Skip to Contact an Expert Skip to Main Content
Carat logo
  • What we do
    What we do
    Explore the Carat Platform

    Orchestrate payments and commerce experiences.

    Alternative Payments

    Engage more customers and lower the cost of payments.

    Secure Commerce

    Protect your brand.

    Heading
    Control Center

    Take control of your business with data and insights.

    Omnichannel Commerce

    Imagine and realize new customer experiences.

    Payment Engine

    Simplify global payments and offer more choice.

    Payment Optimization

    Grow revenue, lower costs, reduce risk.

    Integration

    Simplify integration and get to market faster.

    Heading
    Local Payments & Wallets

    Unlock revenue in markets that matter to you.

    Stored Value and Loyalty

    Drive customer acquisition, retention, and loyalty.

    Currency Solutions

    Attract more customers and reduce cart abandonment.

    Pay by Bank

    Low-cost ACH payments without chargebacks.

    Payouts / Disbursements

    Deliver fast, more secure, cost-effective payouts.

    Online EBT

    Extend digital checkouts to all of your customers.

    Heading
    Fraud Mitigation

    Help reduce fraud losses and maximize acceptance.

    Encryption & Tokenization

    Help secure your business with multiple layers of end-to-end protection.

    Alternative Credit Data

    Help approve more customers, and manage and reduce risk.

    Driving Growth for Retailers cover image
    Driving Growth for Retailers
    Learn more
    Payment Optimization checklist cover image
    Payment Optimization Checklist
    Learn more
    Payment Optimization checklist cover image
    Payment Optimization Checklist
    Learn more
  • Who we serve
    Who we serve
    Retail
    Grocery
    Technology
    Gaming
    Platforms & Marketplaces
    Franchisors
  • Developers
  • Insights
  • location Country Selector
    Country Selector
    North America (English)
    Asia Pacific (English)
    Europe, Middle East & Africa (English)
    Brazil (Português)
  • Contact Us

What Is PCI Compliance?

Security lock on top of credit card

Whether you’re a small mom and pop shop, a restaurant owner, a nonprofit, or a service provider, all are at risk for having their systems and data compromised. In 2019, the Ponemon Institute reported that the average cost of a data breach is $3.92 million.* Taking the appropriate steps to help minimize your risk could assist with reducing your PCI scope and make it easier to become and remain PCI compliant.

We make cardholder security a top priority by investing in the tools and technology you need to protect your customers’ sensitive data. Our solutions help merchants quickly and easily complete annual assessments and validate PCI compliance.

The Basics of PCI Compliance

Introduced by the major card brands, the Payment Card Industry Security Standards Council (PCI SSC) formulated a set of guidelines to enforce a robust card data security process. Any merchant storing, processing, transmitting, or affecting credit or debit card information must always adhere to the standards and certify compliance annually. Regardless of your payment processing method, PCI compliance is a requirement for every business that accepts credit and debit cards.

PCI compliance is an ongoing data security effort each merchant must follow to help ensure customers’ credit card data is secure. Compliance isn’t just a one-time responsibility, but rather an on-going process that needs to be continually monitored and maintained for safety concerns and vulnerabilities.

How PCI Compliance Works

We offer online tools that can help you achieve PCI compliance anytime. Here are some steps you need to know in order to understand and move through the compliance process.

  1. Identify your PCI compliance level – There are four levels of PCI compliance. Levels are based on credit, debit, and prepaid transaction volume over a 12-month period.
    • Level 4 is for merchants that either process up to 1 million offline sales or fewer than 20,000 e-commerce transactions annually.
    • Level 3 is for e-commerce merchants that process between 20,000 and 1 million credit and debit card transactions annually.
    • Level 2 is for merchants that process between 1 million and 6 million card-based transactions a year. The channel used to capture payment data is irrelevant.
    • Level 1 is for merchants that process more than 6 million card transactions a year — regardless of whether they capture payment information online, over the phone, or in-person (at a checkout counter).
  2. Complete the appropriate PCI Self-Assessment Questionnaire (SAQ) – There are currently eight different SAQ types based on how a merchant processes transactions and handles cardholder data. A merchant can work with his or her payment provider to determine the appropriate SAQ to complete.
  3. Fill out your Attestation of Compliance (AOC) – Once the SAQ is complete, validate your compliance by completing the appropriate attestation form.
  4. Maintain PCI compliance throughout the year with the assistance of a Quality Security Assessor (QSA) and Approved Scanning Vendor (ASV) – These service providers will help you mend the security gaps and fix vulnerabilities.
  5. Submit documents to merchant acquirer/credit card processing company – Include your SAQ, AOC, and any scanning reports.

Solutions That Tie to PCI Compliance

We offer PCI compliance solutions that can help you reduce the time, costs, and resources spent on meeting the requirements. We help take the guesswork out of the process so you can get back to growing your business.

PCI Rapid ComplySM

Our PCI Rapid Comply online tool helps ease the PCI compliance process and reduce the headaches. You’ll benefit from a step-by-step SAQ tool to help complete the questionnaire, an integrated scanning tool for quarterly scans, and comprehensive support available via chat, email and phone to answer any questions you may have.

TransArmor®

Encryption and tokenization work together to protect financial data during transactions. Encryption protects sensitive payment information while it is in transit for authorization by converting the payment card data into code that becomes unreadable to anyone without access permission. Tokenization replaces the cardholder account number by assigning randomly-generated numbers that are meaningless to fraudsters. TransArmor Data Protection tokenizes sensitive cardholder data from the time a consumer makes any form of payment, while data is in transit, and while that data is stored.

Why Do You Need PCI Compliance?

PCI compliance is more than just important – it’s mandatory. In the event of a breach, a non-compliant merchant may be subject to fines from the payment processor, legal fees, card replacement charges, costly forensic audits, brand damage, and termination of their card acceptance agreement. These serious consequences could potentially put a merchant out of business.

Let us help you achieve and maintain PCI compliance and avoid any catastrophic events. Contact us today to learn more about the resources and solutions available to help reduce your scope, minimize risk, and protect your small business or large business.

Latest Ideas & Resources

A man in workshop

PYMNTS: How Embedded Finance Drives Logistics and Wholesale Trade

Looking at mobile screen

PYMNTS: How Embedded Finance Drives Software Publishing Platform innovation

A girl shopping for Sweatshirt

PYMNTS: How Embedded Finance Drives Retail Platform Innovation

Explore more solutions from Carat

  • Local Payments & Wallets
  • Pay by Bank
  • Stored Value and Loyalty
  • Currency Solutions
  • Payouts / Disbursements
  • Online EBT
  • Fraud Mitigation
  • Encryption & Tokenization
  • Alternative Credit Data
  • Facebook
  • Twitter
  • LinkedIn

© 2025 Fiserv, Inc. Fiserv is a registered trademark of Fiserv, Inc. All trademarks referenced here are the property of the respective owners. Merchant services provided by First Data Merchant Services LLC, doing business as Carat, is a registered Independent Sales Organization of Wells Fargo Bank, N.A., Concord, CA; Deutsche Bank AG, New York, NY; PNC Bank N.A., Pittsburgh, PA; MVB Bank, Fairmont, WV; Pathward, N.A., Sioux Falls, SD; and Citizens Bank, N.A., Providence, RI..

  • About Fiserv
  • Investors
  • Careers
  • Payments 101
  • Developers
  • Contact
  • Legal
  • Privacy Notice
  • Site Map

Site Selector