PCI DSS Compliance for Businesses That Accept Card Payments

BlueKey IT helps businesses that store, process, or transmit payment card data meet the Payment Card Industry Data Security Standard. We reduce the systems in scope, implement the technical controls, and prepare the documentation and evidence your acquirer expects.

PCI DSS v4.0.1

  • Scope reduction and segmentation
  • Network and endpoint controls
  • Evidence for your SAQ or ROC
Google

Trusted by Businesses Across the U.S.

Real reviews from real customers. See why businesses choose BlueKey IT.

Read All Reviews
Posted on Google Google
Nilam Khurana profile picture
Nilam Khurana
September 12, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Bluekey IT has been helping our businesses for years. From setting up offices, setting up security measures and continued monitoring to make sure we are safe, they have been there. I would highly recommend them.
Posted on Google Google
Katlyn Kaiser profile picture
Katlyn Kaiser
July 31, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I have had a great experience working with BlueKey IT. Their team is knowledgeable, responsive, and always willing to go the extra mile to ensure issues are resolved quickly.
Posted on Google Google
Corey Nash profile picture
Corey Nash
July 29, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Bluekey has been keeping my business systems running smoothly for nearly a decade. If my systems are down, I cannot make money, when I call Bluekey with a problem they are always quick to answer the phone and give me back up and going in short order. I am so thankful to have them on my side.
Posted on Google Google
Anthony Weinberg profile picture
Anthony Weinberg
July 27, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Amazing team of tech professionals, always there when you need them!
Posted on Google Google
Amy Baer profile picture
Amy Baer
July 27, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I own a large company with over 100 employees. We have used BlueKey for many years area and very happy with the service they provide. Their Management and staff are all amazing.
Posted on Google Google
Undrea Smith profile picture
Undrea Smith
July 27, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
We've worked with Blue Key for well over a decade, and they've been much more than just an IT company. As our firm has grown, they've been a true technology partner, helping us upgrade our systems, improve security, and make sure our infrastructure keeps pace with our business. One of the things we value most is their responsiveness. Our team is spread across the country, so having 24/7 support that anyone on our team can access is incredibly important. No matter when an issue comes up, Blue Key is there to help quickly and professionally. If you're looking for an IT company that is proactive, knowledgeable, and genuinely invested in your success, I highly recommend Blue Key. They've played an important role in supporting our growth, and we're grateful for the partnership.
Posted on Google Google
David Robinson profile picture
David Robinson
July 27, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
BlueKey It Services are very knowledgeable and caring. They provide white glove service and top of the line support for all their clients needs. They are all trained to the highest level in their respective industry and I would recommend them to anyone that needs IT services.
Posted on Google Google
Ed Wiegner profile picture
Ed Wiegner
April 8, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Had an AMAZING iT support experience with Alex at Blu Key IT today. In over 25 years this IT support professional wen above and beyond. Patient focused kind focused and understanding. Jason's following up just appreciate that kind of service and knowledge. Thank You
Posted on Google Google
C W Macc profile picture
C W Macc
April 2, 2026
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Harrison at BlueKeyIT is quick to answer, courteous, knowledgeable, and professional. I continue to be 100% satisfied with the genuine Customer Care provided by the entire Team at BlueKeyIT. Highly recommended!

Know Where Card Data Lives, Then Protect It

Most PCI DSS work comes down to two questions: where does card data go in your business, and what protects it along the way? BlueKey IT maps the flow, shrinks the scope where possible, implements the technical controls, and keeps the evidence your acquirer expects.

Scope reduction · Network and endpoint controls · Evidence and documentation · 200+ customers and 6,000+ endpoints managed

PCI DSS in Plain Terms

The Payment Card Industry Data Security Standard is maintained by the PCI Security Standards Council and applies to any business that stores, processes, or transmits payment card data, and to the vendors that support them. It is not a law. It is enforced through the agreements between merchants, acquiring banks, and card brands, which is why your acquirer, not the Council, tells you how you validate.

