PCI DSS for small merchants: what you really have to do – and what not
PCI DSS applies to every merchant that accepts credit cards, including the kiosk with a single terminal. For small businesses this usually means filling in a short questionnaire once a year. Forget it, and some providers charge a penalty fee every month.
The short answer
Yes, PCI DSS affects even the smallest merchant as soon as they accept credit cards. For a business with one approved terminal and no stored card data, in practice this means: fill in a self-assessment once a year, keep an eye on the devices and hand the proof to your provider on time.
PCI DSS is not a law but the security standard of the card schemes, published by the PCI Security Standards Council. It applies through your acceptance contract. The current version is 4.0.1; the requirements of version 4 that were initially only best practice have been mandatory since 31 March 2025 (PCI SSC, accessed 3 October 2026). PAYONE puts the basic rule without a loophole: responsibility lies “with every merchant that accepts credit card payments” (PAYONE, accessed 3 October 2026).
Which level applies to me?
The card schemes divide merchants into four levels by number of transactions. The overview below comes from Stripe’s PCI guide, accessed 3 October 2026; the exact thresholds are set by the card brands, not by the payment provider.
| Level | Card payments per year | Proof |
|---|---|---|
| Level 1 | over 6m Visa/Mastercard, or after a data breach | assessment report by an external assessor (QSA) |
| Level 2 | 1m to 6m | self-assessment or assessment report |
| Level 3 | 20,000 to 1m online | self-assessment, depending on provider |
| Level 4 | under 20,000 online or up to 1m in total | self-assessment, depending on provider |
Almost every shop, practice and trade business is Level 4. A café taking 40 credit card payments a day comes to around 14,600 a year. That is a long way from any obligation to hire an assessor.
Which questionnaire fits my terminal?
The self-assessment is called an SAQ (Self-Assessment Questionnaire). There are several, and which one applies depends not on your size but on how card data flows through your business. The criteria are set out in the PCI SSC’s SAQ guidelines, version 4.0.1 revision 1 of April 2025 (PCI SSC Document Library):
| Your situation | Questionnaire |
|---|---|
| standalone PCI-approved terminal with an IP connection (LAN, Wi-Fi, mobile), no stored card data | SAQ B-IP |
| old dial-up connection (phone line) or manual imprinter | SAQ B |
| listed point-to-point encryption (P2PE), no access to clear-text card data | SAQ P2PE |
| smartphone or tablet with a listed card reader solution | SAQ SPoC |
| till or payment software connected to the internet, terminal attached to it | SAQ C |
| typing card data by hand into a virtual terminal in the browser | SAQ C-VT |
| online shop with the provider’s hosted payment page or iFrame | SAQ A |
If you take payments in the shop and also sell online, you need the right questionnaire for each channel. How the shop integration determines the questionnaire is covered in the article on online payment integration routes.
The PCI SSC itself recommends checking with your acquirer before filling anything in, to confirm whether and which questionnaire it expects. This is not a formality: the acquirer is the party that collects the proof and charges the fee if it is missing.
What does ignoring PCI cost?
This is where it gets concrete. In its price list for Germany dated 1 May 2026, Nexi lists a “PCI DSS non-compliance penalty fee” of 20 euros a month, which is waived once PCI compliance is proven. The same list shows 5 euros a month for the “Nexi Security Center” and a flat 1,500 euros per account data compromise incident, i.e. per data breach (Nexi, PDF, accessed 3 October 2026). PAYONE gives no amounts but lists penalty payments by the card schemes, higher transaction fees and termination of the acceptance contract as possible consequences.
Worked example with a 25-euro average ticket: a kiosk takes 80 credit card payments a month, i.e. 2,000 euros of credit card turnover. The 20-euro penalty fee then equals 25 cents per payment, or a full extra percentage point on that turnover. With an assumed merchant service charge of 1.5 per cent, the forgotten self-assessment makes credit card acceptance two-thirds more expensive. Over a year that is 240 euros for one questionnaire. The figures are chosen freely; the 20 euros come from the Nexi price list, and in other contracts the item may have a different name or not exist at all. Search your price list for “PCI”, “Noncompliance” or “Sicherheit” (security).
What the self-assessment does not replace
Three points are the ones I see misjudged most often in practice.
First, the device. The terminal questionnaires assume a PCI-approved device. For terminals whose approval has expired, the PCI SSC says the merchant should check with the acquirer whether the questionnaire still applies. If you keep running an old purchased device, have its approval checked; more on this in the article on terminal types.
Second, paper. Card numbers on notes, in Excel lists or in e-mails for later charges are stored card data. They take you out of the simple questionnaires.
Third, the network. Running the terminal, the till and the guest Wi-Fi on one network makes the proof needlessly hard. A separate network or a mobile connection for the terminal is the simplest separation.
And most importantly: no provider can exempt you from PCI. A terminal with encryption makes the scope small. Anyone promising “PCI-free” is promising something that does not exist.
What you should do now
- Search your price list and contract for “PCI” and “Noncompliance” and check whether a monthly amount is listed.
- Ask in the merchant portal or your provider whether a PCI proof is outstanding for your contract and which SAQ is required.
- Establish how your terminal is connected (standalone via IP, via the till, P2PE, smartphone) and complete the matching questionnaire.
- Destroy notes, lists and e-mails containing full card numbers and stop the practice.
- Put the terminal on its own network or on mobile data, separate from the guest Wi-Fi.
- Have the approval of older purchased devices checked.
- Put a fixed date in the calendar each year for renewal; the self-assessment is submitted annually (as Stripe also describes in its PCI guide).
How the penalty fee adds to the total cost alongside the merchant service charge, rental and transaction fee is shown in the article on the building blocks of card fees.
FAQ
As a small merchant with a card terminal, do I have to be PCI compliant?
Yes. PCI DSS applies to every merchant that accepts credit cards, regardless of size. With a single approved terminal and no stored card data, the effort is usually limited to an annual self-assessment questionnaire (SAQ).
Which PCI questionnaire do I need for a card terminal?
That depends on the device and how it is connected. Under the PCI Security Standards Council’s guidelines, a standalone PCI-approved terminal with an IP connection falls under SAQ B-IP, a listed point-to-point encryption solution under SAQ P2PE, and a card reader on a smartphone under SAQ SPoC. Your acquirer confirms which one applies to you.
What happens if I do not submit proof of PCI compliance?
Your contract decides. According to its price list dated 1 May 2026, Nexi charges a PCI DSS non-compliance penalty fee of 20 euros a month, which is waived once compliance is proven. PAYONE lists penalty payments, higher transaction fees and even termination of the acceptance contract as possible consequences.
Does a terminal from my provider exempt me from PCI?
No. An approved terminal with encryption makes your assessment scope small, but not zero. PAYONE states explicitly that responsibility for compliance lies with every merchant that accepts credit cards.
General information, not legal advice for individual cases. As of: 03 October 2026.