← Back to blog

Cut PCI Compliance Scope to SAQ A, Avoid 300+ Rules for U.S. SMBs

September 11, 2026
Cut PCI Compliance Scope to SAQ A, Avoid 300+ Rules for U.S. SMBs

Yes, if you accept Visa, Mastercard, American Express, or Discover, you must meet PCI DSS. The fastest way to keep cost and risk low is to never let card data touch your systems in the first place, aiming for the simplest self-assessment level by using hosted or tokenized payment capture. The PCI Security Standards Council sets the rules, and a partner like Ventis Consulting Group can help you apply them without a major IT overhaul.


TL;DR:

  • Businesses that use major card brands must meet PCI DSS requirements regardless of transaction volume, with lower compliance costs possible through hosted or tokenized payment methods.
  • Moving from embedded payment scripts to hosted checkout significantly reduces your PCI scope, often qualifying for the simplest SAQ A with minimal costs.
  • The merchant's PCI level, which determines validation method, is set by the card processor and ranges from Level 1 for over 6 million transactions to Level 4 for under 20,000 transactions annually.
  • Ongoing compliance involves quarterly scans, regular access reviews, and updating security practices, not a one-time project, to avoid common mistakes like storing card data or neglecting system patches.
  • Consulting local PCI experts can streamline scope assessment, help choose the correct SAQ, and support migration to more secure, compliance-friendly payment setups.

Ventis Consulting Group
Simplify Your PCI Compliance Path
Ventis provides cybersecurity assessments and personalized guidance to help small and mid-sized businesses address their technology and security needs.
Explore Ventis Consulting Group

Table of Contents

Which Businesses Need PCI Compliance and What Merchant Level Means

If your business swipes, keys in, or takes a card number over the phone for any of the major card brands, you're in scope for PCI DSS. There's no revenue floor or transaction minimum that exempts you. A food truck that takes five card payments a day has the same baseline obligation as a regional retailer, even though the paperwork looks very different.

Card brands sort merchants into four levels based on annual transaction volume, and your level determines how you validate compliance:

  • Level 1: Over 6 million transactions annually, or any merchant that has suffered a breach, requires an on-site assessment by a Qualified Security Assessor.
  • Level 2: 1 to 6 million transactions annually, typically validated through a Self-Assessment Questionnaire.
  • Level 3: 20,000 to 1 million e-commerce transactions annually.
  • Level 4: Under 20,000 e-commerce transactions, or up to 1 million total transactions across channels. Most small businesses land here, per Paytia's analysis of U.S. merchant thresholds.

Your card processor or acquiring bank assigns your level, not you. Call them, ask in writing which level and SAQ they expect from you, and keep that email. It becomes your reference point if a dispute or audit ever comes up.

Choosing the Right Self-Assessment Questionnaire

The Self-Assessment Questionnaire, or SAQ, is the document that proves you meet PCI DSS for your specific setup. There isn't one universal form. The right SAQ depends entirely on how your business captures card data, and that choice drives most of your cost and workload.

  1. Hosted payment page or redirect. If a customer clicks "pay" and lands on your processor's page (Stripe Checkout, Square, PayPal), you likely qualify for SAQ A, the shortest questionnaire with a limited number of questions.
  2. Embedded JavaScript or iframe on your own page. If your site loads a payment field directly rather than redirecting, you typically fall into SAQ A-EP, which brings network segmentation testing and a much longer control set. Embedding payment scripts is one of the most common ways small businesses unintentionally expand their own scope, according to Paytia's guidance on script integrity.
  3. Standalone dial-out terminals or validated PIN pads. Retailers using standalone, IP-connected terminals that don't touch your network usually qualify for SAQ B or SAQ B-IP.
  4. Anyone storing cardholder data. If you keep card numbers in a spreadsheet, a CRM, or a local database, you're looking at SAQ D, the longest form with well over 300 requirements.

