ONE PARTNER FOR PAYMENTS, TERMINALS & FUNDING · US-BASED SUPPORT · NO HIDDEN FEESCALL (888) 255-0425

PCI Compliance for Small Business: Step-by-Step

In this article

ProTech Payments

BEST PRICE GUARANTEE

We'll beat your current rate.

Send one recent statement. We read it line by line, beat your effective rate where we can, or tell you honestly to stay. Free, no obligation.

Get My Free Rate Review

✓ Free analysis✓ No obligation✓ 48-hour turnaround

PCI compliance is the set of security controls every business that accepts Visa, Mastercard, American Express, or Discover must follow to protect cardholder data. The rules come from the Payment Card Industry Data Security Standard (PCI DSS), a framework maintained by the major card brands through the PCI Security Standards Council. A coffee shop in Katy running a Clover terminal and a roofing company in Houston taking deposits through a payment gateway are both bound by the same standard, even though their risk profile and paperwork differ.

ProTech Payments works with merchants across Katy, Houston, Sugar Land, Cypress, and Fort Bend County to get and stay PCI compliant without paying for controls they do not need. Most small businesses qualify for a short self-assessment, not a full on-site audit, and the right processing setup can shrink the scope of that assessment to a handful of questions. Getting this wrong is expensive: monthly non-compliance fees of $20 to $50 are common, and a single breach can trigger fines, forensic investigation costs, and card reissuance charges that run into tens of thousands of dollars.

This guide walks through what PCI DSS requires, which self-assessment questionnaire applies to your business, the exact steps to reach compliance, and the local Texas considerations that affect Houston-area merchants. Pair it with our free statement analysis to see whether your current processor is charging you compliance fees you can eliminate.

What PCI compliance actually means

PCI DSS is a contractual obligation, not a federal law. When you sign a merchant agreement, you agree to follow the standard as a condition of accepting card payments. Visa and Mastercard enforce it through acquiring banks and processors like Fiserv (the company formed when First Data merged with Fiserv), which pass the requirements down to you.

The data you are protecting

The standard protects two things. Cardholder data is the primary account number (PAN), cardholder name, expiration date, and service code. Sensitive authentication data is the full magnetic stripe, the CVV/CVC code, and the PIN. The hard rule: you may never store sensitive authentication data after a transaction is authorized, even encrypted. Storing a customer’s CVV in a spreadsheet or a CRM note is one of the fastest ways to fail an assessment and create liability.

Why scope is everything

Your PCI scope is every system that stores, processes, or transmits cardholder data, plus anything connected to those systems. A countertop terminal that uses point-to-point encryption (P2PE) keeps card data out of your network entirely, which collapses your scope. A homegrown checkout page that touches raw card numbers expands it. Reducing scope is the single most effective way to lower both your compliance burden and your breach risk, which is why the equipment and gateway you choose matter as much as the paperwork.

How PCI DSS works: the 12 requirements

PCI DSS v4.0 organizes its controls into six goals and 12 core requirements. You do not need to memorize them, but you should recognize what each one asks of a small merchant.

Requirement What it asks for Typical small-business action
1. Firewalls Protect the network perimeter Use a business firewall/router, not the ISP default
2. No vendor defaults Change default passwords Replace router and POS admin passwords
3. Protect stored data Limit and encrypt stored PAN Stop storing card numbers; use a tokenizing processor
4. Encrypt transmission Secure data in transit Use TLS 1.2+ and EMV/contactless
5. Anti-malware Defend against malware Run updated antivirus on POS computers
6. Secure systems Patch software Keep POS firmware and plugins current
7. Restrict access Need-to-know access Give staff individual, role-limited logins
8. Identify users Unique IDs, MFA One login per person; MFA on admin access
9. Physical security Lock down hardware Secure terminals, inspect for skimmers
10. Log and monitor Track access Keep audit logs where applicable
11. Test security Scan and test Quarterly ASV scans if you have a website
12. Security policy Maintain a policy Write and follow a basic security policy

EMV, contactless, and liability

EMV chip cards and contactless (NFC) payments are not PCI requirements by themselves, but they are central to your security posture. Since the 2015 EMV liability shift, a merchant who accepts a counterfeit card on a non-EMV terminal can be held liable for the fraud. Modern terminals that support EMV and contactless reduce both fraud exposure and the data your environment touches. Our guides on what EMV is and contactless payments explain how these technologies cut risk at the point of sale.

