PCI DSS compliance is the security standard every business handling credit card data must meet, and the four PCI compliance levels are defined by annual transaction volume, which determines how each business validates.
Any business that stores, processes, or transmits cardholder data must comply, with no exemption for small or low-volume merchants whose transaction count changes their level rather than whether the rules apply.
Levels 2 through 4 usually self-validate with the Self-Assessment Questionnaire that matches how they take payments, while Level 1 merchants need a Qualified Security Assessor to complete a Report on Compliance.
Compliance cost scales with your level and how much card data you handle, ranging from roughly $1,000 to $5,000 a year for the smallest merchants to $50,000 or more for a Level 1 enterprise.
If your organization handles credit card payments, complying with PCI DSS is non-negotiable. Yet according to Verizon’s 2024 Payment Security Report, only 14% of organizations maintain full PCI compliance.1 Many business leaders still struggle to understand what PCI means, how it applies to their operations, and what’s required to stay compliant.
At TailWind, we help distributed enterprises meet compliance efforts across every location with managed IT services, cybersecurity solutions, and expert field support. Check out this guide to start navigating PCI compliance with confidence.
PCI stands for Payment Card Industry – specifically, it refers to the Payment Card Industry Data Security Standard, or PCI DSS. These standards protect cardholder data during and after a transaction, and any organization that handles credit card information is required to adhere to them.
Complying with PCI DSS can help your business reduce the risk of threats like data breaches, fraud, and regulatory fines. Unfortunately, meeting the requirements isn’t always straightforward – especially for multi-location enterprises. That’s why TailWind helps clients align with compliance frameworks like PCI DSS by building security best practices into the networks we manage.
Any business that stores, processes, or transmits cardholder data has to comply with PCI DSS. That covers far more organizations than most people assume, and there is no size threshold that lets a business opt out.
Two broad groups fall under the standard:
Merchants: any business that accepts credit or debit card payments, whether online, in a store, over the phone, or by mail. A single-location restaurant and a 200-site retail chain are both merchants under PCI DSS.
Service Providers: businesses that store, process, or transmit cardholder data on behalf of others, or that can affect the security of a client's card data. Payment gateways, hosting providers, and managed IT firms often fall here.
The most common misconception is that small or low-volume businesses are exempt. They are not. Transaction volume changes your compliance level and how you validate, not whether the rules apply. A business processing a few thousand card payments a year still has to meet the standard, usually through a Self-Assessment Questionnaire rather than a full audit.
The rare cases that sit outside PCI DSS are organizations that never touch cardholder data at all, for example a company that has fully outsourced payments to a compliant provider and whose own systems never see card details. Even then, you are responsible for confirming that your provider is compliant and keeping their Attestation of Compliance on file.
PCI DSS defines how organizations must secure their networks, devices, and data when handling payment card information.
PCI DSS covers 12 core security requirements organized into six control objectives:
If your business processes credit card payments – online or in-store – you’re responsible for ensuring that your environment complies with these requirements.
The latest version, PCI DSS 4.0, introduced important updates that reflect the changing security landscape. These updates provide more flexibility while raising the bar on what security measures organizations should implement, including robust authentication and encryption standards and continuous security monitoring rather than point-in-time checks.
At TailWind, we stay current with PCI DSS 4.0 and other evolving standards, so we’re always ready to help our clients align with new requirements and avoid compliance gaps.
A PCI assessment is a formal evaluation that determines whether your business meets PCI DSS requirements. It typically includes:
The format and scope of your PCI assessment depend on which PCI compliance level you fall into – which we’ll explain next.
PCI compliance isn’t one-size-fits-all. The PCI DSS defines four compliance levels based on the number of transactions your business processes each year. Here’s a breakdown of these levels:
Who it applies to:
Requirements:
TailWind partners with Level 1 merchants to help manage the complex infrastructure, documentation, and security monitoring needed to meet this highest level of PCI compliance.
Who it applies to:
Requirements:
Level 2 still requires rigorous controls and formal documentation. If you’re unsure how to approach PCI assessment at this level, TailWind can help you streamline testing and remediation with proven IT practices.
Who it applies to:
Requirements:
E-commerce platforms are especially vulnerable to security threats, which is why Level 3 PCI compliance is focused on online transaction environments.
Who it applies to:
Requirements:
Even though Level 4 PCI compliance has the least stringent requirements, small businesses are not immune to security risks. TailWind works with SMBs and franchise locations to secure networks and simplify compliance without overburdening your internal teams.
The penalties for PCI DSS non-compliance vary from payment processor to payment processor, so it can be difficult to pin down exact fines. However, fines compound for each month a business fails to comply, and the per-month charge increases for longer periods.
For example, a business might pay $5,000 per month if it’s out of compliance for three months. But if they’re still non-compliant after seven months, they could pay $50,000 per month. In some cases, some processors have imposed fines ranging from $50 to $90 for each customer affected by a data breach.2
These aren’t “fines” in the same sense that you’d pay for violating a government regulation; they’re penalties built into the contract between merchants, payment processors, and credit card brands. So if your business is found to be non-compliant, the card brands could fine your payment processors, who then fine you as the merchant.
PCI compliance is a contractual requirement, not a federal law in the US. You agree to it through your contracts with acquiring banks, payment processors, and the card brands (Visa, Mastercard, American Express, Discover, and JCB). Those parties can fine you, raise your fees, or revoke your ability to accept cards if you fall out of compliance. Some state laws also reference PCI DSS, so the practical effect is the same as a legal obligation: if you accept card payments, you have to comply.
The PCI Security Standards Council writes and maintains the standard, but it does not enforce it. Enforcement runs through the card brands and your acquiring bank. If you are found non-compliant, the card brands can fine your acquirer, who then passes those penalties on to you as the merchant. Fines are set by contract rather than statute, which is why they vary from one processor to the next and can escalate the longer non-compliance continues.
You are PCI compliant once you have completed the validation your level requires and can prove it. For most businesses that means finishing the correct Self-Assessment Questionnaire, passing quarterly ASV scans, and filing an Attestation of Compliance. Level 1 merchants confirm compliance through a Qualified Security Assessor and a Report on Compliance instead. If you have never completed any of these steps, you are almost certainly not compliant yet, even if you have never had a breach. Your acquiring bank can confirm your current status.
PCI DSS is an ongoing obligation, not a one-time check. External vulnerability scans by an Approved Scanning Vendor are required quarterly, so four times a year, for any business with internet-facing systems in scope. Self-Assessment Questionnaires and, for Level 1 merchants, the QSA-led Report on Compliance are completed annually. Penetration testing is typically required at least once a year and after any significant change to your network. You also need continuous logging and monitoring in between these checkpoints.
In many cases, yes. Merchants at Levels 2 through 4 can usually validate on their own by completing the Self-Assessment Questionnaire that matches how they accept payments, running the required scans, and filing an Attestation of Compliance. You only need a Qualified Security Assessor if you are a Level 1 merchant, or in specific cases where your SAQ type calls for one. That said, many smaller businesses still bring in outside help for scoping and remediation, since those steps are where most compliance efforts stall.
No matter which of the PCI compliance levels you fall into, maintaining security isn’t a one-time event. Ongoing efforts should include:
TailWind helps multi-site businesses simplify these compliance needs with centralized security frameworks, proactive monitoring, and IT services built to scale. Whether you're navigating your first PCI assessment or aligning with new PCI DSS 4.0 requirements, our managed network and field services teams are here to keep your infrastructure secure and compliant.
Book a meeting with our team today to learn more about how we can support your PCI compliance goals with scalable network solutions and expert guidance.
Sources: