Back to the library
Payment Processing
2026-07-26 9 min read

What Is PCI DSS Compliance? A Plain-English Guide

PCI DSS applies to any business that touches card data, no matter its size. Here is what the standard actually requires and which level applies to you.

GM

By Gray Merchants Team

PCI DSS compliancePCI DSS requirementsmerchant compliance levelsSAQhosted payment page
What Is PCI DSS Compliance? A Plain-English Guide
Key takeaways
  • PCI DSS applies to any business that stores, processes, or transmits cardholder data, regardless of size or transaction volume, whether it happens directly or through a third party.
  • The current standard is PCI DSS v4.0.1 (June 2024), with 51 previously future-dated requirements becoming mandatory as of March 31, 2025.
  • Visa defines four merchant compliance levels by annual transaction volume, from Level 1 (over 6 million transactions, requiring a full third-party audit) to Level 4 (under 20,000, requiring just an annual self-assessment).
  • A fully-hosted payment page is the most direct route to SAQ A, the lightest compliance tier, and the PCI Council removed three specific requirements from that path in 2025.
  • Non-compliance consequences flow through the acquiring bank rather than hitting the merchant directly, typically as increased fees or a review of continued processing eligibility.

So what is PCI DSS compliance? It's the security standard every business has to meet if it stores, processes, or transmits card data, set by the card networks through the PCI Security Standards Council. It's not optional, and it's not just for big companies. A one-person online shop and a national retail chain both have to meet it, just at different levels of documentation and testing.

Who Actually Has to Comply

This is the part that surprises a lot of small business owners. PCI DSS applies to any entity that stores, processes, or transmits cardholder data, full stop, regardless of size or transaction volume, and regardless of whether it happens directly or through a third-party processor (PCI Security Standards Council). Even a business that fully outsources checkout to a payment gateway still has some level of PCI obligation, just a much lighter one than a business handling raw card data on its own servers.

The Six Goals Behind the 12 Requirements

PCI DSS organizes its requirements into six broad goals, each covering a group of the 12 numbered requirements:

  1. Build and maintain a secure network and systems (firewalls, no vendor-default passwords)
  2. Protect account data (encrypt stored and transmitted cardholder data)
  3. Maintain a vulnerability management program (anti-malware, secure system development)
  4. Implement strong access control measures (restrict data access by need-to-know, unique user IDs, control physical access)
  5. Regularly monitor and test networks (log and monitor all access, run quarterly vulnerability scans and periodic penetration testing)
  6. Maintain an information security policy (a documented, organization-wide security policy)

That structure hasn't changed in spirit since earlier versions of the standard. What changed with v4.0.1 is mostly how specific requirements get validated and which ones apply to which merchant type.

What's Current Right Now: PCI DSS v4.0.1

The standard you need to meet today is version 4.0.1, published by the PCI Security Standards Council in June 2024. The prior version, 4.0, was retired at the end of 2024. As of March 31, 2025, 51 requirements that had been future-dated (meaning they existed on paper but weren't yet mandatory) became fully required (PCI Security Standards Council, 2024). If your business hasn't reviewed its compliance status since before that date, it's worth checking whether any of those newly-mandatory requirements affect you.

The Four Merchant Compliance Levels

Card networks assign every merchant a compliance level based on annual transaction volume, and that level determines how you validate compliance. Visa's own framework breaks it down this way (Visa):

  • Level 1: over 6 million Visa transactions annually across all channels. Requires an annual Report on Compliance (ROC) from a Qualified Security Assessor (QSA), plus quarterly network scans by an Approved Scan Vendor (ASV).
  • Level 2: 1 million to 6 million Visa transactions annually. Requires an annual Self-Assessment Questionnaire (SAQ) plus quarterly ASV scans.
  • Level 3: 20,000 to 1 million Visa e-commerce transactions annually. Requires an annual SAQ plus quarterly ASV scans.
  • Level 4: under 20,000 Visa e-commerce transactions annually, or up to 1 million Visa transactions through other channels. Requires an annual SAQ, and an ASV scan is recommended.

Most small and mid-sized merchants fall into Level 3 or 4, which means an SAQ rather than a full third-party audit. That's a real difference in cost and effort, and it's exactly why the SAQ type you're eligible for matters so much.