Merchant levels and the right SAQ

Card brands sort merchants into four levels by annual transaction volume. The level determines whether you self-assess or face a formal audit.

Level Annual Visa/MC transactions Validation
Level 1 Over 6 million On-site audit by a QSA, annual ROC
Level 2 1 million to 6 million Annual SAQ, sometimes on-site
Level 3 20,000 to 1 million e-commerce Annual SAQ
Level 4 Under 20,000 e-commerce, or under 1 million total Annual SAQ

Which SAQ applies to you

Nearly every Katy or Houston small business is a Level 4 merchant that completes a Self-Assessment Questionnaire (SAQ). The version you use depends on how you accept payments:

  • SAQ A: e-commerce or mail/phone order where all card handling is outsourced to a PCI-compliant provider (a hosted payment gateway or iframe). Shortest questionnaire.
  • SAQ A-EP: e-commerce where your site affects the payment but does not store data directly.
  • SAQ B: dial-out or standalone terminals with no electronic card storage.
  • SAQ B-IP: standalone IP-connected terminals with P2PE.
  • SAQ C: payment application connected to the internet.
  • SAQ P2PE: validated P2PE hardware terminals, the shortest of the in-person questionnaires.

Choosing a setup that qualifies for SAQ A or SAQ P2PE can cut your questionnaire from over 300 questions to roughly 20. This is why our in-store payments and online payments setups default to tokenized, hosted, or P2PE handling wherever possible.

What PCI compliance costs

Compliance has two cost categories: what you pay your processor, and what you spend on controls.

Processor fees

Many processors charge a PCI compliance fee of $99 to $199 per year, plus a non-compliance fee of $20 to $50 per month if you never complete your SAQ. Some bury both in a statement. A free statement analysis often surfaces these line items, and ProTech routinely removes non-compliance penalties by walking merchants through their SAQ at no extra charge.

Direct costs

Direct costs scale with scope. A single-terminal restaurant on a P2PE device may spend nothing beyond time. A business with an e-commerce site needs quarterly Approved Scanning Vendor (ASV) scans, typically $100 to $300 per year. The expensive scenario is non-compliance after a breach: forensic investigation, $5,000 to $50,000-plus in fines passed through the acquirer, mandatory card reissuance costs, and potential loss of card acceptance. Maintaining compliance is the cheapest line item in that comparison. Our PCI compliance service bundles the SAQ help, scanning when required, and breach-protection guidance so the cost stays predictable.

Step-by-step path to compliance

Here is the sequence ProTech uses with new Houston-area merchants.

Step 1: Define your environment

List every way you take cards: terminals, mobile readers, e-commerce, virtual terminal, invoices, and recurring billing. Each channel touches PCI scope. If you take card-not-present payments over the phone, our guidance on the virtual terminal explains how to keep that channel inside SAQ-friendly limits.

Step 2: Reduce scope before you assess

Switch any setup that stores raw card data to a tokenizing processor or a hosted gateway. Move standalone terminals to P2PE-validated hardware. Stop using shared logins. Every step here moves you toward SAQ A or SAQ P2PE and removes questions you would otherwise have to answer.

Step 3: Identify your SAQ and complete it

Confirm your merchant level (almost always Level 4) and select the matching SAQ. Work through it honestly. The questionnaire is your record that the controls exist.

Step 4: Run an ASV scan if required

If you have a website that touches payment data (SAQ A-EP, C, or D), schedule quarterly external vulnerability scans through an Approved Scanning Vendor and remediate any failures.

Step 5: Attest and submit

Sign the Attestation of Compliance (AOC) and submit the SAQ and AOC to your acquirer or processor portal. This is what stops the monthly non-compliance fee.

Step 6: Maintain it year-round

PCI is continuous, not annual. Patch your point-of-sale software, rotate staff logins when people leave, inspect terminals for skimmers, and re-validate every 12 months. Picking the right hardware up front, covered in our best POS system for small business guide, makes ongoing maintenance far simpler.

