Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsPCI DSS compliance means applying the payment-data security controls that fit your business and providing the evidence required by the organization that manages your compliance program. Your obligations depend on how payments flow, which systems can access or affect account data, what a provider does for you, and whether your acquirer or payment brand requires a Self-Assessment Questionnaire (SAQ), Report on Compliance (ROC), or another validation method.
What does PCI compliance mean for my business?
The Payment Card Industry Data Security Standard (PCI DSS) is a baseline of technical and operational requirements for organizations that store, process, or transmit payment account data, and for organizations that could affect the security of the cardholder data environment. Its intended audience includes merchants, payment processors, acquirers, issuers, and service providers.
In practical terms, compliance requires you to:
- identify payment flows, systems, people, and providers in scope;
- apply the controls relevant to that environment; and
- demonstrate compliance through the validation route accepted for your business.
The standard’s six control goals cover secure networks and systems, protection of account data, vulnerability management, access control, monitoring and testing, and supporting security policies and programs. PCI DSS v4.0.1 organizes these goals into 12 requirements.
PCI DSS is a continuing security program, not a one-time form. A completed questionnaire does not guarantee that a business cannot be breached or eliminate its ongoing duties.
#1 Best Overall
Does PCI DSS apply to small businesses?
Yes. PCI DSS applies regardless of a merchant’s size or transaction volume. A small or straightforward environment may involve fewer systems and controls, but being small does not itself create an exemption.
Payment brands and the acquirer or other organization managing your compliance program decide whether you must validate compliance and which reporting rules apply. Ask that organization what it requires for your merchant account; do not choose a form solely because your transaction volume is low.
If I use a payment processor, do I still need to be PCI compliant?
Yes. Outsourcing payment processing can reduce the controls that apply directly to your environment, but it does not transfer all responsibility. PCI SSC states: “However, this does not remove the merchant’s responsibility to ensure account data is properly protected by the third party.”
A merchant using a processor should:
- confirm that the provider is compliant for the services it supplies;
- keep a written agreement that acknowledges each party’s responsibilities;
- understand which controls the provider performs and which remain yours;
- monitor the provider’s compliance status at least annually; and
- validate your own compliance as required by the compliance-accepting entity.
Do not assume that outsourcing automatically makes you eligible for SAQ A. Eligibility depends on the exact payment flow and all questionnaire criteria.
Recommended Free Tools
Rank #2
How do payment flows change PCI DSS scope?
Your assessment starts with how customers’ payment data moves through your business. Common arrangements have different responsibility splits:
| Payment arrangement | What to examine | Why the route matters |
|---|---|---|
| In-house payment handling | Your applications, networks, terminals, databases, staff access, and security controls | More of the cardholder-data environment may be under your direct control. |
| Embedded processor page or form | Your website’s integration, scripts, hosting, change processes, and the processor’s responsibilities | SAQ eligibility is conditional, including a script-attack criterion for eligible embedded-page/form merchants. |
| Redirect to a processor website | The redirect implementation, links between your site and the provider, and provider assurance | The embedded-form script clarification does not apply in the same way to a redirect. |
| Fully outsourced payment | Your agreements, redirects or integrations, provider status, and responsibilities that remain with you | Outsourcing can narrow scope but does not remove merchant accountability. |
This comparison does not determine your assessment. The responsible acquirer, payment brand, or other compliance-accepting entity must confirm the applicable validation method.
Do I need an SAQ or a Report on Compliance?
There is no universal answer. Payment brands, acquirers, and other compliance-accepting entities determine which validation and reporting method they accept. Depending on the program and your environment, that may be an eligible SAQ, a ROC completed with an assessor, or another specified process.
Self-Assessment Questionnaire (SAQ)
An SAQ is available only for eligible scenarios and comes with eligibility criteria. Select the questionnaire only after mapping your payment flow and confirming acceptance with the organization receiving your validation. SAQ eligibility criteria should not be used as a substitute for an ROC assessment unless that organization has reviewed and agreed to the approach.
Free tools Windows power users keep installed
One-click scans. No signup required.
