked example
$299.40. That is what one online shop paid for ignoring reminder emails. It takes 12,000 card transactions a year, which puts it at Level 4, and its checkout is hosted, so its obligation is SAQ A: a short self-assessment and an annual attestation in the processor's portal. Roughly an hour of paperwork. Instead the shop carried a $24.95 monthly non-compliance fee all year.
Frequently asked questions
- Am I PCI compliant automatically if I use a hosted checkout?
- Hosted checkout removes almost all of the technical burden and none of the paperwork. You still have to validate compliance yourself, normally by completing SAQ A and an annual attestation. Your provider answers for its own systems, not for your obligation as a merchant. Anything outside the hosted page stays yours too, including staff taking card details over the phone.
- How much does PCI compliance cost a small business?
- For a small merchant on a hosted checkout, usually nothing beyond your own time, plus whatever PCI fee your processor adds. Some providers charge a small monthly PCI service fee, and many charge a non-compliance fee of roughly $20 to $40 a month if you never validate. The cost only jumps at Level 1, where engaging a Qualified Security Assessor runs into tens of thousands of dollars.
- What happens if I am not PCI compliant and card data is stolen?
- Card-network fines, passed through your processor, plus the cost of a forensic investigation and card reissuance. Your acquirer can also close the account. The fines land on the acquiring bank first and flow down to you under your merchant agreement, which is why the liability clause is worth reading before you sign. Validating beforehand does not remove liability after a breach, but it improves your position substantially.