Common mistakes that break compliance

Storing card data you should never keep

Writing down a CVV, saving full card numbers in a CRM, or emailing card details to take a payment later all violate the standard. Use a virtual terminal or tokenized recurring billing instead so the card data never lands in your files.

Treating the SAQ as a one-time task

Completing the questionnaire once does not keep you compliant. Validation lapses after 12 months, and an unpatched POS or a shared admin password can put you out of compliance the day after you submit.

Using consumer apps for business payments

Routing customer cards through a personal payment app or an unverified plugin pushes liability onto you and can break SAQ A eligibility. Stick to a merchant account and a vetted gateway, as outlined in our guide to choosing a payment processor for small business.

Ignoring chargeback and breach exposure

PCI compliance reduces breach risk but does not eliminate disputes. Pair it with chargeback management so a fraud event does not turn into both a security incident and a string of lost disputes.

PCI compliance for Houston-area businesses

Texas has no state-level PCI mandate, so the card-brand standard governs every merchant from Katy to Pearland. What changes locally is the payment model many Texas businesses now run.

Dual pricing and surcharging

Texas allows credit card surcharging and dual pricing within the limits set by Visa and Mastercard. Whether you run a dual pricing program or a cash discount program, the underlying card transactions are still in PCI scope. The program changes who pays the processing fee, not your security obligations. Compliant terminals and tokenization apply exactly as they would under standard pricing.

Local support that owns the SAQ with you

ProTech Payments is based in Katy and supports merchants across Houston, Sugar Land, and the surrounding Fort Bend communities. Restaurants, retail shops, auto repair garages, and medical offices each have different scope profiles, and our industry-specific setups for restaurant merchant services and retail merchant services are configured to keep merchants in the shortest applicable SAQ from day one.

Frequently asked questions

Is PCI compliance legally required in Texas?

PCI DSS is not a Texas or federal law. It is a contractual requirement in your merchant agreement, enforced by Visa, Mastercard, and your processor. Failing to comply does not bring a government fine, but it can bring processor penalties, breach liability, and loss of card acceptance.

How much does PCI compliance cost a small business?

Most small merchants pay a processor PCI fee of $99 to $199 per year, and businesses with a website add roughly $100 to $300 for quarterly ASV scans. If your processor charges a non-compliance fee of $20 to $50 monthly, completing your SAQ removes it. ProTech can review these line items in a free statement analysis.

Which SAQ does my business need?

It depends on how you accept cards. Fully outsourced e-commerce typically uses SAQ A, standalone terminals use SAQ B or B-IP, and validated P2PE hardware uses SAQ P2PE. Choosing a tokenized or hosted setup keeps you on the shortest questionnaire.

What happens if I never complete my SAQ?

Your processor will usually charge a recurring non-compliance fee and you remain fully liable in a breach. Completing and submitting the SAQ plus the Attestation of Compliance stops the fee and documents your controls. Validation must be renewed every 12 months.

Does using a Clover or other modern POS make me compliant automatically?

No. A PCI-validated POS like Clover reduces your scope because it handles encryption and tokenization, but you still must complete your SAQ, change default passwords, secure staff logins, and physically protect the hardware. The device helps; it does not replace your attestation.

Can I store a customer’s card to charge them later?

Not the raw card data, and never the CVV. Use tokenization through a virtual terminal or recurring billing so your processor stores a secure token instead of the actual number. This keeps your environment out of scope for storing cardholder data.

Talk to ProTech Payments

PCI compliance gets simpler when your processing is built for it. ProTech Payments sets up Katy and Houston merchants with terminals, gateways, and SAQ guidance that keep scope small and fees predictable. Start with a free statement analysis to find and remove any compliance or non-compliance fees your current processor is charging, then get started with a setup that keeps you compliant year-round. Questions first? Contact our team and we will map your exact SAQ in one call.

SHARE THIS ARTICLE

CONTINUE READING

More for you

Happy waiter giving coffee to a couple while serving them in an outdoor cafe.

Restaurant Credit Card Processing Guide

Restaurant credit card processing is the set of hardware, software, and merchant account services that let a restaurant accept Visa, Mastercard, America…

Form Application Information Data Word

What Is a Chargeback? A Merchant’s Guide

A chargeback is a forced reversal of a card transaction, initiated by the cardholder’s bank and pushed back through the card networks (Visa, Mastercard,…