CO Compliance

July 20, 2026
BY PHILIP ROBB
7 MIN READ

All posts

PCI Compliance for a Small Lubbock Business

Your card processor sends a SAQ link and a monthly fee. Here is which self-assessment applies to a small shop and how to shrink the work.

Somewhere on your monthly processing statement there is a line item you have never asked about. It might say “PCI non-compliance fee.” It might say “PCI program fee.” It shows up every month, it is small enough to ignore, and it has been ignored for years.

That fee is your processor telling you that you never finished the questionnaire they emailed you. The email had a link, the link had a login, and the login asked whether your firewall configuration standards are reviewed at least once every twelve months. So you closed the tab.

We see this at retail counters and front desks all over Lubbock. Here is what the questionnaire is and how to make it smaller.

PCI is a contract, not a law

The Payment Card Industry Data Security Standard is written by the card brands, not by Congress and not by the Texas legislature. You agreed to it when you signed with your processor. Nobody from the state is going to audit you for it.

What happens instead is worse in a specific way. If card data leaks out of your shop, the brands assess the loss to your acquiring bank, and your acquirer passes it to you under the contract you signed. Forensic investigation, card reissue, fines. Attesting that you were compliant when you were not is the part that turns a bad month into a business-ending one. Texas breach notification law (Tex. Bus. & Com. Code §521.053) runs on its own track, separately from any of it.

Which questionnaire you fill out is the whole game

Almost every business in West Texas that takes cards is a Level 4 merchant, which means you self-assess. You pick a Self-Assessment Questionnaire, answer it, and sign an Attestation of Compliance. There are several versions and they differ wildly in length. Picking the right one is most of the job.

The short ones

SAQ P2PE is the shortest path there is. It applies if every card is read by a validated point-to-point encryption terminal, which encrypts the card inside the reader before anything on your network can see it. Your PC, your Wi-Fi, and your practice management or point-of-sale software never touch readable card data.

SAQ B-IP covers standalone approved terminals that connect over IP, with no card data stored electronically. Longer than P2PE, still manageable.

SAQ A applies when card acceptance is fully outsourced, which for most small shops means a hosted payment page or an iframe from your gateway. Card data never lands on your systems at all.

The long one

SAQ D is where you end up when card numbers pass through software running on your own machines. It runs to hundreds of questions covering encryption, logging, access control, patching, and vendor management. Most owners who open SAQ D never finish it, and that is exactly the population that clicks “compliant” anyway.

If you are on SAQ D and you do not have to be, the fix is not to answer faster. The fix is to change how the card is read.

Shrink the scope before you fill out the form

Scope reduction is the honest version of PCI work for a small business. Every system that can see card data is in scope, and every system in scope drags requirements behind it. Cut the number of systems that can see card data and the questionnaire shrinks with it.

In practice that means:

  • Move to validated P2PE or approved standalone terminals. This is the single biggest lever. It is hardware you pay for once against a questionnaire you answer every year.
  • Stop card data from touching general-purpose PCs. The front desk computer that also does email and web browsing should never be in the card path.
  • Segment the payment terminals off the main network. A separate VLAN keeps the guest Wi-Fi, the security cameras, and the back-office PCs out of scope.
  • Kill stored card numbers. A spreadsheet of card-on-file numbers or a folder of old paper authorization forms is in scope, and neither one needs to exist.
  • Write down who your service providers are. Processor, gateway, terminal vendor, and any managed IT provider that touches the environment. The questionnaire asks.

Some paths also require a quarterly external vulnerability scan from an Approved Scanning Vendor. Your acquirer can tell you whether yours is one. Ask before you buy a scan you do not need.

The part nobody puts on the form

The controls that carry the most weight are the ordinary ones. Unique logins per person instead of a shared counter account. Multi-factor authentication on remote access, and patching that happens on a schedule instead of when something breaks. That is the same network and security work any business needs whether or not it takes a card.

Payment compliance is usually just the reason an owner finally looks at it.

Where we come in

We walk the building, trace where card data goes, and tell you which questionnaire you should be on and what it would take to get onto a shorter one. Free walkthrough, written punch list. If your terminals are already fine and the fee is a paperwork problem, we will tell you that too.

The free Cyber Score is the quick version. About two minutes, a grade on what an attacker can see about your domain from outside, and a written report by email. The free IT Blueprint Assessment is the on-site version and covers the whole shop, the card path included. One bill, one number, one crew, for the network the terminals sit on and the office around it. Public number: (806) 370-4700.

01 Start here

Find out where you actually stand.

Like a credit score, but for your business's cybersecurity.

It is free and takes about two minutes. You get a grade and a written report by email.

Owner-operated in Lubbock · (806) 370-4700

Call Get Score