What is PCI DSS?
PCI DSS is the Payment Card Industry Data Security Standard - the contractual security framework that any business storing, processing, or transmitting cardholder data must follow.
PCI DSS isn't a law - it's a set of security requirements imposed by Visa, Mastercard, American Express, Discover, and JCB on every merchant accepting their cards. Compliance is verified annually through a Self-Assessment Questionnaire (SAQ) for small merchants, or a full Report on Compliance (ROC) audit for larger ones.
Most Florida small merchants qualify for SAQ-A - the simplest tier - because they outsource card handling to a payment processor (Stripe, Square, PayPal) that's PCI-validated itself. SAQ-A is roughly 22 questions and can be completed in an afternoon.
Bigger operations that touch cardholder data directly need SAQ-D, which is hundreds of controls, or a ROC audit costing $8,000-$50,000+ depending on scope.
Why it matters for Florida small business
Florida retailers, restaurants, medical practices accepting cards, and any e-commerce business is on the hook. Your card processor will email you the questionnaire annually.
What to do
If you outsource card handling to Stripe / Square / PayPal you're almost certainly SAQ-A - fill it out as soon as you receive the prompt; ignoring it can result in higher transaction fees.