PCI COMPLIANCE · OHIO

PCI compliance requirements, explained simply.

If your business accepts card payments, your merchant agreement likely requires you to follow PCI-DSS. Here's what that means in simple terms — and how NHM helps Ohio businesses put the right controls in place.

  • PCI-DSS scoping and SAQ
  • Network segmentation
  • Card-data environment hardening
  • Quarterly scan and evidence
  • Annual attestation support

Free 30-minute review · No pressure · No obligation

  • PCI Scoping
  • Network Segmentation
  • Card-Data Hardening
  • Quarterly Scans
  • Annual Attestation

Important Disclaimer:

NHM LLC is not a QSA (Qualified Security Assessor). This page provides general information about PCI compliance requirements for educational purposes only and does not constitute professional PCI compliance assessment or certification services. Your payment processor, acquiring bank, card brands, QSA, or legal/compliance advisor determines your specific validation obligations.

What is PCI-DSS?

PCI-DSS (Payment Card Industry Data Security Standard) is a set of security standards maintained by the PCI Security Standards Council, which American Express, Discover, JCB, Mastercard and Visa founded in 2006, to protect cardholder data. The current version is PCI DSS v4.0.1. If you accept, process, store, or transmit credit card information, you must comply.

Who Needs to Comply?

Every business that:

  • Accepts credit or debit card payments
  • Stores cardholder data
  • Processes card payments
  • Transmits card data

This includes retailers, restaurants, e-commerce sites, service businesses, and anyone who takes card payments.

Compliance Levels

Merchant validation levels vary by card brand, payment processor, and transaction volume. As a simplified example, higher-volume merchants may require annual assessments, while many smaller merchants validate with an SAQ. Confirm your exact level and validation steps with your acquiring bank or processor.

Level 1: Over 6 million transactions per year - annual on-site assessment required

Level 2: 1-6 million transactions per year - annual self-assessment questionnaire (SAQ)

Level 3: 20,000-1 million e-commerce transactions per year - annual SAQ

Level 4: Less than 20,000 e-commerce transactions or up to 1 million total transactions per year - annual SAQ

Most small businesses are Level 3 or 4 and can complete a Self-Assessment Questionnaire (SAQ).

The Standard

The 12 PCI Requirements (Simplified)

1

Install and maintain network security controls

Firewalls and similar controls that limit traffic into and out of the systems that handle card data.

2

Apply secure configurations to all system components

Change default passwords and turn off settings and services you don't need.

3

Protect stored account data

If you store card data, encrypt it. Better yet, don't store it if you don't need to.

4

Protect cardholder data with strong cryptography during transmission over open, public networks

Use strong encryption (current TLS) when card data crosses open, public networks.

5

Protect all systems and networks from malicious software

Anti-malware on the systems that need it, kept current, plus defenses against phishing.

6

Develop and maintain secure systems and software

Keep software updated and patch security vulnerabilities promptly.

7

Restrict access to system components and cardholder data by business need to know

Only give access to employees who need it for their job.

8

Identify users and authenticate access to system components

No shared accounts, and multi-factor authentication for access to the card data environment.

9

Restrict physical access to cardholder data

Secure physical access to areas where card data is stored or processed.

10

Log and monitor all access to system components and cardholder data

Log access to system components and card data, and review the logs.

11

Test security of systems and networks regularly

Vulnerability scans, penetration tests where required, and change detection.

12

Support information security with organizational policies and programs

Written security policies, risk assessments, and staff awareness training.

How to Work Toward PCI DSS Validation

1

Assess Your Current State

Understand how you currently handle card data and where you might be vulnerable.

2

Identify Which SAQ Applies

Determine which Self-Assessment Questionnaire (SAQ) applies to your business type.

3

Implement Required Controls

Put security controls in place to meet the 12 requirements.

4

Complete Your SAQ

Fill out the appropriate SAQ documenting your compliance.

5

Check Scan Requirements

If you have in-scope internet-facing systems, arrange required external vulnerability scans with an Approved Scanning Vendor (ASV), typically quarterly and after significant changes.

6

Submit Compliance Documentation

Submit your SAQ and scan results to your payment processor.

7

Maintain Compliance

Compliance is ongoing, not a one-time task. Maintain security controls and update documentation regularly.

Costs of Non-Compliance

Failing to comply can result in:

  • Fees and assessments: Card brands or acquiring banks may impose costs, higher processing requirements, or remediation obligations depending on the issue.
  • Loss of ability to accept cards: Card companies can terminate your merchant account
  • Liability: You may be liable for fraud losses
  • Reputation damage: Breaches hurt customer trust
  • Legal costs: Lawsuits from affected customers

Benefits of Compliance

Beyond avoiding fines, compliance provides:

Better security: Protects your business and customers
Customer trust: Customers trust secure businesses
Reduced liability: Lower risk if a breach occurs
Business reputation: Demonstrates you take security seriously

Get PCI DSS Support

Don't risk payment disruption or unclear card-data obligations. Contact us to discuss how we can help you implement PCI DSS security controls, prepare SAQ documentation, and coordinate with your processor or assessor where needed.