What is PCI DSS?

PCI DSS is the Payment Card Industry Data Security Standard - the contractual security framework that any business storing, processing, or transmitting cardholder data must follow.

PCI DSS isn't a law - it's a set of security requirements imposed by Visa, Mastercard, American Express, Discover, and JCB on every merchant accepting their cards. Compliance is verified annually through a Self-Assessment Questionnaire (SAQ) for small merchants, or a full Report on Compliance (ROC) audit for larger ones.

Most Florida small merchants qualify for SAQ-A - the simplest tier - because they outsource card handling to a payment processor (Stripe, Square, PayPal) that's PCI-validated itself. SAQ-A is roughly 22 questions and can be completed in an afternoon.

Bigger operations that touch cardholder data directly need SAQ-D, which is hundreds of controls, or a ROC audit costing $8,000-$50,000+ depending on scope.

Why it matters for Florida small business

Florida retailers, restaurants, medical practices accepting cards, and any e-commerce business is on the hook. Your card processor will email you the questionnaire annually.

What to do

If you outsource card handling to Stripe / Square / PayPal you're almost certainly SAQ-A - fill it out as soon as you receive the prompt; ignoring it can result in higher transaction fees.

Related terms