Skip to content

For businesses that take cards · Private to your browser

How much of PCI actually applies to you?

PCI is a sliding scale — the less card data your own systems touch, the less of it applies. Answer four questions and see your likely SAQ type and the single biggest move to shrink your scope. Not a QSA assessment; nothing is sent anywhere.

Answer for how your business actually takes cards today. The result updates as you go.

  1. How do you mainly accept card payments?

  2. Does a full card number ever get stored on your systems — database, spreadsheet, booking notes, email, or paper?

  3. For any online sales: is card entry handled entirely by your processor (a hosted page or iframe — Stripe, Square, etc.), so card data never touches your site or server?

  4. For any in-person terminals: are they P2PE-validated and/or on a network segment separate from your office and guest Wi-Fi?

Reading this without JavaScript?

The short version: never store card numbers, use a hosted online checkout, and keep card terminals on their own network segment. Those three moves take most small merchants to the shortest questionnaire. The PCI-aware IT page explains how each is built.

Want your scope built down and documented?

Book the free IT Health Check

The moves that shrink scope

Never store card numbers

Not in spreadsheets, booking notes, or email. A stored card number is the single biggest multiplier of both scope and liability.

Use hosted checkout online

If the payment page is served by your processor, not your site, your website stays out of card scope. Our web builds never touch card data.

Segment the card network

Card systems on their own VLAN, provably separate from office laptops and guest Wi-Fi, so "the card environment" is one segment, not your whole business.

Prefer P2PE terminals

Point-to-point encryption means your network only ever carries ciphertext. A hardware choice that massively shrinks scope.

Straight answers

Is this an official PCI assessment?

No. This is a plain-English scope finder to help you understand roughly how much of PCI applies and where the biggest reduction is. Your processor or acquirer determines your actual SAQ type and obligations, and we are not a QSA (Qualified Security Assessor) — be wary of any IT company that claims to certify PCI. This orients you before that conversation; it does not replace it.

Why does how I take cards change everything?

PCI is a sliding scale: the less card data your own systems touch, the less of the standard applies. A hosted online checkout, a P2PE terminal, and never storing card numbers can shrink a business from the long questionnaire down to the short one. Scope reduction is the whole game for a small merchant.

What is an SAQ?

A Self-Assessment Questionnaire — the standard way smaller merchants attest to PCI without a full audit. Which one applies (A, B, C, P2PE, D, and variants) depends on how card data flows through or around your systems. This tool points you toward the likely shape; your processor confirms it.

Do you store anything I enter?

No. There is no signup and nothing leaves your browser — the logic runs on this device. It is a private orientation tool.

Smaller scope, smaller headache.

We build the environment PCI wants to see — segmented card networks, P2PE-friendly terminals, hosted checkout, isolated guest Wi-Fi — and keep the evidence current, so your annual questionnaire is a review, not an archaeology project.