The standard has 12 requirements grouped into six goals. Here is the full set, with how BlueKey IT supports each goal.

PCI DSS goal and requirementsHow BlueKey IT helps
Build and maintain a secure network and systems
1. Install and maintain network security controls
2. Apply secure configurations to all system components
Firewall management, network segmentation, and hardened configurations
Protect account data
3. Protect stored account data
4. Protect cardholder data with strong cryptography during transmission over open, public networks
Encryption, secure remote access, and help removing card data you do not need to keep
Maintain a vulnerability management program
5. Protect all systems and networks from malicious software
6. Develop and maintain secure systems and software
Endpoint protection, patch management, and vulnerability scanning
Implement strong access control measures
7. Restrict access by business need to know
8. Identify users and authenticate access
9. Restrict physical access to cardholder data
Role-based access, MFA, account reviews, and workstation and device security
Regularly monitor and test networks
10. Log and monitor all access to system components and cardholder data
11. Test security of systems and networks regularly
Audit logging, 24/7 monitoring, and regular internal and external vulnerability scans
Maintain an information security policy
12. Support information security with organizational policies and programs
Policies, security awareness training, risk analysis support, and incident response documentation

Version status as of October 2026: PCI DSS v4.0.1, published in June 2024, is the current version. It has no new or deleted requirements compared with v4.0. v4.0 was retired on December 31, 2024, and the 51 requirements that v4.0 marked as future-dated became mandatory on March 31, 2025. We are not aware of a published successor version, and we will update this page if that changes.

How You Take Payments Determines Your Scope

Merchants validate with a Self-Assessment Questionnaire, or SAQ, chosen by how they accept payments. The PCI Council defines the eligibility criteria for each one, and your acquirer or card brand decides which you must complete. This table summarizes the merchant SAQ types. Use it to start a conversation with your acquirer, not to self-select a form.

SAQTypically fitsNotes
ACard-not-present merchants (e-commerce or mail and telephone order) that fully outsource all account data functions to PCI DSS validated third partiesNo electronic storage, processing, or transmission of account data on your systems or premises. Not for face-to-face payments
A-EPE-commerce merchants that partially outsource payment processing, where the website does not receive account data but can affect the security of the payment transaction or pageNo electronic storage, processing, or transmission of account data on your systems
BMerchants that use only imprint machines or standalone dial-out terminalsNo electronic storage of account data. Not for e-commerce
B-IPMerchants that use only standalone, PCI-listed payment terminals with an IP connection to the processorNo electronic storage of account data. Not for e-commerce
C-VTMerchants that key card data one transaction at a time into a validated third-party virtual terminal from an isolated computerNo electronic storage of account data. Not for e-commerce
CMerchants with payment application systems connected to the internetNo electronic storage of account data. Not for e-commerce
P2PEMerchants that use only a validated, PCI-listed point-to-point encryption solutionNo access to clear-text account data and no electronic storage
SPoCMerchants that use a commercial mobile phone or tablet with a secure card reader from a PCI-listed SPoC solutionNo access to clear-text account data and no electronic storage. Not for e-commerce or mail and telephone orders
D (merchant)All merchants that do not fit the other forms, including e-commerce merchants that accept card data on their own website and merchants that store card data electronicallyThe most extensive questionnaire. Many requirements apply

A note on e-commerce: in January 2025 the Council updated SAQ A so that merchants no longer validate requirements 6.4.3 and 11.6.1 on that form. Instead, the eligibility criteria now require the merchant to confirm that its site is not susceptible to attacks from scripts that could affect its e-commerce systems. Confirm with your acquirer how this applies to you.

Reducing Scope Is the Fastest Way to Reduce Work

The cardholder data environment, or CDE, includes the system components, people, and processes that store, process, or transmit cardholder data, plus any system components that do not handle that data but have unrestricted connectivity to those that do. Every system in scope has to meet the requirements that apply, so the fewer there are, the less there is to secure, document, and test.

