
PCI compliance for small business: a plain-English guide
Compayr Research · · 6 min
PCI DSS — the Payment Card Industry Data Security Standard — is the set of security rules for anyone who handles card data. It is not an Australian law; it is a standard the card networks require through your merchant agreement. If you accept cards, it applies to you. The reassuring part: most small businesses using a modern provider carry very little of the burden themselves.
What PCI DSS is
PCI DSS is maintained by the PCI Security Standards Council and sets baseline controls for storing, processing and transmitting cardholder data safely. Compliance is a contractual obligation between you, your provider and the card schemes — not a government licence.
Who it applies to
Any business that accepts card payments is in scope. What differs is how much applies to you, and that depends on how you take payments.
Your setup changes how much you have to do
- Using a provider's terminal or hosted online checkout — the card data flows through their compliant systems, so your scope is usually small.
- Storing or typing full card numbers yourself — this pulls far more of the standard onto you and is best avoided.
The less card data touches your own systems, the simpler compliance becomes.
The SAQ
Most small merchants demonstrate compliance by completing a Self-Assessment Questionnaire (SAQ). Which SAQ type you complete depends on how you accept payments; your provider or acquiring bank will tell you which one applies and how often.
What it can cost
Some providers include PCI support in their plan; others charge a PCI compliance or non-compliance fee, and the amount varies — check your agreement so it does not surprise you on a statement.
Practical steps
- Choose a provider that is itself PCI DSS compliant.
- Never store full card numbers in spreadsheets, emails or notes.
- Complete the SAQ your provider asks for, and keep it current.
- Keep terminals, apps and point-of-sale software updated.
- Limit who can access payment systems and devices.
Choosing a provider? Compare the providers we track by estimated card acceptance cost, with fees shown separately. Compare now →
PCI obligations depend on how your business accepts payments — confirm your exact requirements with your provider or acquiring bank. General information, not financial or legal advice.
See what you'd really pay — compare the major providers we track at your turnover
Compare nowRates and provider details are indicative, last verified July 2026 — verify with providers. Compayr may earn a referral fee when a merchant switches via our comparison.
Follow us on Google
Add Compayr as a preferred source to see our comparisons higher in your Google results.
Add Compayr as a preferred sourceMore in Merchant Basics

Do you really know what you pay? How to read your merchant statement before October
Ask ten merchants their card acceptance rate and eight will quote the headline number from their signup letter — which is almost never what they actually pay. Merchant statements bury the truth in fee codes, blended tiers and GST lines. Before October's reforms, you need three numbers off that statement. Here's how to find them in fifteen minutes.

Least-cost routing (merchant choice routing): how to cut debit card costs
Least-cost routing (also called merchant choice routing) sends contactless debit taps down the cheaper network. After the October 2026 surcharge ban it becomes one of the few levers left to lower what you pay — here is how it works and how to switch it on.

Tap to Pay on iPhone and Android: taking card payments without a terminal
Tap to Pay turns a phone into a contactless card reader — no separate terminal, no hardware to buy. Here is how it works in Australia, which providers offer it, what it costs, and where it fits.
