PCI Compliance for a Small Lubbock Business
Your card processor sends a SAQ link and a monthly fee. Here is which self-assessment applies to a small shop and how to shrink the work.
Your card processor sends a SAQ link and a monthly fee. Here is which self-assessment applies to a small shop and how to shrink the work.
Somewhere on your monthly processing statement there is a line item you have never asked about. It might say “PCI non-compliance fee.” It might say “PCI program fee.” It shows up every month, it is small enough to ignore, and it has been ignored for years.
That fee is your processor telling you that you never finished the questionnaire they emailed you. The email had a link, the link had a login, and the login asked whether your firewall configuration standards are reviewed at least once every twelve months. So you closed the tab.
We see this at retail counters and front desks all over Lubbock. Here is what the questionnaire is and how to make it smaller.
The Payment Card Industry Data Security Standard is written by the card brands, not by Congress and not by the Texas legislature. You agreed to it when you signed with your processor. Nobody from the state is going to audit you for it.
What happens instead is worse in a specific way. If card data leaks out of your shop, the brands assess the loss to your acquiring bank, and your acquirer passes it to you under the contract you signed. Forensic investigation, card reissue, fines. Attesting that you were compliant when you were not is the part that turns a bad month into a business-ending one. Texas breach notification law (Tex. Bus. & Com. Code §521.053) runs on its own track, separately from any of it.
Almost every business in West Texas that takes cards is a Level 4 merchant, which means you self-assess. You pick a Self-Assessment Questionnaire, answer it, and sign an Attestation of Compliance. There are several versions and they differ wildly in length. Picking the right one is most of the job.
SAQ P2PE is the shortest path there is. It applies if every card is read by a validated point-to-point encryption terminal, which encrypts the card inside the reader before anything on your network can see it. Your PC, your Wi-Fi, and your practice management or point-of-sale software never touch readable card data.
SAQ B-IP covers standalone approved terminals that connect over IP, with no card data stored electronically. Longer than P2PE, still manageable.
SAQ A applies when card acceptance is fully outsourced, which for most small shops means a hosted payment page or an iframe from your gateway. Card data never lands on your systems at all.
SAQ D is where you end up when card numbers pass through software running on your own machines. It runs to hundreds of questions covering encryption, logging, access control, patching, and vendor management. Most owners who open SAQ D never finish it, and that is exactly the population that clicks “compliant” anyway.
If you are on SAQ D and you do not have to be, the fix is not to answer faster. The fix is to change how the card is read.
Scope reduction is the honest version of PCI work for a small business. Every system that can see card data is in scope, and every system in scope drags requirements behind it. Cut the number of systems that can see card data and the questionnaire shrinks with it.
In practice that means:
Some paths also require a quarterly external vulnerability scan from an Approved Scanning Vendor. Your acquirer can tell you whether yours is one. Ask before you buy a scan you do not need.
The controls that carry the most weight are the ordinary ones. Unique logins per person instead of a shared counter account. Multi-factor authentication on remote access, and patching that happens on a schedule instead of when something breaks. That is the same network and security work any business needs whether or not it takes a card.
Payment compliance is usually just the reason an owner finally looks at it.
We walk the building, trace where card data goes, and tell you which questionnaire you should be on and what it would take to get onto a shorter one. Free walkthrough, written punch list. If your terminals are already fine and the fee is a paperwork problem, we will tell you that too.
The free Cyber Score is the quick version. About two minutes, a grade on what an attacker can see about your domain from outside, and a written report by email. The free IT Blueprint Assessment is the on-site version and covers the whole shop, the card path included. One bill, one number, one crew, for the network the terminals sit on and the office around it. Public number: (806) 370-4700.
Like a credit score, but for your business's cybersecurity.
It is free and takes about two minutes. You get a grade and a written report by email.
Owner-operated in Lubbock · (806) 370-4700