Stop storing what you do not need

Many businesses keep full card numbers in spreadsheets, email, notes fields, or old scans. Finding and removing that data is often the highest value step, because data you do not store cannot be stolen.

Use validated outsourcing where it fits

Hosted payment pages, validated point-to-point encryption, and tokenization keep card data off your systems. They reduce scope, but they do not remove your obligation. How you integrate them still determines which SAQ applies.

Segment the network

Payment terminals and systems that touch card data should sit on their own network segment with firewall rules that allow only what is needed. Segmentation is the main technical way to keep the rest of your network out of scope, and it has to be tested to count.

Document the flow

A data flow diagram showing how card data enters, moves through, and leaves your environment is the foundation of every assessment. Requirement 12.5.2 expects the scope to be documented and confirmed at least every 12 months and after significant change.

What v4.0 Added That Is Now Mandatory

Many requirements that arrived with v4.0 were future-dated and became mandatory on March 31, 2025. If your last assessment predates that, check these first. This is a selection, not the full list.

RequirementWhat it expectsWhat it means in practice
5.4.1Processes and automated mechanisms to detect and protect personnel against phishingEmail filtering and anti-phishing controls on top of user training
6.4.3Payment page scripts are managed: authorized, with integrity assured and an inventory with written justificationA script inventory for e-commerce payment pages and a way to detect changes
8.3.6Minimum password length of 12 characters, or 8 if the system cannot support 12, with numeric and alphabetic charactersUpdated password policy and system settings
8.4.2Multi-factor authentication for all access into the CDEMFA is required for all access into the CDE, not just remote or administrative access
10.4.1.1Automated mechanisms for audit log reviewsCentralized logging with automated review and alerting rather than manual log reading
11.3.1.2Authenticated internal vulnerability scansInternal scans run with credentials so they see missing patches and misconfigurations
11.6.1A change and tamper detection mechanism for HTTP headers and payment page content as received by the consumer browserMonitoring of what the customer browser actually receives on your payment page
12.3.1A targeted risk analysis for requirements that allow flexible frequencyWritten analysis explaining how often you perform activities such as log reviews and scans
12.6.3.1Security awareness training that covers phishing and social engineeringTraining content updated to include phishing and social engineering

Other requirements also carried the March 31, 2025 date, including items in requirements 3, 4, 7, 8, 9, 10, and 12. Your assessor or acquirer can confirm which apply to your environment.

Testing: Internal Scans, External Scans, and Penetration Tests

Requirement 11 is where many small merchants fall behind, because the evidence has to be dated and repeated.

External vulnerability scans

Requirement 11.3.2 calls for external vulnerability scans at least every three months, performed by a PCI Council Approved Scanning Vendor, with vulnerabilities resolved and passing results documented, and rescans as needed. Whether you need them depends on your SAQ type, so confirm with your acquirer.

Internal vulnerability scans

Internal scans look from inside your network. Requirement 11.3.1.2 requires authenticated scans, which use credentials so the scanner can see missing patches and unsafe settings. We schedule recurring scans through our vulnerability scanning service, track findings to closure, and keep the reports.

Penetration testing

Penetration testing applies to environments where it is required, such as SAQ D merchants and service providers. We help scope and perform tests through our penetration testing service, with the report provided by a third party, coordinate access, and track remediation of what it finds.

