Map and assess
An engineer maps where card data flows and reviews your terminals, POS, router, WiFi and back-office computers. The business assessment is a $200 flat fee, credited toward the project if you proceed.
If your Utah store or restaurant takes cards, PCI DSS, the card industry's security standard, applies to you. This guide covers what the standard is, how small merchants prove compliance, and what to check on your network, point of sale (POS) system and card terminals.
What you must submit depends on the card brands and your payment processor, so confirm the details with your processor.
PCI DSS is the Payment Card Industry Data Security Standard: security requirements for any business that stores, processes or transmits payment card data. The PCI Security Standards Council (PCI SSC) maintains it.
The Council does not enforce it. The card brands (Visa, Mastercard, American Express, Discover and JCB) and acquirers, the banks that process your card payments, decide who must prove compliance and how. In practice, your acquirer, or the payment processor working for it, tells you what to submit and when.
The current version is PCI DSS v4.0.1, published in June 2024. It replaced v4.0, which was retired on December 31, 2024, and it added or removed no requirements. The new v4.0 requirements with a delayed start became mandatory on March 31, 2025, so they all apply now. Check pcisecuritystandards.org for updates.
PCI SSC says PCI DSS is intended for all entities involved in payment processing, including merchants, regardless of size or transaction volume. Whether a small merchant must submit proof of compliance is decided by the card brands.
The card brands assign merchant levels, mostly by annual transaction volume. Visa merged its Levels 3 and 4 on April 25, 2024, so Visa Level 3 now covers merchants processing up to 1 million Visa transactions a year. Mastercard still has its own Level 4, so one business can hold different levels with different brands. Your acquirer tells you your levels and what to submit for each.
PCI SSC describes the Self-Assessment Questionnaire (SAQ) as the tool eligible merchants use to report the results of a self-assessment. The SAQ comes with an Attestation of Compliance (AOC) that you sign. Your acquirer decides whether an SAQ is enough or an outside assessor's report is required.
Which SAQ applies depends on how you take payments:
Confirm that you meet every eligibility condition of your SAQ, and ask your processor which one they expect. Choosing a shorter SAQ than your setup allows gives a wrong answer.
PCI DSS groups its controls into 12 principal requirements:
This checklist assumes one location that takes cards in person, with a POS, terminals, a router and a back-office computer. Requirement numbers refer to PCI DSS v4.x, and your SAQ decides which items you must document.
PCI SSC publishes a small merchant guide, Questions to Ask Your Vendors. Start with these:
WITS supports Utah retail stores and restaurants with network design, segmentation, patching, monitoring and documentation. PCI DSS work sits within our IT compliance services and managed cybersecurity. Our engineers hold Cisco CCIE Enterprise Infrastructure and Kali Linux Professional (KLCP) certifications. These are networking and security credentials, not PCI credentials.
Using WITS does not make your business compliant, and WITS does not replace your acquirer's validation. You complete and submit your own SAQ. We design the network separation and run the patching and monitoring that several checklist items depend on, and we support your documentation.
An engineer maps where card data flows and reviews your terminals, POS, router, WiFi and back-office computers. The business assessment is a $200 flat fee, credited toward the project if you proceed.
We build separate networks for the POS, staff and guests, set firewall rules, remove default credentials, add multi-factor authentication for remote access and set a patching schedule.
On managed plans, WITS monitors and patches your systems and supports your documentation of the network. WITS Command is $85 per user per month. WITS Inner Circle is $125 per user per month and adds annual penetration testing, security awareness training, an incident response plan and quarterly compliance review, with support for PCI DSS. Both are month-to-month with a 5 user minimum.
Short answers for store and restaurant owners
Yes. Being small does not exempt you. Ask your processor for your merchant level, which SAQ to use and when to submit it.
Standalone PCI-approved terminals connected to no other system fit SAQ B-IP. Validated P2PE terminals fit SAQ P2PE. An isolated, internet-connected POS at a single location fits SAQ C. Other setups can fit SAQ SPoC, B, C-VT or A, and if none of them fits, SAQ D applies. Confirm with your processor.
Requirements that had been best practices until that date became mandatory, including multi-factor authentication for all access to the card data environment (8.4.2) and 12 character passwords where supported (8.3.6). Every assessment now includes them.
Yes, if guest WiFi runs on a separate network with no route to the POS or terminals. Without segmentation your whole network is in scope, and a firewall is required between wireless networks and your card systems.
No provider can do that for you. WITS can design the network separation and run the patching and monitoring your SAQ answers depend on, and support your documentation. You remain responsible for compliance. Call 385-242-2514 to book an on-site assessment.
Have another question? We're here to help.
Contact UsThis is general information, not legal advice or a compliance assessment. You stay responsible for your own compliance and for what you submit to your processor, whether or not you use an IT provider. Requirements change, so read the current standard and confirm your level and SAQ with your acquirer.
Sources: PCI SSC document library, PCI SSC self-assessment questionnaires, PCI DSS v4.0.1 announcement, PCI SSC resources for merchants, PCI SSC SPoC standard, Visa What To Do If Compromised guide, merchant levels table, Mastercard Site Data Protection program.
Help turning PCI DSS requirements into controls and evidence.
IT for stores, from point-of-sale to network security.
IT for restaurants, with payment systems kept separate from guest WiFi.
Let's discuss how we can support your business with reliable managed IT services.
