---
title: "PCI Compliance Guide for Merchants"
canonical: "https://help.spoton.com/space/SK/4283203664/PCI%20Compliance%20Guide%20for%20Merchants"
format: markdown
---
## Simplified Compliance with Our Solutions

SpotOn supports its merchants with the PCI compliance process through a third-party service, SecureTrust by Viking Cloud.

### Secure Payment Processing

Our solutions minimize your exposure to cardholder data, reducing the PCI DSS compliance scope.

### Compliance Support Tools

Resources and tools to guide you through the SAQ process, tailored to your specific business model and compliance level.

### Ongoing Security Monitoring

Continuous monitoring services to ensure your payment environment remains secure against threats.


**Contents**  


> Macro (toc)

---

# Introduction to PCI DSS


"PCI compliance" refers to a set of rules for taking credit cards securely to minimize risks of data breaches or other security problems. Every business that takes credit cards, even if only a few cards a month, *must* comply with Payment Card Industry Data Security Standard (PCI DSS) requirements.


The Payment Card Industry Data Security Standard (PCI DSS) is a global standard that outlines the required measures for all entities that process, store, or transmit credit card information. PCI compliance is not only a mandate but a fundamental step in protecting credit card data, reducing the risk of data breaches and fraud. SpotOn solutions were built, configured, and installed to support you in meeting certain relevant PCI DSS requirements; **however, you're still responsible for ensuring your business is compliant with the PCI DSS and all major card brands at all times.**


Navigating the complexities of the PCI DSS is essential for merchants to ensure the security of customer payment card information. Each year you will need to complete a "self-assessment questionnaire" (SAQ) as well as hire a third party to perform network scans. SpotOn has partnered with Viking Cloud/ Secure Trust to assist in completing these assessments and completing scans as required by your set-up. If you run through a self managed network you may have increased obligations under PCI DSS.


Key PCI Compliance Requirements:

The below guidelines apply broadly to all businesses that accept credit cards. Your business may need to implement particular policies or procedures based on your business operations. For most businesses using SpotOn POS services and our provided Meraki routers, your obligations will be taken care of by SpotOn. 


1. **Network Security: **Building and maintaining a secure network means that Implement firewalls and router configurations to protect data. You'll also need to change all passwords from factory/manufacturer defaults to more secure options.
2. **Protect Cardholder Data:** Protecting your customers' data means that you either don't store card details or only store them securely. Encrypt stored cardholder data and secure all data transmissions.
3. **Malware and Vulnerability Management:** Use anti-virus software and develop secure systems and applications. You'll need processes in place to timely identify and install security updates/patches as they become available.
4. **Access Control Measures:** To comply with the access control measures limit data access to a need-to-know basis, assign unique IDs for computer access, and control physical access. This should include creating unique IDs for each employee using BOH features, implementing automatic log-outs after a certain period of inactivity, and requiring regular password changes.
5. **Monitoring & Testing:** Regularly test security systems and processes to ensure that everything is functioning properly, and that data is stored correctly.
6. **Security Policy:** Lastly, Develop and maintain policies addressing information security which details security procedures, and includes information on identifying risks.


---

# PCI DSS Compliance Levels

| Levels | Description | Requirements |
| --- | --- | --- |
| Level 4 | Merchants processing fewer than 20,000 e-commerce transactions per year<br>**OR**<br>Merchants processing up to 1 million total transactions annually.<br>This level typically includes small businesses and merchants with a lower transaction volume. | - Completion of an appropriate SAQ based on the merchant's specific payment processing setup.
- Quarterly network scan by an Approved Scan Vendor (ASV), as applicable.
- Attestation of Compliance Form. |
| Level 3 | Merchants processing 20,000 to 1 million e-commerce transactions per year.<br>This level includes businesses that primarily operate online and process a considerable volume of electronic payments. | - Completion of the relevant SAQ, which may vary based on the e-commerce technology and data handling practices.
- Quarterly network scan by an ASV, as applicable.
- Attestation of Compliance Form. |
| Level 2 | Merchants processing 1 to 6 million transactions per year.<br>It is designed for mid-sized merchants who handle significant volumes of transactions but not at the scale of Level 1 businesses. | - Completion of a Self-Assessment Questionnaire (SAQ) appropriate to the merchant's payment processing method.
- Required quarterly network scan by an ASV.
- Attestation of Compliance Form. |
| Level 1 | Merchants processing over 6 million transactions per year<br>**OR**<br>Merchants who have experienced a data breach or attack that compromised cardholder data.<br>This level is designed for large merchants and service providers. | - Annual Report on Compliance (ROC) by a Qualified Security Assessor (QSA) or an internal auditor if signed off by an officer of the company.
- Required quarterly network scan by an ASV.
- Attestation of Compliance Form. |

---

# Understanding SAQ Types

The Self-Assessment Questionnaire (SAQ) is a validation tool for merchants not required to undergo an onsite assessment per the PCI DSS. The SAQ includes a series of yes-or-no questions related to PCI DSS requirements applicable to the merchant's payment card processing environment. The type of SAQ a merchant will need to complete depends on how they accept and process cardholder data:


    SAQ A: For merchants who outsource all cardholder data processing to PCI DSS compliant third parties and do not store, process, or transmit any cardholder data on their systems or premises.

    SAQ A-EP: For e-commerce merchants who use third-party service providers to handle their payment processing and do not have direct control of the management of cardholder data.

    SAQ B: For merchants using only imprint machines and/or standalone, dial-out terminals with no electronic cardholder data storage.

    SAQ B-IP: For merchants using standalone, IP-connected payment terminals with no electronic cardholder data storage.

    SAQ C: For merchants with payment application systems connected to the Internet, without electronic storage of cardholder data.

    SAQ C-VT: For merchants who manually enter a single transaction at a time via a keyboard into an Internet-based virtual terminal solution.

    SAQ D: For all other merchants not covered by the above and all service providers defined by a payment brand as eligible to complete an SAQ.


---

# Steps to Achieving Compliance

### Assess

Identify cardholder data, evaluate your payment card processing methods, and identify potential vulnerabilities.

### Remediate

Secure vulnerabilities, minimize data storage, and use encryption, truncation, or tokenization to protect stored cardholder data.

### Report 

Submit compliance reports to your acquiring bank and card brands, including completed SAQs, and if applicable, an ROC by a QSA for Level 1 merchants.


---

# Conclusion

PCI DSS compliance is an ongoing journey requiring continuous attention to security practices. 

Understanding your compliance level and the applicable SAQ type is essential for navigating the compliance process effectively. Our platform is committed to supporting you through this journey, offering tools and services to simplify compliance and ensure the security of your payment environment.

For more information on SAQs, compliance levels, or assistance with your specific compliance needs, please reach out to [compliancehelp@spoton.com](mailto:compliancehelp@spoton.com).