forumNew topic

We take in-store POS and online payments — what does PCI DSS 4.0 require from us?

AAhmet B***New memberCommunity member
Joined
May 2026
Message
62
#1

We are a design and furniture store with two branches in Istanbul. We accept payments using bank POS terminals at our physical locations and also sell online via a virtual POS on our open-source e-commerce platform. Our total card volume is around 3,500 transactions per month. Recently, we received an official email from a private bank whose virtual POS we use; it stated that under the transition to PCI DSS 4.0, we need to update our security compliance and fill out a self-assessment questionnaire.

I'm vaguely familiar with PCI DSS, but I never looked into what changed with 4.0 or how it directly affects small businesses like ours. We never store card details on our own servers anyway; payments are processed entirely through the bank's hosted checkout page. Are they going to demand a full server audit now, or do we just sign off on a form? Do we need to hire security consultants from scratch for PCI DSS 4.0, and where should we even start?

BBurcu Ş***Member
Job title
Field sales representative
Sector
Insurance
Organization type
medium-sized business
Joined
Oct 2023
Message
293
#2

When taking payments online, does the customer enter their card details directly into a form on your site, or are they redirected to the bank's 3D Secure hosted payment page? That distinction completely changes which document you need to fill out.

HHilal D***MemberCommunity member
Joined
Dec 2024
Message
166
Most Helpful#3

Short answer: PCI DSS 4.0 is the latest iteration of the global security standard that any business handling card data or touching the payment flow must comply with. For businesses that don't store card details and have modest annual transaction volumes, the primary obligation isn't an expensive audit, but rather completing the correct Self-Assessment Questionnaire (SAQ) and submitting it to your acquiring bank.

You don't need to stress over the standalone bank POS terminals in your physical stores; their security is largely handled by the bank, and your only real duty is to periodically inspect them for physical tampering or theft and log those checks. Your primary surface area of responsibility is your e-commerce site.

Even if you don't store card details, you fall under PCI DSS scope because customers interact with the payment checkout flow on your site. If they are entirely redirected to the bank's payment page, you file SAQ-A; if payments are processed via an embedded iframe or script on your site, you must complete SAQ-A-EP. The biggest change under 4.0 for small e-commerce stores is the strict requirement to audit and verify the integrity of all external scripts running on the payment page (such as live chats, tag managers, and analytics code).

Before committing to costly consulting services, take these steps: 1) Strip out any unnecessary third-party JavaScript from your checkout pages. 2) Enforce multi-factor authentication (2FA) across your admin panels and server logins. 3) Download the SAQ form requested by your bank (most likely SAQ-A), fill out the requirements, sign it, and hand it over to your bank representative.

MMehmet M***Member
Job title
Digital marketing specialist
Sector
Education
Organization type
regional distributor
Joined
Nov 2025
Message
302
#4

Requirements 6.4.3 and 11.6.1 in PCI DSS 4.0 directly target script security on e-commerce sites. Malicious scripts injected into a payment page can harvest card details in the background. You're required to justify and document every single external script running on checkout pages.

HHasan G***Member
Job title
QA Tester
Sector
Printing
Organization type
cooperative
Joined
Mar 2022
Message
8
#5

We got that exact same email two months ago. We process about 40,000 transactions a year. A consulting firm quoted us 35,000 TL. We sat down and spoke directly with the bank, and because we use a redirect payment flow, they clarified that just filling out the SAQ-A form was sufficient. We knocked it out internally in 3 days, submitted it, and it was approved.

UUğur Y***VeteranCommunity member
Joined
Oct 2024
Message
3
#6

no reason to panic if you don't store card numbers in your db but banks blast these emails to everyone automatically for compliance fill out the form properly and send it back and you're done.

Correction: I misremembered the figure, it was a bit lower.

ZZerrin G***MemberCommunity member
Joined
Jul 2023
Message
260
#7

Bank info-sec departments tend to treat every mom-and-pop shop like an e-commerce giant and fire off generic templates. Don't rush out to spend thousands of liras on audits right away; first get written confirmation from your bank rep on whether SAQ-A is enough.

FFiliz P***ExpertCommunity member
Joined
Nov 2024
Message
14
#8

While filling out the form, you might get stuck especially on these 3 points: 1) Complexity and regular rotation of server and admin panel passwords, 2) Having two-factor authentication enabled for admin panel logins, 3) A serial number tracking list for physical POS devices.

İİsmetMember
Job title
Logistics Manager
Joined
Nov 2023
Message
112
#9

First thing tomorrow, put the serial numbers on the bottom of the POS devices at your physical branches into a spreadsheet. Create a simple checklist where you inspect them weekly and sign off that 'no physical tampering' occurred; that directly checks off the audit question.

JJale T***VeteranCommunity member
Joined
Nov 2024
Message
398
#10

Don't let it intimidate you; even though PCI DSS 4.0 looks super complicated at first, the self-assessment guides prepared for small businesses are pretty clear. If you download the SAQ-A document from the official site, translate it to Turkish, and go step by step, you can finish it in half a day.

MMustafa S***Member
Job title
Human Resources Manager
Sector
Jewelry
Organization type
two-branch business
Joined
May 2024
Message
43
#11

ill argue the opposite dont get mad. i mean forgotten test environments are more oftten the entry point than live systems.

if you have quesions write them; I'll answer as best I can.

DDilara B***Member
Job title
Operations manager
Sector
Furniture manufacturing
Organization type
regional distributor
Joined
Jun 2024
Message
1

Doki · Interface design · 2024

#12

Generally correct, but one part is missing. If it's your first time, start small; scaling comes later.

When we decide without measuring, we always end up in the same place. Just leaving this note, it might be useful.

RRabia Ç***Member
Job title
IT manager
Sector
Energy
Organization type
40-person manufacturing company
Joined
Jun 2025
Message
354
#13

I'll argue the opposite, don't get mad. The real issue isn't the number, but what it's based on.

This is my opinion, I'm not claiming it's absolute truth.

YYağmur C***VeteranCommunity member
Joined
May 2023
Message
395
#14

The most overlooked point about PCI DSS 4.0 requirements is this: The answer varies greatly by industry; there is no one-size-fits-all rule.

Correct me if I'm wrong.

HHasan K***MemberCommunity member
Joined
Apr 2023
Message
221
#15

Same here.

AAycan Ö***MemberCommunity member
Joined
Jul 2023
Message
321
#16

Let me summarize the topic, since several different answers were given. The biggest time-waster for us was not knowing who had the final say.

I'm also curious if anyone does it differently.

SSelin Y***Veteran
Job title
Front office accounting
Sector
Real estate
Organization type
120-person company
Joined
Sep 2024
Message
111
#17

I'm a small business let me explain from my side. Any unwritten clause becomes a point of disagreement later as both sides remember it differently.

Correct me if I'm wrong.

EErcan D***Member
Job title
Administrative manager
Sector
Software
Organization type
two-branch business
Joined
Jul 2022
Message
419
#18

Let me share my experience. Forgotten test environments are more often the entry point than live systems.

Proven by experience.

KKübra G***Expert
Job title
IT manager
Sector
Sports and fitness
Organization type
20-person company
Joined
Nov 2025
Message
10
#19

I was thinking the same thing. If you get three different answers on a topic, the question was asked wrong.

KKaanMember
Job title
Product Manager
Joined
May 2024
Message
96
#20

Thanks for writing this, that's the right way. Just because everyone does it doesn't mean it's right.

If it's your first time, start small; scaling comes later. Of course, it varies if your situation is different.

Reply