Partly. A card processor or payment provider has its own side of a card transaction to protect, and that side matters. But the PCI Security Standards Council’s FAQ says the standard applies to merchants of any size, and that outsourcing payments doesn’t remove the merchant’s responsibility to make sure account data is properly protected. So PCI compliance for a small business still has a part that belongs to the business, and the business is the one asked to validate it.
Here’s why that distinction matters. Because the business stays responsible for making sure card data is protected even when a provider handles the payments, a wrong assumption about what the provider covers can surface later as an inaccurate compliance questionnaire, a gap in the provider’s agreement, or card details sitting where nobody is protecting them.
PCI DSS is the card industry’s data security standard for businesses that take card payments. An acquirer is the merchant bank behind a business’s card payments, and it’s one of the parties the Council’s FAQ points merchants toward when they need to know what to validate.
Does PCI DSS apply to a business this small?
Yes. The PCI Security Standards Council’s FAQ for small merchants says PCI DSS is intended for all entities involved in payment processing, including merchants, regardless of their size or transaction volume. A business that rarely runs a card still sits inside that scope. Size can change the effort involved, but not whether the standard applies.
The same FAQ offers some relief, though. Compared with larger merchants, it says, small merchants often have simpler environments, with limited amounts of cardholder data and fewer systems that need protecting, which can help reduce their compliance effort. That’s a fair expectation to carry into the conversation. It isn’t a ruling on your particular setup.
Who decides what you have to prove?
Not your IT provider, and not your bookkeeper. The Council’s FAQ says whether a small merchant is required to validate compliance is determined by the individual payment brands (the card companies behind the cards you accept), and it tells merchants with questions about validation and reporting to contact their acquirer or the payment brand they do business with. That’s the door to knock on. Everything else is preparation for that answer.
Why small can mean simpler
Fewer systems can mean fewer places card data lands. If card details never sit on an office computer, on paper, or in an inbox, there’s less to describe and less to protect. That’s the Council’s point about simpler environments, applied to your own floor plan. Your acquirer or payment brand still decides what you have to show, so treat the simplicity as a head start and not as a conclusion.
What does a payment provider cover, and what stays with you?
As a general rule, a provider is responsible for its own systems and the services it sells. The Council’s FAQ on outsourced payment processing says the standard applies whether these activities are conducted directly or by a third-party provider, and that outsourcing doesn’t remove the merchant’s responsibility to make sure account data is properly protected by that third party.
That answer brings some relief. The same FAQ says that when a merchant outsources its payment processing and doesn’t store, process or transmit cardholder data, many PCI DSS requirements may not apply directly to the merchant’s environment. Less of the standard pointing at your office is a meaningful difference. It just isn’t the same as nothing.
What stays with the business
The Council’s FAQ names what the merchant keeps when payment processing is outsourced:
- Ensuring the provider is PCI DSS compliant for the services offered.
- Keeping written agreements with the provider that acknowledge its responsibilities.
- Monitoring the provider’s compliance status at least annually.
- Clearly defining and understanding any shared responsibilities.
That list is oversight work. It needs an owner and a place to keep the answers. That’s the shape of PCI compliance for a small business that outsources payments, as the Council’s FAQ lays out the merchant’s duties: the provider does the processing, and the business keeps the oversight.
Validation doesn’t disappear either. The Council’s FAQ says merchants are still required to validate PCI DSS compliance, typically through a self-assessment questionnaire such as SAQ A. A self-assessment questionnaire is a form in which the business describes how it protects card data. If nobody can answer the questions on the form, that’s the first gap to close.
How does your business take card payments?
Start by writing down every route a card payment takes into the business, as it works in practice rather than as you remember setting it up. That list is what your acquirer and your payment provider may ask about, and as a general rule it can change how much of the standard points at your own equipment.
Routes worth looking for include:
- A terminal at the front counter.
- A card reader paired with a phone or tablet.
- A point-of-sale system sitting on the office network.
- Card details read over the phone and typed into a screen.
- A payment page on the website.
- Card details saved on paper, in a spreadsheet or in an old message.
Then ask your payment provider and your IT provider which devices and which user accounts touch card data. Those can be two separate questions with two separate owners, and the answers may surprise whoever set the system up.
Why bother with the list at all? As a general rule, how a business takes cards can change which self-assessment questionnaire its acquirer asks for and how much of the standard applies directly to the business. Which questionnaire fits which setup is a question for your acquirer or payment brand, so put it to them rather than guessing from the equipment you own.
