Do You Have to Be PCI Compliant? Rules, Levels, and Penalties

If your business accepts, processes, stores, or transmits payment card data in any form, you have to be PCI compliant. There is no federal law in the United States that mandates the Payment Card Industry Data Security Standard, but every major card brand requires it as a condition of using their payment networks, which makes it a contractual obligation with real financial consequences. The current version, PCI DSS v4.0.1, has been fully enforceable since March 31, 2025, so every requirement now applies with no grace periods.

Who the Standard Actually Covers

The rule is broader than most business owners assume. PCI DSS applies to merchants selling goods or services, service providers who handle payment data on behalf of others, and third-party processors. Size is not part of the test. A one-person online store filling ten orders a week carries the same baseline obligation as a national retailer processing millions of transactions.

What triggers the obligation is contact with cardholder data, not volume. If card numbers pass through your website, sit in your point-of-sale system, get keyed into a virtual terminal, or land in an email from a customer, you are inside the scope of the standard.

Outsourcing Doesn’t Get You Out

The most common misconception among small businesses is that handing payment processing to a third-party gateway makes PCI compliance someone else’s problem. It doesn’t. Using a third party can significantly reduce the scope of what you need to protect, but you remain responsible for confirming that your specific setup is secure and that no unencrypted card data lingers on your servers, email systems, or local devices.

The PCI Security Standards Council is explicit that it develops and maintains the standards but does not enforce them. Enforcement falls to the card brands, your acquiring bank, and your payment processor, each of which can impose their own penalties. In other words, the entity you owe compliance to is the same entity that pays you: your processor. That is why the pressure is real even without a statute behind it.

Merchant Levels Shape What Compliance Looks Like

Every business inside the scope has to comply, but how you prove it depends on your transaction volume. Card brands sort merchants into four tiers based on transactions over a twelve-month period, and the tier determines how rigorously you must validate. Visa’s thresholds are the most widely referenced:

  • Level 1: more than 6 million Visa transactions per year across all channels. Requires an annual on-site assessment by a Qualified Security Assessor and quarterly network scans.
  • Level 2: between 1 million and 6 million transactions per year. Typically validated through a Self-Assessment Questionnaire and quarterly scans.
  • Level 3: fewer than 1 million e-commerce transactions per year.
  • Level 4: fewer than 20,000 e-commerce transactions per year, or up to 1 million total non-e-commerce transactions.

Other card brands set their own thresholds, so a merchant can sit at one level for Visa and a different level for Discover or Mastercard.1Visa. Account Information Security (AIS) Program and PCI If your volume grows and pushes you into a higher tier, your acquiring bank will expect you to shift to the more rigorous validation method for that level. Level 1 merchants get a Report on Compliance from a Qualified Security Assessor; everyone else typically works through a Self-Assessment Questionnaire matched to how their payment environment is set up, along with an Attestation of Compliance submitted to their acquiring bank or processor. Validation is good for one year, so the cycle repeats annually.

What Non-Compliance Actually Costs

The financial consequences of ignoring PCI DSS come from several directions and scale sharply with size and with whether a breach occurs.

The most common penalty for small businesses is a monthly non-compliance fee from the payment processor. If you have not submitted your SAQ or completed your quarterly scans, processors typically add a recurring charge to your merchant statement, often in the range of $20 to $100 per month. On its own it is not catastrophic, but it adds up and signals to your processor that you are not taking security seriously.

For larger merchants or those with higher risk profiles, card brands and acquiring banks can impose escalating fines that start in the thousands per month and climb into the tens of thousands the longer the issue persists. These fines are assessed to your acquiring bank, which passes them to you. After several months, the amounts can reach $50,000 to $100,000 per month or more.

The real exposure comes when a breach happens while you are non-compliant. Card brands can levy penalties up to $500,000 per incident, and you will be on the hook for the costs of notifying affected cardholders, reissuing compromised cards, and covering fraudulent charges. Your acquiring bank can also terminate your merchant account, which means you lose the ability to accept card payments until you find a new processor willing to take on the risk.2PCI Security Standards Council. About Us For most businesses, losing card acceptance is an existential problem.