Report on Compliance (ROC)
A ROC is a formal assessment report generally prepared with a qualified assessor when the compliance program requires it. A Qualified Security Assessor (QSA) can help define scope, test controls, and document whether applicable requirements are accurately addressed.
How to confirm the correct route
- Document how payment data enters, moves through, and leaves your business.
- List systems, personnel, vendors, and connections that store, process, transmit, or could affect payment-data security.
- Obtain your processor’s current compliance evidence and responsibility information.
- Ask your acquirer, payment brand, or compliance-accepting entity which validation method and reporting date apply.
- Use a QSA or other qualified adviser when scope or shared responsibilities are unclear.
What changed with PCI DSS 4.0.1?
PCI SSC published PCI DSS v4.0.1 on 11 June 2024 as a limited revision following stakeholder feedback. It corrected formatting and typographical errors and clarified the focus and intent of some requirements and guidance. PCI SSC said it added no requirements and deleted none.
PCI DSS v4.0 was retired on 31 December 2024. As of that date, v4.0.1 was the only active PCI SSC-supported version. The revision did not change the 31 March 2025 effective date for future-dated requirements. PCI SSC’s release announcement answered the timing question directly: “No. This limited revision does not impact the effective date of these new requirements.”
How should businesses report the post-2025 requirements?
Because 31 March 2025 has passed, reports use the successor requirements. PCI SSC says the superseded requirements should be reported as Not Applicable in an ROC or SAQ:
Rank #4
| Superseded requirement | Successor requirement | Reporting treatment after 31 March 2025 |
|---|---|---|
| 6.4.1 | 6.4.2 | Report 6.4.1 as Not Applicable; assess 6.4.2. |
| 8.3.10 | 8.3.10.1 | Report 8.3.10 as Not Applicable; assess 8.3.10.1. |
| 10.7.1 | 10.7.2 | Report 10.7.1 as Not Applicable; assess 10.7.2. |
This is a reporting treatment for superseded identifiers, not a removal of the underlying security topics.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What is the SAQ A e-commerce clarification?
For eligible e-commerce merchants using a processor’s embedded payment page or form, revised SAQ A eligibility requires confirmation that the merchant site is not susceptible to script attacks that could affect its e-commerce systems.
The clarification is specific to the embedded-page/form scenario. It does not apply in the same way to merchants that redirect customers to a processor website or fully outsource payment by sending customers to the processor’s site. All other SAQ A eligibility criteria still apply, and the recipient of your validation must confirm that SAQ A is appropriate.
PCI SSC’s January 2025 announcement removed requirements 6.4.3 and 11.6.1 from SAQ A and added the script-attack eligibility criterion. That reporting change did not remove or diminish those underlying PCI DSS requirements.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Who determines and supports compliance?
PCI Security Standards Council
PCI SSC publishes PCI DSS, supporting guidance, and questionnaires. It does not decide the reporting route for every merchant.
Acquirer, payment brand, or compliance-accepting entity
This organization sets the validation method, reporting format, and timing it will accept for your business or service.
Qualified Security Assessor
A QSA is an independent organization trained to perform PCI DSS assessments. An assessor can help establish scope and verify that applicable requirements are accurately defined and documented. A QSA is not automatically mandatory for every merchant.
Merchant and service provider
Both parties must document shared responsibilities, maintain their assigned controls, and keep evidence that supports the required validation.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Frequently Asked Questions
Does using a hosted payment page make a business exempt from PCI DSS?
No. Hosting or outsourcing may reduce the systems in your direct scope, but the merchant still has responsibilities for provider oversight, agreements, shared controls, and any validation required by its compliance program.
Can I choose an SAQ based only on my transaction volume?
No. Transaction volume may affect a payment brand’s validation rules, but SAQ eligibility depends on the complete payment arrangement and questionnaire criteria. Confirm the form with your acquirer, payment brand, or other compliance-accepting entity.
Is PCI DSS v4.0 still current?
No. PCI DSS v4.0 was retired on 31 December 2024. PCI DSS v4.0.1 is the active PCI SSC-supported version described here.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