The Evidence Your Acquirer or Assessor Will Ask For

EvidenceWhat it shows
Completed SAQ and Attestation of Compliance, or Report on ComplianceThe assessment result for your validation type, signed by an authorized officer
Data flow diagram and network diagramWhere card data enters, moves, and is stored, and where segmentation sits
Inventory of system componentsEvery device, server, application, and service that is in scope
Firewall and configuration standardsHow network controls and system builds are defined and reviewed
Vulnerability scan reportsPassing external ASV scans if required, and internal scan results with remediation records
Access and MFA recordsWho can reach the CDE, how they authenticate, and how access is reviewed and removed
Logs and review recordsLog retention and evidence that logs are reviewed and alerts acted on
Policies and risk analysisWritten security policies, the annual risk assessment, and targeted risk analyses
Training recordsCompletion records for security awareness training including phishing content
Incident response planA written plan with roles and steps, tested at least annually

What’s Included in BlueKey PCI DSS Compliance

  • Laptop showing analytics charts during a technology assessment
    Scoping and gap assessmentWe map where card data flows and which systems are in scope, then identify gaps against the requirements that apply to you.
  • Network switch with blue ethernet cables
    Network security and segmentationManaged firewalls and network segmentation that keep payment systems separate from the rest of your network.
  • Green code on a screen representing encrypted backup data
    EncryptionEncryption for stored data and for card data in transit, plus secure remote access.
  • Laptop keyboard lit in blue representing endpoint detection and response
    Endpoint protectionEndpoint detection and response and anti-malware on systems that touch payment data.
  • Software update in progress on a laptop screen
    Patching and vulnerability scanningManaged patching and regular internal vulnerability scans, with fixes tracked to completion.
  • Smartphone showing a lock screen for account security
    MFA and access controlUnique accounts, role-based access, multi-factor authentication, and prompt removal of access when staff leave.
  • Security operations workstation with multiple monitors showing code
    Logging and monitoringCentral logging and 24/7 monitoring of systems in the payment environment.
  • Binder of written security policies and procedures on a desk
    Policies, training, and evidenceWritten policies, staff security awareness training, and the evidence your acquirer or assessor asks for.

How It Works

  • 1. Scope and assess

    We map how your business takes payments, reduce what is in scope where possible, and identify the questionnaire or report that fits you.

  • 2. Remediate and document

    We implement the technical controls and write the policies and records that support them.

  • 3. Maintain and validate

    We monitor, patch, and scan on a schedule, keep evidence current, and support you through your annual validation.

What You Receive

  • Scope and data flow documentation

    Diagrams and inventories that show what is in the CDE and why.

  • Gap report and remediation plan

    Findings mapped to the requirements that apply, with owners and status.

  • Network segmentation and firewall records

    Rule sets, change records, and segmentation test results where used.

  • Scan reports

    Internal scan results with remediation tracking, and support coordinating external scans.

  • Access and MFA evidence

    Reports showing who has access and how it is authenticated and reviewed.

  • Policy set and risk analysis

    Security policies and the written analyses that PCI DSS expects.

  • Training records

    Awareness training with phishing content and completion reports.

  • Validation support

    Help completing the SAQ and Attestation of Compliance with your acquirer.

Support requests follow our standard help desk response times: 1 business hour for critical issues, 2 hours for high, 4 hours for medium, and 8 hours for low priority requests.

Common Gaps Before a First PCI Assessment

  • Card data stored by accident

    Full card numbers sit in email, spreadsheets, notes fields, or scanned forms.

  • Flat network

    Payment terminals, point of sale systems, and office computers share one network with no segmentation.

  • MFA gaps

    Remote access or administrative accounts into payment systems rely on passwords alone.

  • No dated scan history

    Vulnerability scans are run occasionally and nothing shows quarterly or remediation cadence.

  • Out-of-date scope

    The data flow diagram was drawn once and no one reviewed it when the payment process changed.

  • Policies that no one follows

    Policies exist, but do not match how the business takes payments or handles incidents.

Who It’s For

Merchants and service providers that store, process, or transmit payment card data, including medical practices, dental offices, accounting firms, and other businesses that take cards in person, online, or by phone. Formal validation follows your acquirer and card brand rules. We prepare your environment and evidence and work with whoever validates it. Have an in-house IT team? See co-managed IT.

Pricing

Scoping assessments and remediation projects are quoted individually. Ongoing PCI DSS safeguards can be added to a managed IT or co-managed IT plan.