State Laws That Add Legal Teeth

No federal statute requires PCI DSS compliance, but a handful of states have written it into law or created liability frameworks that penalize non-compliance in practice.

Nevada is the most direct. Under NRS 603A.215, any business operating in Nevada that accepts payment cards must comply with the current version of PCI DSS by the compliance deadline set by the PCI Security Standards Council. That is state law, not a contractual matter between you and your processor.3Nevada Legislature. Nevada Revised Statutes 603A.215 – Security Measures for Data Collector That Accepts Payment Card

Minnesota takes a different route. Under its data breach statute, if a business retains prohibited card data such as full magnetic stripe data or CVV numbers and a breach occurs, that business must reimburse financial institutions for costs resulting from the breach. Those costs include reissuing affected cards, closing and reopening accounts, refunding unauthorized charges, and notifying cardholders. The financial institution can also recover damages it paid to affected cardholders.4Minnesota Office of the Revisor of Statutes. Minnesota Statutes 325E.64 – Access Devices; Breach of Security The result is a strong incentive to follow PCI DSS data retention rules even without a direct compliance mandate.

All 50 states have data breach notification laws, and many of them include exceptions for encrypted data. Maintaining PCI-compliant encryption can therefore reduce your notification obligations and potential liability if a breach happens, even in states that do not reference PCI DSS by name.

Third-Party Providers Are Still Your Problem

Hiring a payment processor or cloud hosting provider to handle card data does not transfer your PCI obligations. The PCI SSC states repeatedly that using a third-party service provider does not relieve you of responsibility for your own compliance or accountability for securing cardholder data in your environment.5PCI Security Standards Council. Third-Party Security Assurance – Information Supplement

Practically, three things need to happen. Get a written agreement that spells out which PCI DSS responsibilities belong to you and which belong to the provider. Confirm the provider’s compliance status by requesting their Attestation of Compliance, SAQ, or the relevant sections of their Report on Compliance. Then monitor that status on an ongoing basis: keep an inventory of every third-party provider that touches your payment environment, track when each was last validated, and have a plan for what you will do if one falls out of compliance or refuses to prove its status.

How to Make Compliance Manageable

Every covered business has to comply, but the amount of work involved varies enormously based on how much card data your systems actually touch. Scope reduction is the single most effective strategy for keeping compliance manageable, especially for small merchants.

Outsourcing payment processing is the biggest lever. If you use a hosted payment page or redirect customers to a PCI-validated third-party processor, card data never hits your servers. That typically qualifies you for SAQ A, the simplest questionnaire. You still need to confirm your setup is secure and complete quarterly scans by an Approved Scanning Vendor under v4.0, but the overall burden is dramatically smaller than handling card data yourself.

Tokenization replaces actual card numbers with non-sensitive substitutes that are useless to an attacker. A properly implemented tokenization solution can remove systems from your cardholder data environment, reducing what you need to protect and potentially simplifying which SAQ you qualify for.6PCI Security Standards Council. PCI DSS Tokenization Guidelines – Information Supplement Tokenization does not eliminate the need for PCI compliance, but it can shrink the effort considerably.

Validated point-to-point encryption is the third option. P2PE solutions encrypt card data at the terminal and keep it encrypted until it reaches the payment processor. Merchants using a validated P2PE solution can complete SAQ P2PE, which has far fewer requirements than the catch-all SAQ D.

For a small business processing fewer than 20,000 e-commerce transactions, the annual cost of maintaining compliance through one of these simplified approaches generally runs from a few hundred to a few thousand dollars, covering the SAQ, quarterly scans, and any associated processor fees. That is a fraction of what a single data breach would cost.

The Bottom Line for Your Business

If card data touches your business, PCI DSS applies. The question is not whether you have to comply but how heavy your validation burden will be, and that comes down to how you have arranged your payment environment and how many transactions you process. Confirm your merchant level with your acquiring bank, identify the SAQ that matches your setup, and, if the scope feels overwhelming, look hard at outsourcing, tokenization, or P2PE before you start building controls you may not need.