Navigating the Payment Card Industry Data Security Standard (PCI DSS) can feel like stepping into a maze without a map. But it doesn’t have to be that way. Whether you’re a seasoned business owner or just getting started with card payments, understanding and meeting PCI DSS requirements is essential – not just for protecting sensitive data, but for preserving your brand reputation and customer trust.

This guide breaks the process down into practical, manageable steps, helping you turn a complex standard into a competitive advantage. Here’s how to secure your business and build stronger partnerships by becoming PCI DSS compliant. 

Step 1: Know Your PCI DSS Level

Before you can begin your PCI DSS journey, you need to understand your merchant level. PCI DSS classifies merchants based on annual transaction volume and risk profile. Your level determines what kind of assessment you must complete and who needs to validate it—a critical first step to avoid missing requirements or wasting time on unnecessary tasks.

What PCI DSS compliance level am I?

PCI DSS has four merchant levels. The level that applies to your organisation depends on how many transactions you process, and what channels the transactions occur through. 

Firstly, who is a merchant? In PCI DSS terms, a merchant is any organisation that processes card transactions. So, if you’re an organisation that doesn’t meet the ordinary meaning of the term “merchant” (such as a government department or charity), don’t make the mistake of thinking that PCI DSS guidance directed at merchants doesn’t apply. If you accept card transactions (and therefore required to comply with PCI DSS), you’re a merchant in PCI terms.

 

What are the different transaction channels?

PCI DSS highlights two primary transaction channels:

  • Card-present: Where the card is read by a physical payment terminal, typically for in-person transactions (such as in retail stores). These transactions are seen as lower risk, given they are backed by robust physical payment systems and often require additional verification (such as a PIN).
  • Card-not-present: Where the card is not read by a physical terminal, commonly used for e-commerce, as well as mail and phone order transactions. These transactions are generally viewed as higher risk, since the merchant cannot physically verify the card or cardholder, increasing the potential for fraud.

Because of the differing security considerations of these two transaction types, PCI DSS compliance levels aren’t determined by transaction volume alone, as more weight is given to card-not-present transactions.

 

The PCI DSS Merchant Levels. 

Level 1:
PCI DSS level 1 applies to organisations that process over 6 million card transactions annually across all channels. Card brands can require merchants that don’t meet the transaction threshold to comply as a Level 1 merchant if they’ve previously experienced a data breach or are considered at higher risk of one.

Level 2:
PCI DSS level 2 applies to organisations that process 1 million to 6 million transactions annually across all channels.

Level 3:
PCI DSS level 3 applies to organisations that process 20,000 to 1 million card-not-present transactions annually. 

Level 4:
PCI DSS level 4 applies to organisations that process fewer than 20,000 card-not-present transactions annually, or up to 1 million total transactions across all channels.

 

Compliance Requirements by PCI DSS Merchant Level

Here’s a breakdown of the four PCI DSS merchant levels:

Level Annual Assessment Quarterly ASV Scans Attestation of Compliance (AOC) Report on Compliance (ROC)
Level 1 Onsite assessment by a Qualified Security Assessor (QSA) or internal auditor if signed by officer*.  ✅ Required ✅ Required ✅ Required
Level 2 Self-Assessment Questionnaire (SAQ) ✅ Required ✅ Required Not required**
Level 3 SAQ ✅ Required ✅ Required Not required**
Level 4 SAQ ✅ Often required by acquirer (varies) ✅ Often required by acquirer (varies) Not required**

*In some limited cases, an internal audit team may perform the annual assessment, provided this is approved by the organisation’s acquiring bank and signed off by a senior officer (such as the CIO or CISO). This signature certifies the validity of the assessment and places personal responsibility for its accuracy on the signing officer.

**A RoC is not required for level 2-4 merchants. However, your payment brand or acquiring bank may require your organisation to complete one. 

 

Once you’ve determined your PCI DSS level, you’ll know what’s required of your organisation to achieve and maintain PCI DSS compliance, and are ready to follow the next steps that apply. 

 

Step 2: Self-Assess or Get Reviewed

Depending on your level, you’ll need to either complete a self-assessment or undergo a formal review by a QSA. This step ensures you’re meeting the right security standards for how your business handles card data – without overcomplicating things.

 

Step 3: Define Your Assessment Scope

Scope is everything. The goal here is to identify all systems, processes, and technologies that store, process, or transmit cardholder data. This is what’s known as the Cardholder Data Environment (CDE).

Getting this right early on can dramatically reduce time, cost, and complexity later. Start broad and trim carefully.