Where that equipment sits on the office network is a separate question, and our post on splitting an office network into separate zones covers the card reader and phone system side of it.
What should you ask your acquirer or processor?
Ask short, specific questions, and get the answers in writing. The goal is to establish who owns which part of card-payment security and what the business has to show for it. A single email or call can cover it, and the answers belong somewhere a successor can find them.
Questions to send:
- Who is our acquirer?
- What do you need us to validate, and how?
- Which self-assessment questionnaire applies to the way we take payments?
- Is our payment provider PCI DSS compliant for the services we use, and how can we confirm that?
- If a line on our statement mentions PCI, what does it cover, and does it leave anything for us to complete?
Keep the reply itself, not a summary of it. If what you’re told conflicts with the agreement you signed, that’s a question for a lawyer.
These questions are payment-specific on purpose. For the wider set, our post on security questions to ask before adding a vendor covers where a vendor’s data lives and what happens to access when a contract ends.
Where your IT provider fits, and where to write it down
Draw the line at the equipment. As a general rule, the point-of-sale computer, the network it sits on, the user accounts and the staff who can reach them are the business’s to look after, together with whoever supports its technology. A terminal or reader may belong to the business or may come from the provider, so ask which. The provider is responsible for its own systems and the service it sells. Both halves need an owner, and the business is the one that has to know where the line falls.
O&O Systems’ cybersecurity and compliance services page says its team helps businesses whose industry requires standards such as PCI and keeps their systems documented and audit-ready. That describes what the page offers. No provider can promise a business is compliant, and what you have to validate comes from your acquirer or payment brand.
O&O Systems’ IT asset management service establishes a clear record of every IT asset, from hardware to software. Whoever keeps your business’s record should add the card-payment devices, the payment provider and the acquirer’s name to it.
Keep that record somewhere the next person can find it. Worth writing down:
- Who your acquirer is.
- Who your payment provider is.
- Who answers the compliance questionnaire.
- How the business takes card payments.
- Which devices and accounts touch card data.
- When the provider’s compliance status was last confirmed.
- Who to call.
Then update it when someone leaves, when you add a way to take payments, or when you change providers. A record nobody maintains is the one that misleads the next person who needs it.
Frequently Asked Questions About PCI and Your Processor
Do we need to think about PCI compliance if we only take a few card payments?
Yes. The PCI Security Standards Council’s FAQ says PCI DSS is intended for all entities involved in payment processing, including merchants, regardless of their size or transaction volume. A low payment volume doesn’t move a business outside the standard. What it can change is how much work validating takes, since there may be fewer systems and less card data to describe.
What is a self-assessment questionnaire?
It’s a form in which a business describes how it protects card data. The Council’s FAQ says merchants are still required to validate compliance, typically through a self-assessment questionnaire such as SAQ A. Which one applies to a given business comes from its acquirer or payment brand, so ask before filling anything in.
Does a PCI line on our processor statement mean we’re compliant?
Not on its own. A line item on a statement is a billing entry, and on its own it may not tell you what the business has validated or what’s still open. If you see one, ask your processor in writing what it covers and whether anything is left for the business to complete. The written answer is the thing to keep.
How often should we check that our payment provider is still compliant?
The Council’s FAQ puts monitoring the provider’s compliance status at least annually among the merchant’s responsibilities when payment processing is outsourced. Pick a date you’ll remember, ask the provider for current confirmation and note when you received it. If the provider changes or a service changes, it’s worth checking again rather than waiting for the annual date.
What happens to the PCI paperwork when the person who set up payments leaves?
It becomes someone else’s job the moment they go, whether or not anybody says so out loud. Name the successor, hand over the acquirer and provider contacts, and show them where the questionnaire and the written answers live. If nothing was written down, rebuild the record by asking the acquirer what it expects the business to validate.
Can an IT provider make our business PCI compliant?
No, and no provider can promise compliance. An IT provider can help with the devices, the user accounts and the network around a card reader, and can help keep a record of what the business has. What the business must validate, and how, comes from its acquirer or payment brand. That answer isn’t something a technology vendor can supply for you.
Start with how the cards reach you
A good first step in PCI compliance for a small business is knowing which part is yours and who decides the rest. Build the list of payment routes, send your questions to your acquirer, and keep the answers where the next person can find them.
If the device and account side of that picture needs another set of eyes, contact O&O Systems about how your business takes card payments.