Compayr
Surcharging on Visa, Mastercard and eftpos ends in 12 days — 1 October 2026.See what it costs you
PCI compliance for small business: a plain-English guide
Merchant Basics

PCI compliance for small business: a plain-English guide

Compayr Research · · 6 min

PCI DSS — the Payment Card Industry Data Security Standard — is the set of security rules for anyone who handles card data. It is not an Australian law; it is a standard the card networks require through your merchant agreement. If you accept cards, it applies to you. The reassuring part: most small businesses using a modern provider carry very little of the burden themselves.

What PCI DSS is

PCI DSS is maintained by the PCI Security Standards Council and sets baseline controls for storing, processing and transmitting cardholder data safely. Compliance is a contractual obligation between you, your provider and the card schemes — not a government licence.

Who it applies to

Any business that accepts card payments is in scope. What differs is how much applies to you, and that depends on how you take payments.

Your setup changes how much you have to do

  • Using a provider's terminal or hosted online checkout — the card data flows through their compliant systems, so your scope is usually small.
  • Storing or typing full card numbers yourself — this pulls far more of the standard onto you and is best avoided.

The less card data touches your own systems, the simpler compliance becomes.

The SAQ

Most small merchants demonstrate compliance by completing a Self-Assessment Questionnaire (SAQ). Which SAQ type you complete depends on how you accept payments; your provider or acquiring bank will tell you which one applies and how often.

What it can cost

Some providers include PCI support in their plan; others charge a PCI compliance or non-compliance fee, and the amount varies — check your agreement so it does not surprise you on a statement.

Practical steps

  • Choose a provider that is itself PCI DSS compliant.
  • Never store full card numbers in spreadsheets, emails or notes.
  • Complete the SAQ your provider asks for, and keep it current.
  • Keep terminals, apps and point-of-sale software updated.
  • Limit who can access payment systems and devices.

Choosing a provider? Compare the providers we track by estimated card acceptance cost, with fees shown separately. Compare now →

PCI obligations depend on how your business accepts payments — confirm your exact requirements with your provider or acquiring bank. General information, not financial or legal advice.

See what you'd really pay — compare the major providers we track at your turnover

Compare now

Rates and provider details are indicative, last verified July 2026 — verify with providers. Compayr may earn a referral fee when a merchant switches via our comparison.

Follow us on Google

Add Compayr as a preferred source to see our comparisons higher in your Google results.

Add Compayr as a preferred source