PCI DSS applies to organisations involved in storing, processing or transmitting cardholder data, and small merchants are not exempt merely because transaction volumes are low. Outsourcing checkout to a payment provider can reduce the merchant's technical scope substantially, but the business still needs to understand and validate the responsibilities that remain.
PCI DSS applies regardless of merchant size
The PCI Security Standards Council says PCI DSS is intended for all entities involved in payment processing, including merchants regardless of size or transaction volume. Small businesses often have simpler payment environments, which can reduce compliance effort, but the standard itself does not disappear because the merchant takes only a few card payments.
The exact validation requirement is normally determined by the merchant's acquirer or payment brand. Ask the acquiring provider which Self-Assessment Questionnaire or other evidence is required rather than relying on a generic internet checklist.
PCI DSS v4.0.1 is the current supported standard
PCI SSC published PCI DSS v4.0.1 as a limited revision of version 4.0 and retired v4.0 at the end of 2024. The future-dated requirements in the v4 framework became effective in 2025. In 2026 the Council is already gathering feedback for the next evolution, but v4.0.1 remains the current published standard.
Do not keep using an old SAQ downloaded years ago. Validation forms and guidance change. Store the version and completion date with the compliance file so the merchant can prove which standard it used for that year's assessment.
Using a hosted payment provider reduces scope but does not erase merchant responsibility
PCI SSC says a merchant that outsources all card-data processing still retains responsibilities. It needs to ensure that third-party providers are PCI DSS compliant for the services supplied, keep written agreements covering provider responsibilities, monitor provider compliance and understand shared responsibilities.
This is important for merchants that say "we never touch card numbers". The website, payment link, call-centre process or third-party integration can still affect payment security. Keep current Attestations of Compliance or other provider evidence required by the acquirer.
SAQ A ecommerce merchants still have website security obligations
PCI SSC's current SAQ A guidance applies to merchants whose electronic account-data functions are fully outsourced. Even then, ecommerce merchants need to confirm that their webpage is not susceptible to script attacks that could affect the payment process.
PCI SSC also clarified in June 2026 that SAQ A ecommerce webpages can still require external vulnerability scanning by an Approved Scanning Vendor, including sites that redirect to a third-party payment service provider or embed that provider's iframe. Outsourcing checkout does not make the merchant website irrelevant.
Keep an annual compliance file instead of treating the SAQ as a one-day exercise
Maintain the completed SAQ, provider compliance documents, scan reports where required, incident contacts and a list of systems that can affect payment pages. Record material changes such as a new gateway, ecommerce plugin, call-centre tool or terminal provider.
Review the environment after changes rather than waiting for the next annual questionnaire. A new marketing script on checkout can create payment-page risk even though the card form itself remains hosted by a compliant provider.
PCI compliance does not replace incident response
If card data may have been compromised, contact the acquirer and payment provider using their incident process. Preserve logs and do not delete suspicious code before evidence is collected. Payment brands can impose forensic or remediation requirements after a breach.
PCI DSS is a baseline control framework, not a guarantee that fraud cannot occur. The merchant should combine compliance with patching, access control, phishing protection, payment-page monitoring and staff procedures that reduce the chance of card data being exposed.
Create a simple PCI responsibility matrix. List the website platform, payment page, card terminal, virtual terminal, call recording, service providers and staff roles, then identify which party protects each component. Small businesses often fail not because the technology is sophisticated, but because everyone assumes the payment provider is responsible for every part of the customer journey.
Review third-party providers at least annually and whenever a major service changes. If the ecommerce platform replaces the gateway, the business adds telephone ordering or staff start using a new mobile terminal, the applicable SAQ can change. Compliance should follow the actual payment environment rather than the questionnaire the merchant completed when it first opened the account.
Keep evidence of annual staff awareness for employees who handle terminals, virtual payments or ecommerce administration. PCI compliance is not only technical. Employees who recognise phishing, suspicious terminal substitution and unsafe storage practices reduce the risk that a compliant payment platform is undermined by day-to-day behaviour.
Editorial Verdict
Small merchants are not outside PCI DSS. The practical objective is to minimise scope by using reputable hosted payment services while understanding the controls that remain with the merchant.
Use the current v4.0.1 materials, follow the acquirer's validation requirements and keep third-party compliance evidence current. Outsourcing payment processing is valuable, but responsibility for the merchant's own website and provider governance does not vanish.
Sources
- PCI SSC, PCI DSS v4.0.1 publication: https://blog.pcisecuritystandards.org/just-published-pci-dss-v4-0-1
- PCI SSC, small merchant PCI DSS FAQ: https://www.pcisecuritystandards.org/faqs/do-small-merchants-with-limited-transaction-volumes-need-comply-with-pci-dss/
- PCI SSC, outsourced payment processing FAQ: https://www.pcisecuritystandards.org/faqs/does-pci-dss-apply-to-merchants-who-outsource-all-payment-processing-operations-and-never-store-process-or-transmit-cardholder-data/
- PCI SSC, SAQ A scanning FAQ: https://www.pcisecuritystandards.org/faqs/1604/