PCI DSS Compliance FAQ

Is PCI DSS a law?

No. PCI DSS is an industry standard maintained by the PCI Security Standards Council and enforced through the contracts between merchants, acquiring banks, and card brands. Consequences of non-compliance, such as fees or added liability after a breach, depend on your agreements. Some state laws also reference PCI DSS.

Which version of PCI DSS is current?

PCI DSS v4.0.1, published in June 2024, is the current version. It is a limited revision of v4.0 with clarifications and corrections and no new or deleted requirements. v4.0 was retired on December 31, 2024, and the requirements that v4.0 marked as future-dated became mandatory on March 31, 2025.

What is the cardholder data environment?

The cardholder data environment, or CDE, is made up of the system components, people, and processes that store, process, or transmit cardholder data or sensitive authentication data, plus system components that do not handle that data but have unrestricted connectivity to those that do. Reducing and segmenting the CDE is the most effective way to reduce the work of compliance.

Does using Stripe, Square, or another processor remove our PCI obligations?

It can reduce your scope, especially when card data never touches your own systems, but it does not remove the obligation. You may still need to complete a Self-Assessment Questionnaire, and the way you integrate the processor affects which questionnaire applies. Ask your acquirer which validation applies to you.

Which Self-Assessment Questionnaire do we need?

It depends on how you accept payments and what your systems do, not on your size alone. The merchant forms are SAQ A, A-EP, B, B-IP, C-VT, C, P2PE, SPoC, and D, and the PCI Council defines the eligibility criteria for each. We help you confirm the right one with your acquirer and prepare the evidence behind it.

What is an ASV scan?

An ASV scan is an external vulnerability scan performed by an Approved Scanning Vendor, which is a company approved by the PCI Security Standards Council. Requirement 11.3.2 calls for external scans at least every three months, with vulnerabilities resolved and passing results documented. Merchants that qualify for certain SAQs may not need them, so confirm with your acquirer.

What is an Attestation of Compliance?

The Attestation of Compliance, or AOC, is the official PCI Council form used to attest to the results of an assessment, whether you completed a Self-Assessment Questionnaire or a Report on Compliance. Your acquirer or card brand typically asks for it.

Are small businesses exempt from PCI DSS?

No. Every business that accepts card payments is expected to protect card data. Your acquirer and card brands decide how you validate, and smaller merchants usually complete a Self-Assessment Questionnaire.

Who validates PCI DSS compliance?

Smaller merchants usually self-assess with an SAQ and sign an AOC. Larger merchants and service providers may be required to use a Qualified Security Assessor or a qualified internal assessor to produce a Report on Compliance. The PCI Security Standards Council sets the standard but does not certify merchants.

Does BlueKey IT certify that we are PCI compliant?

No. Compliance is validated through your acquirer and card brand process. We implement and document the technical controls, prepare your evidence, and work with your acquirer or assessor.

We only use a standalone card terminal. Do we still have PCI obligations?

Yes, but they may be lighter. Merchants that use only standalone terminals may qualify for SAQ B, B-IP, or P2PE depending on how the terminal connects and whether it uses a validated point-to-point encryption solution. Your network and any devices on it can still affect eligibility, so confirm with your acquirer.

Can you manage our IT and PCI DSS compliance together?

Yes. Many businesses add PCI DSS support to a managed or co-managed IT plan so network security, patching, monitoring, backups, and documentation are handled in one place.

Talk With a Compliance Specialist

Tell us how your business takes payments. We will explain what PCI DSS means for your environment and put together a clear plan and quote.

Related compliance frameworks: CMMC compliance, HIPAA IT compliance, FTC Safeguards Rule compliance, SOC 2 readiness, and ISO 27001 readiness. See also cybersecurity insurance readiness, cybersecurity and compliance, endpoint security, backup and disaster recovery, and Microsoft 365 and Google Workspace.

Last updated: October 2026. Based on PCI DSS v4.0.1 and PCI Security Standards Council guidance.