Skip to content
Ajgori Technologies
All posts

E-commerce 8 min read

What PCI DSS means for a small online store

What PCI DSS means for a small online store, how your checkout type changes your duties, and the simple habits that keep you compliant.

On this page
  1. What PCI DSS is
  2. Why it applies to small stores too
  3. How your checkout type changes your duties
  4. Self-assessment questionnaires
  5. Simple steps for PCI compliance in a small business
  6. Summary

PCI compliance for a small business means following the card industry's security rules for any system that handles card payments, even if you only take a few online orders a week. For most small online stores, the practical work is lighter than it sounds: choose a checkout that keeps card details away from your own systems, complete the right self-assessment questionnaire, and keep your website and accounts secure. The type of checkout you use decides how much of the standard applies to you.

PCI stands for Payment Card Industry. The rules are set out in the PCI Data Security Standard, known as PCI DSS. This guide explains what it means for a small store in plain terms. It is not legal advice; your payment provider or acquiring bank is the authority on what you must do. If you need help with your store's checkout, our e-commerce service page explains how we work.

What PCI DSS is

The PCI Data Security Standard is a set of security requirements for organisations that store, process or transmit payment card data. It is managed by the PCI Security Standards Council, a global forum that brings together organisations from across the payments industry.

In broad terms, the standard covers:

  • Protecting card data wherever it is stored, processed or transmitted.
  • Securing the systems involved, including networks, servers and software.
  • Controlling access so only the right people can reach card data and payment systems.
  • Monitoring and testing to detect and fix security problems.
  • Having security policies that staff understand and follow.

The full standard is long and detailed, because it covers everyone from very large payment processors to small shops. Most small online stores only need to deal with the parts that match how they take payments.

A common mistake and its fix

A common mistake is assuming that PCI DSS does not apply at all because "the payment gateway handles the cards". Using a gateway can reduce your responsibilities a great deal, but your business still accepts card payments and still has duties, such as keeping the website that sends customers to the payment page secure.

The fix is to ask your gateway or acquiring bank directly: "Given how we take payments, which PCI DSS requirements and which questionnaire apply to us?" Keep their answer with your records.

Why it applies to small stores too

PCI DSS is not only for large retailers. If your business accepts card payments, you are expected to protect card data, whatever your size.

  • Your agreement with your payment provider usually includes a commitment to follow PCI DSS.
  • Small stores are still targets. Attackers look for weak points in any checkout, and small sites are often less protected.
  • The consequences fall on the business. A breach can have serious financial and practical consequences, which your payment provider's terms describe.
  • Customers expect it. A secure checkout is part of earning trust.

For example, a small store that uses a hosted payment page never handles card numbers itself. But if an attacker gained access to the store's admin area and changed the "Pay now" link to point to a fake payment page, customers could hand their card details to the attacker. Keeping the store's own software and admin accounts secure is part of protecting card data, even when the gateway does the processing.

The good news is that small businesses can usually reduce their responsibilities a great deal through the way they take payments.

The same rules apply to travel booking sites, which also have to manage payments before a supplier confirms, as our guide to payments for travel booking websites explains.

How your checkout type changes your duties

The biggest single decision affecting PCI compliance for small businesses is where card details are entered and which systems they pass through.

  1. Hosted payment page. The customer is redirected to a payment page run by your payment gateway. Card details are entered on the gateway's systems and never pass through your website. This usually leaves your business with the fewest requirements.
  2. Embedded checkout using the gateway's secure fields. The payment form appears inside your page, but the card fields are provided and controlled by the gateway. Card details still do not reach your server, but because the form sits on your page, the security of that page matters more.
  3. Your own card form. Card numbers are entered into a form you built and pass through your server. This brings the widest responsibilities and is rarely a good idea for a small store.
  4. Storing card numbers. Keeping card numbers yourself, even temporarily, adds significant responsibility. Where a store needs repeat payments, gateways usually provide a token, a stand-in reference that can be charged again without you holding the card number.

For most small online stores, a hosted payment page or the gateway's secure embedded fields is the sensible choice. Our comparison of a hosted payment page and an embedded checkout explains the trade-offs in more detail.

With a hosted or embedded checkout, your store learns the payment result through a webhook, and our guide to payment webhooks and pending orders explains how to handle it reliably.

Self-assessment questionnaires

Many small merchants show their compliance through a Self-Assessment Questionnaire, known as an SAQ. According to the PCI Security Standards Council, an SAQ is a self-validation tool intended for merchants and service providers that are not required to submit a formal report on compliance.

  1. There are different questionnaires for different ways of taking payments. A store that fully outsources card handling to a compliant provider answers a much shorter questionnaire than one that processes card data on its own systems.
  2. The questions are mostly yes or no, covering each requirement that applies to your setup.
  3. Your acquiring bank or payment provider can tell you what you need to submit and how often. The Council's guidance is to contact your acquiring bank or the payment card brand if you are unsure which questionnaire applies.
  4. Many payment providers help. Some guide you through the right questionnaire in their dashboard, based on how you integrate with them.
  5. Keep a record. Save your completed questionnaire and any supporting evidence, and review it when your checkout or website changes.

If your developer changes how payments are taken, for example moving from a hosted page to an embedded form, check whether a different questionnaire now applies.

Simple steps for PCI compliance in a small business

For a typical small online store, these habits cover most of the practical work:

  1. Use a hosted page or the gateway's secure fields. Keep card details off your own website and server.
  2. Never store card numbers or security codes. Do not keep them in emails, spreadsheets, notes or your database. Use your gateway's tokens for repeat payments.
  3. Keep your website secure. Update your platform, plugins and themes promptly, remove what you do not use and protect admin accounts with strong passwords and two-step login.
  4. Use HTTPS on every page, so information sent between customers and your site is encrypted.
  5. Limit access. Give staff and agencies only the access they need to your store and payment dashboard, and remove old accounts.
  6. Check your integration after changes. Updates to the checkout, theme or payment plugin can change how card data flows.
  7. Complete your SAQ as required and keep it with your records.
  8. Know what to do if something goes wrong. Your payment provider's terms usually explain how to report a suspected breach.

If you build your own checkout on a framework such as Laravel, our guide on integrating a payment gateway into a Laravel app shows a structure that keeps card data with the gateway. For background on how payments move, see how payment gateways work for online stores.

Summary

  • PCI DSS is the card industry's security standard, and it applies to any business that accepts card payments.
  • Small stores can reduce their responsibilities greatly by using a hosted payment page or the gateway's secure fields.
  • Many small merchants validate compliance with a Self-Assessment Questionnaire, chosen according to how they take payments.
  • Your acquiring bank or payment provider can tell you what you must submit; ask them if you are unsure.
  • Never store card numbers, keep your website secure and review your setup whenever the checkout changes.

Handled sensibly, PCI compliance is a manageable part of running a small online store. If you'd like help setting up a secure checkout, you can tell us about your store here.

E-commerce

Related posts

E-commerce

What it costs to build an online store

What drives the cost of building an online store, which costs continue after launch, and how to plan a realistic first version.

7 min read

Working on something?

Get in touch and tell us about it.