
“PCI compliance” sounds like an audit with auditors. For the overwhelming majority of businesses, it’s a questionnaire, a scan, and a handful of habits — and skipping it quietly costs you a monthly fee most merchants never notice they’re paying. Here it is in plain English.
What PCI DSS actually is
The Payment Card Industry Data Security Standard is a set of security requirements written by the card brands — not a government law. Every business that accepts cards agrees to it inside the merchant agreement. Nobody sends an inspector for a small merchant; instead, your processor asks you once a year to attest that you meet the requirements that apply to how you take payments.
Which questionnaire applies to you
- SAQ A — you sell online and payment pages are fully hosted by your provider. Shortest form by far.
- SAQ A-EP — your site controls the checkout page even though the card data goes straight to the processor. More questions, and your site is in scope.
- SAQ B / B-IP — you take payments through standalone terminals with no card data on your systems.
- SAQ C — a payment application on an internet-connected computer.
- SAQ D — everything else, including anyone who stores card numbers. The long one. Avoid landing here.
If you’re unsure which one you fall under, ask your provider before you fill anything out. Attesting to the wrong questionnaire is worse than attesting late.
Four habits that keep you compliant
- Don’t store what you don’t need. Never keep the CVV after authorization — not in a CRM note, not on an order form, not in a recorded call. Full card numbers on file should be replaced with tokens from your gateway.
- Tokenize repeat billing. For subscriptions and saved cards, the token lives with the processor and is useless if stolen. This is the single highest-value change most merchants can make.
- Keep the payment path narrow. The fewer systems that touch card data, the smaller your scope — and the shorter your questionnaire.
- Patch and control access. Current software, unique logins per person, multi-factor on anything remote, and no shared admin passwords.
The non-compliance fee nobody mentions
Fall out of compliance and most processors quietly add a monthly non-compliance charge — often alongside a “PCI program” fee you’re already paying. It rarely appears as a headline number; it lives in the same statement fine print as the other line items we broke down in high-risk merchant account fees. Completing the questionnaire usually takes under an hour. It is the cheapest fee you will ever eliminate.
Why high-risk merchants get looked at harder
If your industry already carries elevated risk, a breach on your systems is a much bigger liability for the sponsoring bank — so security posture becomes part of how your file is judged, both at underwriting and at every annual review afterward. Tokenized billing, a hosted checkout, and a clean questionnaire genuinely help you keep the account you fought to get.
Set up so compliance is the default
At Creditcard Payment Services, we set up card processing and gateways so card data never lands where it becomes your problem — hosted pages, tokenized recurring billing, and ACH and eCheck for the invoices where cards were never the right rail. Since 2009, for the industries other banks avoid.
Not sure which questionnaire you’re on — or paying a non-compliance fee right now? Apply online or call 1-800-475-6011. No cost, no obligation.
Ready to find out where you stand?
Most approvals come back in 2–3 business days — and there’s no cost to apply and no obligation.
Apply onlineor call 1-800-475-6011