PCI DSS v4.0.1 is the current version. Requirements that were “future-dated” in v4.0 became mandatory on March 31, 2025.
Who PCI DSS applies to
- Restaurants, bars and cafés
- Hotels, lodges, condo associations and rental managers that take cards
- Retail shops, rental shops and outfitters
- Any business that stores, processes or transmits cardholder data
What PCI DSS means for a small business
PCI DSS is a contractual standard enforced through your card processor and acquiring bank, not a law. Small merchants usually validate with a Self-Assessment Questionnaire (SAQ). Which SAQ applies depends on how you take cards, and that choice drives how much of your network is “in scope.”
The single biggest lever is segmentation: keeping card terminals and payment systems separate from guest Wi-Fi, office computers and everything else. Done right, it shrinks your scope, your risk and your paperwork.
PCI DSS requirements and how we meet them
| Requirement | How Vail Valley IT handles it |
|---|---|
| Network security controls and segmentationReq. 1 | Business firewall with payment systems isolated from guest and office networks. Business Network & Wi-Fi Support |
| Secure configurationsReq. 2 | Default passwords changed, unnecessary services disabled, documented configurations. |
| Protect systems from malware and keep them patchedReq. 5–6 | Managed endpoint protection and scheduled patching. Managed IT Services |
| Strong access control and MFAReq. 7–8 | Unique accounts, no shared logins, MFA for administrative and remote access. |
| Vulnerability scans and testingReq. 11 | Internal scans, and quarterly external ASV scans where your SAQ requires them. Penetration Testing & Vulnerability Scanning |
| Security awareness programReq. 12.6 | Annual security awareness training for staff, including phishing and card-skimming awareness. Security Awareness Training |
Common PCI DSS gaps we find in valley businesses
- Card terminals on the same Wi-Fi as guests or staff phones
- Default router or POS passwords
- Shared POS logins among staff
- No record of quarterly scans
- An SAQ answered “yes” to controls that are not actually in place
Evidence to keep on file
- Completed SAQ and attestation of compliance
- Network diagram showing segmentation
- Scan reports (internal and ASV where required)
- Training records
- Configuration and access records
How we get you there
Gap assessment
We compare your current setup to PCI DSS and list what is missing.
Remediation plan
Prioritized fixes with a flat price, in plain language.
Implement & train
Controls, policies and staff training put in place.
Test & document
Scans, pen tests and an evidence file you can hand to an auditor.
Frequently asked questions
Does a small restaurant have to be PCI compliant?
Yes. Every merchant that accepts cards must comply with PCI DSS. Most small merchants validate annually with a Self-Assessment Questionnaire through their processor.
How does guest Wi-Fi affect PCI compliance?
If guest Wi-Fi shares a network with card terminals, the whole network can fall into PCI scope. Proper segmentation keeps guest traffic completely separate and reduces both risk and compliance effort.
brand