"PCI-DSS" stands for Payment Card Industry Data Security Standard. It is the security framework that anyone who accepts credit cards has to follow. For very large enterprises with their own card-data systems, PCI compliance is a major project. For a typical small merchant who runs cards through a terminal or a hosted online checkout, it is roughly twenty minutes of paperwork a year. Here is what that paperwork actually entails.
What level you are
PCI has four merchant levels based on transaction volume. Briefly:
- Level 1: more than 6 million card transactions per year, or any business that has had a major card breach. Full annual audit by a Qualified Security Assessor.
- Level 2: 1 to 6 million transactions per year. Self-assessment plus quarterly vulnerability scans if applicable.
- Level 3: 20,000 to 1 million eCommerce transactions per year.
- Level 4: under 20,000 eCommerce transactions, or up to 1 million across all channels. This is most small merchants.
The Self-Assessment Questionnaire (SAQ)
Level 4 merchants - and most Level 2 and 3 merchants - satisfy PCI by completing a once-a-year Self-Assessment Questionnaire. There are different SAQ versions depending on how you accept cards. The most common for small businesses are:
- SAQ A: you only take cards through a fully outsourced online checkout (Stripe, Shopify, a hosted payment page). About 20 yes/no questions.
- SAQ B: you only use standalone terminals or imprint machines, no internet or computer involved. About 40 questions.
- SAQ B-IP: you use IP-connected terminals (most modern ones). About 80 questions, still very tractable.
- SAQ C and D: more involved configurations, more questions. Most small merchants do not need these.
Your processor will tell you which SAQ applies. Most processors host the questionnaire inside their compliance portal so you log in, answer the questions, and submit. AdvoCharge guides every client through this - we will tell you which SAQ you need, what each question means in plain English, and how to answer it accurately.

Quarterly scans (only sometimes)
If you take card payments online and store, process, or transmit card data on your own server, you need quarterly Approved Scanning Vendor (ASV) scans of your network. If you use a hosted checkout where the card data never touches your server (the SAQ A case above), you do not need scans.
The "PCI Non-Compliance Fee" scam
Look at your monthly statement. If you see a line item that says "PCI non-compliance fee" or "PCI failure fee," that is almost certainly because you have not completed your annual questionnaire. The processor automatically starts charging you - often $20 to $40 per month - until you fill it out. The fee is real, the cost to remove it is zero.
This is one of the things we audit on every statement review. About one in three merchants we look at has been paying a non-compliance fee for months or years simply because nobody pointed it out.
Worth saying clearly: some processors charge a "PCI compliance fee" that is real (covers the portal and scans) and some charge it on top for pure profit. A fair processor includes basic compliance services in the rate; if you are paying a $99 annual "PCI fee" on top of your processing, ask what it actually covers.
What to actually do
- Find out which SAQ your processor wants you on. They will tell you.
- Log into the compliance portal (usually linked from your processor's online account) and complete the questionnaire. Honest answers - not what you think they want to hear.
- If applicable, schedule the quarterly scans.
- Save the completed Attestation of Compliance certificate. Some insurance carriers ask for it.
That is it. For most merchants, that is the entire compliance obligation for the year. AdvoCharge clients get a calendar reminder and a walkthrough at renewal time - it is part of the service, not an upsell. Read more about how we handle compliance on the Security & PCI-DSS page.