Compliance ยท Card data (PCI DSS)
PCI isn't one giant standard you either pass or fail. It's a scope. And scope can be shrunk.
The rule of thumb for every Anchorage shop that takes cards: the less your network ever touches card data, the less of PCI applies to you. Architecture, not paperwork, is where compliance gets easier.
How Anchorage businesses actually take cards.
Your processor or acquirer determines the exact questionnaire that applies to you. But nearly every local setup is one of three shapes, and the shape decides how heavy compliance feels.
Smallest card-data footprint
Counter terminal, separate from everything
A standalone card terminal that dials out on its own connection, or a P2PE-validated terminal on an isolated network segment. The card number never touches your computers.
Typically SAQ B / B-IP / P2PE territory
The scope you want if you can get it. Most of PCI simply stops applying to your office network.
Middle card-data footprint
Integrated point-of-sale
The register, the kitchen printer, the inventory system, and the card reader all talk to each other, common in restaurants and retail with modern POS platforms.
Typically SAQ C territory
The POS environment is in scope, so segmentation decides whether "the POS network" means one VLAN or your entire business.
Depends on checkout card-data footprint
E-commerce
You sell online. With a hosted checkout (the payment page is served by your processor, not your site), the heavy lifting shifts to them.
Hosted checkout: typically SAQ A. Your own payment form: much more.
This is why our web builds never handle card data directly, hosted checkout keeps your site out of card scope.
What we actually do
Six moves that shrink scope and harden what's left.
Segment the POS network
Card systems live on their own VLAN with firewall rules between them and everything else. The guest Wi-Fi, the office laptops, and the break-room smart TV are not in your card environment, provably.
Prefer P2PE-validated terminals
Point-to-point encryption means the card number is encrypted inside the terminal and your network only ever carries ciphertext. Massive scope reduction for a hardware choice.
Never store card numbers
Not in spreadsheets, not in the booking notes, not in email. If a full card number exists anywhere on your systems, your scope and your risk just exploded. We help you find and end these habits.
Isolate guest Wi-Fi completely
Customer Wi-Fi shares nothing with the card environment: separate SSID, separate VLAN, no route between them. UniFi makes this clean; we make it verified.
Harden and log what remains
Default passwords changed, management interfaces locked down, firmware current, and logs kept, the unglamorous requirements that scanners and questionnaires actually check.
Keep the evidence
Network diagrams, segmentation rules, and change history, current and in writing, so the annual questionnaire is a review, not an archaeology project.
The honest boundary
PCI attestation runs through your card processor, and formal assessments come from QSAs and Approved Scanning Vendors certified by the PCI council, not from your IT company. What we own is the environment those assessments examine: the segmentation, the hardened Wi-Fi, the POS hygiene, the logs, and the current network documentation that turns the annual questionnaire from a guess into a review. If your setup would honestly fail a question today, we will say so, and fix it.
Where this lands
Small retail
Registers, cameras, and inventory systems that just work, with the card environment walled off.
See how →
Coffee shops & restaurants
POS, guest Wi-Fi, and music that survive the morning rush, on properly separated networks.
See how →
Network & firewall management
The UniFi-first segmentation and firewall discipline this whole page rests on.
See the service →
PCI FAQ.
Do small Anchorage shops really have to deal with PCI?
If you take cards, yes, it applies at every size through your agreement with your card processor. The good news: for most small businesses the honest path is a short self-assessment questionnaire, not an audit, and the smaller you keep your card-data footprint, the shorter it gets.
What exactly is an SAQ?
A Self-Assessment Questionnaire, the standard way smaller merchants attest to PCI. Which SAQ applies depends on how card data flows through (or around) your systems, and your processor or acquirer makes that determination. Our role is building an environment where the answers are honestly yes.
Are you a QSA? Can you certify us?
No, and be wary of any IT company that claims to. Qualified Security Assessors and Approved Scanning Vendors are certified by the PCI council, and attestation runs through your processor. We implement and document the technical environment those assessments look at.
What about the quarterly network scans my processor mentions?
Some setups require quarterly scans by an Approved Scanning Vendor, usually arranged through your processor. We prepare the environment, fix what scans find, and keep the segmentation tight so the scan surface stays small.
What's the single best first move?
Separate your card systems from everything else. Segmentation is the one change that simultaneously shrinks compliance scope, contains a breach if one happens, and usually costs configuration time rather than new hardware.
Not sure what your card footprint looks like?
The free 30-minute IT Health Check includes a plain-English read on where card data flows through your business today, and the one or two architecture moves that would shrink it.