Why the Self-Assessment Questionnaire (SAQ) Type Matters

Not all SAQs are created equal. The type you qualify for depends entirely on how your business actually handles card data, not just your transaction volume. A business that keys in cards manually has different obligations than one whose customers only ever see a payment page hosted entirely by a third party.

SAQ A is the narrowest, lowest-burden tier, and it's only available to merchants that have fully outsourced all cardholder data handling to validated third parties, with none of that data ever touching the merchant's own systems (PCI Security Standards Council, 2025). A fully-hosted or iframe-embedded payment page is the most direct way to qualify, since the card data never passes through your own servers at all.

The PCI Council tightened and simplified this path further in 2025. As of the effective date that year, merchants using a fully-outsourced hosted payment page had three specific requirements (6.4.3, 11.6.1, and 12.3.1) removed from their SAQ A obligations entirely, replacing a more complex eligibility test with a simpler confirmation that the site isn't vulnerable to script-based attacks (PCI Security Standards Council, 2025). A hosted payment page that keeps cardholder data off your own servers entirely is the most direct route to this lighter compliance tier.

What Happens if You're Not Compliant

Non-compliance isn't primarily enforced against the merchant directly. It flows through the acquiring bank. Card network programs hold acquirers accountable for the compliance of the merchants they sponsor, and acquirers pass consequences down through their merchant agreements, typically as increased fees or, in serious or sustained cases, a review of the account's continued processing eligibility. The exact fee structures vary by acquirer and aren't uniformly published, so the specific number that applies to any one business depends on its own merchant agreement.

What is worth being precise about: compliance isn't a one-time checkbox. It's validated annually (or quarterly for network scans), and a business that let its compliance lapse since the last SAQ deadline is worth revisiting now, especially given how many requirements shifted with the move to v4.0.1.

What This Actually Means for a High-Risk Merchant

A high-risk business already carries more underwriting scrutiny than a standard retail account, and clean, current PCI documentation is one of the few things entirely within your control to keep that underwriting process smooth. Acquiring banks want to see that a merchant takes cardholder data handling seriously before they extend the reserve terms and processing capacity a growing high-risk business needs. A dedicated high-risk merchant account built around real compliance documentation, rather than treating it as an afterthought, moves through underwriting faster and holds up better if a dispute or review ever comes up.

Frequently Asked Questions

Does a small business really need to worry about PCI DSS?

Yes. PCI DSS applies regardless of size or transaction volume. A small business's obligation is typically much lighter (an annual SAQ instead of a full audit), but it's not optional.

What's the fastest way to reduce PCI compliance burden?

Use a fully-hosted or iframe-embedded payment page so cardholder data never touches your own servers. That's the most direct path to SAQ A, the lightest validation tier.

How often does PCI DSS compliance need to be validated?

Annually for the SAQ or Report on Compliance, and quarterly for network vulnerability scans if your level requires an ASV scan.

What's the difference between an SAQ and a Report on Compliance (ROC)?

An SAQ is a self-assessment a business completes itself. A ROC is a formal report produced by a Qualified Security Assessor (QSA) after an on-site audit, required only for the highest-volume Level 1 merchants.

What changed with PCI DSS v4.0.1 that merchants should know about?

Version 4.0.1 (June 2024) is the current standard. As of March 31, 2025, 51 requirements that had been future-dated became fully mandatory, and the SAQ A eligibility path for hosted-payment-page merchants was simplified with three requirements removed entirely.

Want a merchant account setup that keeps PCI scope as light as possible from day one? Apply free for a 24 to 48 hour decision, or talk to a specialist about hosted payment page options.

GM

Gray Merchants Team

Gray Merchants is a payment ISO that places merchant accounts across every risk level — from low-risk retail and e-commerce to 67+ high-risk verticals. The editorial team writes on high-risk merchant accounts, chargeback defense, MATCH/TMF remediation, and ACH processing — whether you are new, scaling, switching processors, or rebuilding after a decline.

Talk to a specialist

Tell us about your business

Share a few details and a specialist reviews your industry, volume, and processing history, then comes back with the right path — no obligation.

  • Underwriting decision in 24–48 hours
  • $0 setup fee, dedicated MID
  • Specialist replies within 4 business hours
  • Every term disclosed in writing before you sign

Request a call from a specialist

Are you currently processing?

No obligation. A specialist replies within 4 business hours, Mon–Fri 9:00–18:00 EST.

What Is PCI DSS Compliance? A Plain-English Guide | Gray Merchants