1st Bankcard Services

PCI compliance, explained plainly for a small business

PCI compliance sounds like a project. For most small merchants it is a short annual questionnaire and a few sensible habits. Here is what it actually asks of you, and what it costs.

7 min readUpdated July 2026

If you take cards, you are on the hook for PCI compliance, and most owners find that out from a fee on a statement rather than a plain explanation. So here is the plain version. PCI compliance is the set of security rules the card industry expects every business that accepts cards to follow, and for a typical small shop it comes down to a yearly questionnaire and a handful of habits, not a six-month audit. Get it explained once and the mystery goes away.

What is PCI compliance?

PCI compliance means meeting the Payment Card Industry Data Security Standard, usually shortened to PCI DSS. It is the security rulebook the major card brands, Visa and Mastercard and the rest, agreed on together to protect cardholder data. It is not a government law. It is a contractual standard: when you signed up to accept cards, you agreed to follow it, the same as every other merchant on the planet.

The point of the standard is narrow and useful. Keep card numbers out of the wrong hands. That means protecting card data when you store it, when you send it, and when you handle it, and proving once a year that you are doing the basics right.

What does PCI DSS actually require?

At a high level, PCI DSS asks you to protect card data with a small number of common-sense controls. You do not need to memorize the standard. You do need to know the shape of it:

  • Do not store what you do not need. The safest card number is the one you never wrote down. Modern terminals and gateways are built so the raw number never sits on your systems.
  • Protect the data that does move. Card data should be encrypted in transit so a number cannot be read if it is intercepted.
  • Lock down access. Unique logins, real passwords, and no sharing one admin account across the whole team.
  • Keep the software current and watch for tampering, especially on the physical devices where cards get swiped, dipped, or tapped.

That is the spirit of it. The full standard has hundreds of individual items, but the ones that touch a small merchant are the ones above.

What is the SAQ, and how does validation work?

For most small businesses, validating PCI compliance means filling out a Self-Assessment Questionnaire, or SAQ, once a year. It is a yes-or-no checklist about how you handle cards, and which version you complete depends on how you take payments. A shop that only uses a modern terminal answers a short one. A business that keys card numbers into a web page answers a longer one, because more of the risk sits with you.

The general rule is simple: the less card data touches your own systems, the shorter your questionnaire and the smaller your scope. If your terminal or gateway handles the raw number and you never store it, you have taken most of the burden off your own plate. Some setups also call for a network scan by an approved vendor, but a typical countertop terminal usually does not.

PCI validation is not a grade a processor hands you. It is your yearly attestation that you handle cards responsibly. A good processor makes that easy to complete. It cannot do it for you, and anyone who promises to make you compliant with no effort on your end is overselling.

How does a processor help with PCI compliance?

A processor helps in three concrete ways. First, it gives you equipment and software that keeps raw card numbers off your systems, which shrinks your questionnaire before you answer a single line. Second, it provides a compliance portal that walks you through the SAQ in plain language and tracks your renewal date. Third, it keeps your program current as the rules change, so you are not the one reading network bulletins.

The security tools that do the heavy lifting are encryption and tokenization, and they are worth understanding on their own. We break them down in our guide on how encryption and tokenization protect a transaction. Together they are the reason a small shop can keep its PCI scope small.

What does PCI compliance cost with us?

Here is the straight money answer, because this is usually where the surprise lives. We charge one PCI compliance fee, billed once a year. It covers your PCI DSS validation and the compliance portal that walks you through it, and we show you the exact amount in writing before you sign. There is no monthly PCI charge buried in the statement and no penalty that quietly kicks in later.

That yearly fee is the only charge beyond the two we publish: interchange passed through at cost, and a flat ten-cent markup per transaction. No monthly fees, no statement fees, no batch fees, no monthly minimums. When someone asks what they pay us, the answer is interchange, a dime a transaction, and one PCI fee a year. That is the whole list.

Watch out for the opposite trick. Some statements carry a monthly PCI fee, and some add a fat non-compliance penalty every month you have not finished the questionnaire, sometimes twenty or thirty dollars a month, which is really a fee for not clicking through a form. If your current statement shows a recurring PCI line, that is a fair thing to question.

Upload a recent statement and we will point out any PCI or compliance fees hiding in it, in dollars.

Analyze my statement

One last note. This is general information about how PCI works, not legal or compliance advice for your specific business. Your exact requirements depend on how you accept cards and how much card data you touch. We help you figure out which questionnaire applies to you and keep your validation current.

Questions, answered plainly

No. PCI DSS is a contractual security standard set by the card brands, not a government law. You agreed to follow it when you signed up to accept cards, and every business that takes cards is expected to meet it.

We charge one PCI compliance fee billed once a year, and we disclose the exact amount in writing before you sign. It covers your annual PCI DSS validation and the compliance portal. There is no monthly PCI charge and no hidden non-compliance penalty.

For most small merchants, yes, a short annual Self-Assessment Questionnaire. Our compliance portal walks you through it in plain language and tracks your renewal date. A processor can make it easy, but the attestation is yours to complete.

You carry more risk if card data is exposed, and some processors add monthly penalties until you finish your questionnaire. The fix is usually just completing the SAQ and using equipment that keeps raw card numbers off your systems.


See it on your own statement

Reading about the fees is one thing. Finding yours takes about a minute. Send your last statement and a specialist sends back your effective rate and your markup, next to a dime.