SAQ A merchants often incur lower annual compliance costs, typically in the range of a few hundred to a few thousand dollars, while SAQ D merchants usually face higher expenses due to more extensive assessor fees and technical requirements. Moving from an embedded checkout to a hosted redirect, or tokenizing card data at the point of capture, is usually the single fastest way to drop from a costly SAQ into SAQ A.

The 12 PCI DSS Requirements, Explained Simply

PCI DSS organizes its rules into 12 requirements. None of them demand enterprise-grade infrastructure. Most translate into decisions a small business owner can make in an afternoon.

  • Install and maintain network security controls. Keep a firewall between your point-of-sale network and everything else, including guest Wi-Fi.
  • Apply secure configurations. Change every default password on routers, POS terminals, and payment software the day you install them.
  • Protect stored account data. Better yet, don't store it at all.
  • Protect cardholder data with strong cryptography during transmission. Use processors that encrypt data in transit by default.
  • Protect against malware. Run endpoint protection on any device that touches payment systems.
  • Develop secure systems and software. Keep POS software and plugins patched, and confirm script integrity on any customer-facing checkout page.
  • Restrict access to cardholder data by business need. Not every employee needs access to payment records.
  • Identify users and authenticate access. Multi-factor authentication on admin accounts is now a baseline expectation under PCI DSS v4.x, not a nice extra.
  • Restrict physical access to cardholder data. Lock the room with your server or POS backend.
  • Log and monitor all access. Keep logs long enough to investigate an incident after the fact.
  • Test security regularly. This is where quarterly ASV scans come in for anyone with internet-facing systems.
  • Support information security with organizational policies. Written policy, even a short one, satisfies this for most small merchants.

Quick fact: PCI SSC's merchant guidance confirms that validation requirements scale with transaction volume, but the underlying 12 requirements apply to every merchant that stores, processes, or transmits card data, regardless of size.

Your PCI Compliance Checklist: This Week, This Quarter, and Every Year

Getting compliant isn't one project with an end date. It's a set of habits, and the order you tackle them in matters.

  1. As soon as possible: Map every place a card number touches your business, phone, website, or in-person terminal, and identify anywhere you're storing numbers you shouldn't be.
  2. As soon as possible: Change every default password on POS terminals, routers, and payment software, and enable multi-factor authentication for all admin or payment-portal logins.
  3. As soon as possible: Stop writing down or emailing full card numbers, and delete any spreadsheets or notes containing them.
  4. Confirm your merchant level and required SAQ in writing with your acquirer promptly.
  5. If you haven't already, migrate to a hosted checkout or tokenized capture method, as this commonly enables eligibility for SAQ A.
  6. For any internet-facing system, schedule quarterly scans with an Approved Scanning Vendor and complete your SAQ and Attestation of Compliance.
  7. Maintain quarterly ASV scans, conduct employee access reviews regularly (at least twice a year), and provide annual staff training on phishing and card-skimming recognition.
  8. Keep a basic written incident response plan ready to act immediately if a breach occurs.

Pro Tip: Save every SAQ, Attestation of Compliance, and ASV scan report in one folder with the date attached. When a processor asks for proof two years from now, you want to find it in thirty seconds, not scramble through old email threads.

Staying Compliant: Ongoing Duties and the Mistakes That Trip Up Small Businesses

PCI compliance expires the moment you stop paying attention to it. Compliance isn't a certificate you earn once, according to the U.S. Chamber of Commerce's guidance for small businesses, it's a set of controls you have to keep proving quarter after quarter. Quarterly ASV scans, patch management, and access reviews aren't optional extras. They're the ongoing half of the job that most owners underestimate when they first read the requirements.

The recurring mistakes are predictable:

  • Adding a new booking widget or payment plugin without checking whether it expands your SAQ scope.
  • Assuming your payment processor "handles all of that," without confirming in writing which controls are actually theirs.
  • Leaving MFA off admin accounts because it feels like friction for a small team.
  • Skipping ASV scans because "nothing's changed," even though new vulnerabilities get disclosed every week.