Key steps to scope effectively:

  • Map your payment ecosystem: Identify all entry points—apps, servers, POS devices, third-party tools—where card data is collected, used, or stored.
  • Build a Cardholder Data Matrix: Document which systems touch card data, what data is stored, why, how long, and how it’s protected.
  • Use discovery tools: Automated scanning tools can help you uncover unknown storage locations of cardholder data.
  • Segment your network: Isolating systems that handle card data can reduce the compliance burden. Proper network segmentation reduces scope and simplifies your assessment.

What data qualifies?

  • Cardholder Data:

    • PAN (Primary Account Number)
    • Cardholder Name
    • Expiration Date
    • Service Code
  • Sensitive Authentication Data (which must never be stored):

    • Full magnetic stripe or chip data
    • CVV/CVC
    • PIN/PIN block

Ensuring a clear and limited scope not only makes compliance easier, it protects your business by limiting exposure.

 

Step 4: Complete the Self-Assessment Questionnaire (SAQ)

A Self-Assessment Questionnaire (SAQ) is a detailed checklist used to verify your compliance with applicable PCI DSS controls. It’s tailored to your business model and card handling practices.

There are multiple versions of the SAQ, each suited to a different kind of payment setup. Choosing the wrong one – or filling it out incorrectly – can lead to compliance failure or increased risk.

Be honest and thorough. The SAQ isn’t just paperwork—it’s a diagnostic tool to identify vulnerabilities and guide remediation.

 

Step 5: Fix What’s Broken (Remediation)

Few organisations get through the SAQ without uncovering gaps. This step is all about closing those gaps, whether that means implementing missing controls, improving encryption, or changing how systems are configured.

Your remediation plan should:

  • Group similar fixes into phases to reduce complexity and avoid rework
  • Prioritise by risk. Fix the most critical issues first
  • Use compensating controls only when you cannot meet a PCI DSS requirement directly
  • Consider outsourcing high-risk components to PCI DSS-compliant service providers

Youl also need to fill out the ‘Action Plan for Non-Compliant Status’ if you can’t fix everything right away. This plan must be submitted with your SAQ and updated quarterly until you reach full compliance.

 

Step 6: Pass a Network Vulnerability Scan

If you’re a Level 1, 2, 3, or 4 merchant that processes, transmits, or stores cardholder data online or through a networked system, you’ll need to run a vulnerability scan every 90 days—at minimum.

What’s involved:

  • The scan must be performed by an Approved Scanning Vendor (ASV)
  • It evaluates your system for known vulnerabilities and misconfigurations
  • Any failed scan must be remediated and re-tested until it passes

How often should you get a vulnerability scan? 

Proactive scanning – monthly or even more frequently – is a smart way to stay ahead of emerging threats.

 

Step 7: Submit the Attestation of Compliance (AOC)

The AOC is your formal declaration that you’re PCI DSS compliant. It must be completed and signed by an authorised executive – typically the CEO, CIO, or Information Security Manager.

What to include:

  • The completed AOC (found at the end of your SAQ document)
  • Any necessary Action Plan for Non-Compliant Status
  • Proof of network vulnerability scans

Then, you can send the completed AOC to your acquiring bank, demonstrating that your organisation has met the security standards required to process card payments.

 

Step 8: Maintain Compliance Year-Round

PCI DSS compliance isn’t a one-time achievement – it’s a continuous process. Security threats evolve. Systems change. So should your approach to risk.

Stay compliant by:

  • Completing a fresh SAQ annually
  • Running quarterly vulnerability scans
  • Reassessing scope when infrastructure changes
  • Training your staff regularly on data security best practices

Need help along the way? Contact our team. We’re here to guide you at every stage.

 

Data Breaches & Non-Compliance: The Real Risks

Data breaches are on the rise, and impacting organisations of all sizes and industries. Each breach damages trust, costs money, and invites regulatory and contractual penalties.

If a breach occurs:

  • Don’t alter your systems. Preserve all digital evidence.
  • Contact Stratica immediately to begin a forensic investigation.
  • Cooperate with card brands and your financial institution.

Potential penalties include:

  • Visa: Up to $25,000 (and more) for small merchant violations
  • MasterCard: Up to $100,000 per violation
  • Ongoing monthly fines for unresolved issues
  • Liability for fraud-related damages, investigation costs, and card reissuance

Your financial institution may pass fines on to you, as outlined in your Merchant Agreement (section 3.7).

 

Why PCI DSS Compliance Matters

PCI DSS isn’t just a compliance checkbox. It’s your defence against fraud, your commitment to trust, and your competitive edge.

By understanding the process and partnering with experts like Stratica, you can secure your business, strengthen customer loyalty, and meet your contractual obligations with confidence.

 

Need Help?

Stratica’s experts are here to assist with every part of your compliance journey—from scoping and SAQs to remediation and breach response.

Contact Us