forumNew topic

We take in-store POS and online payments — what exactly does PCI DSS compliance want from us?

YYasinNew member
Job title
Technical Service
Joined
Nov 2024
Message
30
#1

We operate in furniture and home textiles; we make sales both in our physical store using POS devices and online via virtual POS on our own e-commerce site. Our total annual card transaction volume sits around 40,000 across both in-store and online.

Recently, the bank and payment processor we applied to for renewing our virtual POS infrastructure asked us for our PCI DSS compliance status and the related self-assessment documents. When I looked it up online, I saw talk of audits costing thousands of dollars licensed QSA auditors, and certification processes; honestly, we got pretty intimidated.

What does this "certificate" actually mean for an SME-sized business like ours? Do we really need to go through an independent audit and get an official certificate, or do we just fill out a form? If we process payments via iFrame or redirect without ever touching card data on our own server what exactly is expected of us?

HHakan A***Member
Job title
Software team lead
Sector
Catering
Organization type
20-person company
Joined
Oct 2023
Message
86
Most Helpful#2

Short answer: With an annual volume of 40,000 transactions, you fall into the Level 4 merchant category; therefore, you do not need to hire an external auditor (QSA), undergo an on-site audit costing thousands of dollars, or obtain an official certificate. What is required of you is to complete a Self-Assessment Questionnaire (SAQ) appropriate for your payment integration method and, if necessary, have an Approved Scanning Vendor (ASV) perform periodic network vulnerability scans.

First off, the word "certificate" is often misused in the industry. Big banks and giant platforms processing millions of transactions a year fall under Level 1 and get formally certified; SMEs, however, prove compliance via an SAQ form and an Attestation of Compliance (AOC). The first thing you need to do is determine whether cardholder data passes through your servers at all.

If your e-commerce site handles payments by redirecting customers to the payment gateway's hosted checkout page or via an iFrame, and the card number never touches a form on your server, you fall under "SAQ A." This form consists of about 20-25 basic questions and is the lightest audit level. You simply confirm that you do not store, process, or transmit card data on your servers.

On the in-store POS side, if you're using standalone terminals provided by the bank that communicate directly over cellular or on an isolated network, the risk is minimal. Ask your bank or payment provider in writing: "We use an iFrame/redirect setup; is completing SAQ A sufficient?" Once they confirm, just fill out the form, sign it, and send it over to close the loop.

PPınar U***MemberCommunity member
Joined
Mar 2023
Message
188
#3

No need to panic at all, the legal jargon in standard bank emails always freaks people out for no reason. As long as you never store the card number, expiry date, or CVV code in your database, your only job is filling out the right form and signing it.

İİlknur Y***MemberCommunity member
Joined
Feb 2023
Message
98
#4

Three things you should check right away: 1) Verify whether card details are entered directly inside the payment provider's iframe/window on your site, 2) Make sure card numbers are properly masked on your physical POS receipts, 3) Request the applicable SAQ template directly from your bank rep.

ZZafer S***Member
Job title
Store associate
Sector
Insurance
Organization type
sole proprietorship
Joined
Dec 2025
Message
67
#5

Some consulting firms out there exploit SMEs' lack of knowledge on this and quote $5,000 to $10,000 as if you actually need a Level 1 audit. Don't fall for it, at your volume you definitely don't need to hire an external audit firm.

SSılaMember
Job title
Marketplace specialist
Organization type
8-person team
Joined
Mar 2024
Message
138
#6

We got the exact same notice when we were doing around 80,000 transactions a year. Since our payment flow was redirect-based, we just filled out SAQ A and sent in our website's SSL and security scan. The whole thing was approved by the bank in 2 days and cost us zero lira.

MMurat K***Member
Job title
SaaS developer
Organization type
boutique agency
Joined
Mar 2024
Message
118

Doki · Log management setup · 2025

#7

if u don't store cards on your server there's nothing to worry about. main thing is keeping the site's admin password strong and the ssl cert up to date. just fill out the form and send it to the bank.

AAyşe Y***MemberCommunity member
Joined
Jun 2024
Message
10
#8

when I first got that email, I thought we were gettinng shut down; the terminology is so intimidating it scares the hell out of you then but once you look into it you realize the bank is basically just asking for your signature to confirm "you're not holding any card info on your end right?"

FFerhat E***Expert
Job title
Production Manager
Sector
Real estate
Organization type
40-person manufacturing company
Joined
Aug 2023
Message
128

Doki · Infrastructure migration · 2024

#9

Please review your technical integration type specified in your merchant agreement with your payment processor. If you collect card data directly via API, you may fall under SAQ A-EP; in that case, the requirements and security controls will be somewhat more stringent.

ZZuhalMember
Job title
Store Manager
Organization type
chain store
Joined
Jul 2024
Message
82
#10

Check in with your software agency and get confirmation on whether your site processes or logs card data in any way. If the answer is no, tell the bank you'll be submitting SAQ A, take 30 minutes to fill it out, and put the matter to rest.

ZZafer D***Member
Job title
Operations manager
Sector
Tourism
Organization type
8-person team
Joined
Nov 2024
Message
15
#11

Good call starting this thread.

BBeyza K***Member
Job title
Store Manager
Sector
Electrical-electronics
Organization type
cooperative
Joined
Dec 2025
Message
165
#12

I feel the same way... like start with a small trial; don't commit to everything at once.

MMerve K***Member
Job title
Supply chain manager
Sector
Retail
Organization type
a company within a holding
Joined
Apr 2025
Message
328

Doki · Infrastructure migration · 2026

#13

I completely agree. btw solutions that work at a small scale collapse when you grow; I learned this late.

If I were you I'd go this route.

NNeşe A***Member
Job title
Content agency
Organization type
early-stage startup
Joined
Mar 2024
Message
106
#14

There's a trap here, let me mention it. Hasty decisions become decisions you have to fix six months later.

This is my opinion, I'm not claiming it's absolute truth.

CCaner E***MemberCommunity member
Joined
Sep 2024
Message
11
#15

Great work. Start with a small trial; don't commit to everything at once.

Everything goes well for the first three months; problems arise in the fourth. If you have questions, write them; I'll answer as best I can.

PPolat A***MemberCommunity member
Joined
Apr 2023
Message
413
#16

ive been down this road let me tell you. most time waste accumulates in tasks waiting for approval.

PPerihan S***MemberCommunity member
Joined
Jul 2023
Message
352
#17

Same here.

TTülay K***Member
Job title
Customer service representative
Sector
Packaging
Organization type
chain store
Joined
Apr 2023
Message
402
#18

I feel the same way. Hasty decisions become decisions you have to fix six months later.

Just leaving this note it might be useful.

YYasemin E***MemberCommunity member
Joined
Mar 2026
Message
2
#19

Saved.

TTülay Y***Veteran
Job title
Warehouse Manager
Sector
Security services
Organization type
a company within a holding
Joined
Aug 2025
Message
12
#20

We need to take it step by step. Most time waste accumulates in tasks waiting for approval.

Correct me if I'm wrong.

Reply