A short logging habit and an annual access review catch most of these before they become a real incident. If a breach does happen, having a response plan already written turns a chaotic afternoon into a manageable checklist.

When to Bring In a Consultant

Some of this you can handle alone with an afternoon and a checklist. Some of it, especially scoping a payment migration or coordinating ASV scans across multiple locations, goes faster with someone who's done it before. A solid engagement usually includes a scope review of your current payment flows, help selecting and completing the right SAQ, coordination with an Approved Scanning Vendor, and a plan for moving toward hosted or tokenized payments.

Four-step PCI compliance consulting process

If you're evaluating a Qualified Integrator and Reseller or a security consultant, ask three things: what deliverables you'll receive in writing, how long the engagement takes, and whether they can explain your specific merchant level and SAQ back to you in plain language. If they can't, keep looking. Some local providers build these engagements around exactly that kind of clarity to support small business compliance.

What Actually Moves the Needle on PCI Compliance

Most PCI advice online reads like a compliance officer wrote it for a Fortune 500 company. It isn't wrong, exactly, it's just aimed at the wrong reader. A five-person retail shop doesn't need a network segmentation diagram. It needs to stop storing card numbers in a spreadsheet and switch to a hosted checkout.

The conventional advice treats all 12 requirements as equally urgent from day one. They aren't. Data minimization does more work than almost anything else on the list, because if cardholder data never enters your environment, whole categories of requirements simply stop applying to you. That's not a shortcut. It's the intended design of the SAQ system itself.

Where I'd push back hardest is on the instinct to treat PCI as an IT department problem to solve once and forget. It's closer to a payroll cycle: quarterly scans, annual training, ongoing access reviews. Businesses that build it into a calendar instead of a project plan stay compliant with far less stress. Start with scope reduction. Everything else gets easier once that's done.

— Greg

Get PCI Scoping Help Without the Guesswork

Ventis Consulting Group gives Pittsburgh-area small businesses a straighter path to PCI compliance than hiring a national assessor or trying to interpret 300-plus requirements alone: local, hands-on scoping that tells you exactly which SAQ applies and what to fix first.

Ventis Consulting Group

A compliance consultation typically starts with a review of how your business actually captures card payments, followed by a practical roadmap covering SAQ selection, ASV scan coordination if you have internet-facing systems, and migration support if moving to a hosted or tokenized checkout makes sense for you. Ventis also folds PCI work into broader cybersecurity compliance practices like MFA rollout and vendor verification, so you're not solving payment security in isolation from the rest of your network. For businesses that want a second set of eyes on vulnerability scanning specifically, resources like California Telecom's vulnerability assessment guidance are worth a look alongside your ASV coordination.

Reach out through Ventis Consulting Group's unified communications and IT solutions page to schedule a scope review and get a straight answer on what your business actually needs.

Get PCI Scoping Help Without the Guesswork — overview diagram

Where to Verify the Details

For primary sources, start with the PCI Security Standards Council's merchant resources for SAQ downloads, CISA's small-business cybersecurity guidance, and the FTC's cybersecurity resources for small businesses.

Sources

FAQ

Does My Small Business Need to Be PCI Compliant?

Yes. Any business that accepts Visa, Mastercard, American Express, or Discover cards must meet PCI DSS requirements, regardless of size or transaction volume.

Can I Do PCI Compliance Myself?

Most small businesses can complete a Self-Assessment Questionnaire without a consultant, especially if they use a hosted checkout that qualifies for SAQ A, though scheduling ASV scans and interpreting a longer SAQ often benefits from outside help.

Do All Merchants Have to Be PCI Compliant?

Yes, every merchant that stores, processes, or transmits cardholder data falls under PCI DSS, though the validation method (which SAQ, whether an on-site assessment is needed) scales with transaction volume and merchant level.

Do I Need to Be PCI Compliant if I Use Square?

Yes, though using a processor like Square that hosts the payment capture typically qualifies you for the simplest SAQ A, since you're not storing or transmitting raw card data through your own systems.