forumNew topic

We take POS and online payments, what is PCI DSS and what are our actual obligations?

AAycan K***Member
Job title
Store Manager
Sector
Catering
Organization type
20-person company
Joined
Mar 2024
Message
132
#1

We have two brick-and-mortar retail stores in Bursa and an online store running on a turnkey platform. In the stores, we use physical POS terminals provided by banks, while on our website, the payment step is completed via an iframe from a licensed third-party payment gateway.

The other day, we got an informational email from the bank we use for our virtual POS. It says that for PCI DSS compliance, we need to fill out a self-assessment questionnaire and upload it to their system, otherwise POS commission rates could increase or the service might be suspended.

This is the first time I'm seeing this term. What exactly is PCI DSS? We do not store card numbers anywhere on our own servers or in our stores; the card details are handled entirely on the payment gateway's screen. Despite that, what does this standard require from an SME like us, and what are we supposed to declare to the bank?

MMelis K***VeteranCommunity member
Joined
Dec 2025
Message
26
Most Helpful#2

Short answer: PCI DSS is the global data security standard that any business accepting card payments must comply with. Even if you do not store card information on your servers, you are not exempt because you facilitate the payment flow, but your obligations are extremely straightforward.

While large enterprises undergo on-site audits with independent assessors, businesses with lower annual transaction volumes like yours self-attest by completing forms called Self-Assessment Questionnaires (SAQ). Because card data never touches your servers, you likely fall under the SAQ-A or SAQ-A-EP category. It's usually enough to just log into your bank's or payment provider's portal and complete this questionnaire online.

As for the POS terminals in your physical store, standard controls apply: 1) Regularly inspect the serial numbers of the POS terminals physically to ensure the devices haven't been tampered with. 2) Keep the internet network the terminals are connected to separate from any guest Wi-Fi. 3) Strictly forbid cashier staff from writing down card information on paper or into any local system.

When filling out the form requested by your bank, you will simply indicate that you do not store card data on your systems. Since your payment provider integration uses an iframe or a redirect, most of the technical questions will be out of scope. No need to panic, this whole thing usually just comes down to a 30-minute form submission.

İİlker C***Member
Job title
Software developer
Sector
Machinery manufacturing
Organization type
sole proprietorship
Joined
Dec 2023
Message
52
#3

The bank just sent a boilerplate automated email. For small businesses that don't store card data, PCI DSS is not a nightmare. What matters is whether the payment form on your site is genuinely an iframe, or if the card data first hits your server before going to the bank. If it's the latter, your obligations become way heavier.

TTolga K***Member
Job title
IT manager
Sector
E-commerce
Organization type
a company within a holding
Joined
Jul 2024
Message
76
#4

Talk to your web developer, confirm whether the input fields where card numbers are entered are loaded directly from the third-party payment provider's servers. If you're using an iframe, you'll fill out SAQ-A, which is only about 20-25 basic operational questions.

LLevent Ş***ExpertCommunity member
Joined
Apr 2025
Message
14
#5

We got the exact same email last year, and our accountant got scared and suggested we hire an external audit consultant for 80,000 TL. Then we called the bank's technical support and they told us 'if you don't store cards on the site, just fill out and submit the SAQ form in the portal and you're good.' Solved it in 15 minutes.

NNuri G***Member
Job title
Purchasing manager
Sector
Agriculture
Organization type
early-stage startup
Joined
Mar 2023
Message
62
#6

If an inspection happens on the store side, keep these two things in mind to avoid penalties: 1) Make sure the middle digits of the card number are masked on receipts printed by the POS terminal. 2) Ensure security cameras aren't pointed directly at the POS PIN pad at the register.

İİlknur Y***ExpertCommunity member
Joined
Oct 2023
Message
19
#7

We use a turnkey e-commerce package too, if we just forward this form to the platform provider instead of asking the bank can they fill it out on our behalf?

CCihanMember
Job title
Credit Consultant
Joined
Jun 2024
Message
92
#8

The self-assessment questionnaire legally must be signed off by an authorized representative of your business. Requesting their own PCI DSS certificate of compliance from your platform provider and submitting it to your bank as supporting documentation will speed up the process.

SSamiNew member
Job title
Music producer
Joined
Sep 2024
Message
44

Doki · Vulnerability scanning · 2023

#9

If you aren't storing card data in any way, nothing to worry about, just submit the SAQ-A form in the portal and move on.

MMert A***ExpertCommunity member
Joined
Jul 2023
Message
231
#10

We experienced almost the exact same thing last year. The biggest time-waster for us was not knowing who had the final say.

An untested backup is not a backup. Proven by experience.

ÖÖmer P***Member
Job title
Technical service technician
Sector
Textile
Organization type
regional distributor
Joined
Dec 2024
Message
42

Doki · Log management setup · 2026

#11

I'll try it.

GGizem M***Member
Job title
Industrial engineer
Organization type
chain store
Joined
Jun 2024
Message
96
#12

You're right.

FFurkan U***Member
Job title
Administrative manager
Sector
Energy
Organization type
40-person manufacturing company
Joined
Jul 2025
Message
84
#13

Let me summarize what's been said so far. When we decide without measuring, we always end up in the same place.

Security isn't absolute; it's about making attacks not worth the effort. If I were you, I'd go this route.

PPolat S***VeteranCommunity member
Joined
Sep 2024
Message
9
#14

The discussion got scattered, let me summarize. Most time waste accumulates in tasks waiting for approval.

Hope this helps.

LLale A***Member
Job title
Production Manager
Sector
Plastic
Organization type
20-person company
Joined
Sep 2025
Message
36

Doki · KVKK compliance consulting · 2024

#15

I don't think this advice fits everyone. like if 2FA is on, a stolen password alone is useless.

I'm also curious if anyone does it differently.

ZZübeyde A***Veteran
Job title
Courier coordinator
Sector
Healthcare services
Organization type
a company within a holding
Joined
Jan 2024
Message
12
#16

Timely topic.

İİbrahim Y***Member
Job title
Marketing manager
Sector
Electrical-electronics
Organization type
20-person company
Joined
Nov 2023
Message
95
#17

I went through the same thing. Don't rely on a single measure; go layer by layer.

If you post the result here, it will help others too.

LLevent U***MemberCommunity member
Joined
Mar 2022
Message
270
#18

I didn't know that. Solutions that work at a small scale collapse when you grow; I learned this late.

Solutions that work at a small scale collapse when you grow; I learned this late. Proven by experience.

FFiliz A***ExpertCommunity member
Joined
May 2025
Message
14
#19

I have no experience with what is the pci dss standard, so I'm asking. If 2FA is on, a stolen password alone is useless.

When you try to change everything at once, nothing settles. Good luck with that.

MMetin P***ExpertCommunity member
Joined
Jun 2023
Message
186
#20

thanks a lot Ill try it today.

Reply