PCI DSS Compliance — the Controls Behind Every Card You Take
If your business accepts credit cards, PCI DSS already applies to you — and version 4.0.1 is now in force, with no “small business” exemption. We implement and operate the technical controls PCI tests, and help you shrink what falls under it in the first place.
The honest part up front: nobody sells a PCI certificate. Small merchants validate through a Self-Assessment Questionnaire with their bank; larger ones through an independent QSA. What we sell is the engineering that makes either one true.
PCI DSS in plain English
The Payment Card Industry Data Security Standard is a set of twelve requirements the card brands (Visa, Mastercard, Amex, Discover) enforce on everyone who handles cardholder data. It is not a law, but it is a contract: your merchant agreement requires it, and a breach without it turns fines and liability toward you. The current version is v4.0.1, and its once-optional requirements are now mandatory.
| How you validate | Who it’s for | What it involves |
|---|---|---|
| Self-Assessment Questionnaire (SAQ) | Most small and mid-sized merchants | You attest to the controls yourself, on a form scoped to how you take payments — often with a passing external scan attached |
| Report on Compliance (QSA) | High-volume merchants and service providers | An independent Qualified Security Assessor examines and documents every control |
What we do, and what we don't. PCI attestation comes from a QSA or your own signed questionnaire, never from your IT provider. CRC Cloud does not issue compliance certifications — we get your IT ready for the people who do. We build and run the controls, find the gaps and close them, and have the evidence organized before the QSA or acquirer arrives, so the review is a formality rather than a discovery exercise. If they flag something, we remediate it fast. Align, implement and prepare — never certify or guarantee.
Either way, the questionnaire is only as true as the controls behind it. Attesting to controls you don’t actually run is how a manageable compliance task becomes an uninsurable breach.
The cheapest card data to protect is the data you never hold
Before we implement a single control, we work to make fewer of them necessary. Every system that touches cardholder data is in scope for PCI; everything properly segmented away is out. Reducing scope is the highest-leverage thing an SMB can do — it shortens your SAQ, lowers your cost, and removes whole categories of risk.
- Tokenization & hosted payment pages — let your processor hold the card number so your systems never do.
- Network segmentation — wall the cardholder-data environment off from the rest of your business so a compromise elsewhere can’t reach it.
- Point-to-point encryption — encrypt card data at the terminal so it’s never readable on your network.
The PCI controls we implement and operate
For the cardholder-data environment that remains in scope, these map directly to the twelve requirements:
Segmentation & Firewalls
Managed firewalls and network segmentation that isolate the cardholder-data environment — Requirements 1 and 2, and the foundation of a small scope.
Anti-Malware & EDR
Endpoint detection and response on every in-scope system, kept current and monitored — Requirement 5, proven rather than assumed.
Patching & Secure Config
Timely patching and hardened, default-free configuration — Requirement 6 and the unglamorous work most breaches exploit.
Access Control & MFA
Least-privilege access and multi-factor authentication into anything near cardholder data — Requirements 7 and 8, now stricter under v4.0.
Logging & Monitoring
Centralized logging with SIEM correlation and retention — Requirement 10, and the evidence that proves the rest of it is actually running.
Scanning & Testing
Internal vulnerability scanning and remediation, coordinated external ASV scans, and managed penetration testing where required — Requirement 11.
Where PCI readiness lives in our plans
The monitoring, SIEM evidence, EDR, and MFA PCI leans on are the substance of Secure IT; Core IT covers the foundations, and managed firewalls and segmentation are quoted with your infrastructure at the free assessment. Already have internal IT? Co-Managed IT adds the depth without replacing your team. See every published rate →
PCI is one lane of a wider practice. See how we approach SOC 2, HIPAA, and the rest on our compliance hub →
PCI DSS, asked and answered
Does PCI DSS apply to my business?
If your business stores, processes, or transmits cardholder data — or can affect its security — PCI DSS applies, no matter how small you are. That covers almost every business that takes a credit card: retail, restaurants, medical and dental offices, professional firms that bill cards, and e-commerce. The level of validation scales with your card volume, but the obligation itself does not have a size exemption.
Is CRC Cloud a PCI QSA, and can you certify us?
No, and be careful with anyone who claims to. A Qualified Security Assessor (QSA) is an independent, PCI-approved firm that validates larger merchants and issues a Report on Compliance; most small merchants instead validate with a Self-Assessment Questionnaire through their bank or processor. Our role is the engineering underneath: we implement and operate the technical controls PCI tests, and get your environment and evidence ready so the SAQ is honest and defensible — not a box-checking exercise.
What is the single best way to lower our PCI cost and risk?
Shrink the scope. Every system that touches cardholder data falls under PCI; every system that does not, and is properly segmented away, falls out. The cheapest card data to protect is the card data you never hold — so we push toward tokenization, processor-hosted or redirect payment pages, and network segmentation that walls the cardholder-data environment off from the rest of your business. Less scope means fewer controls, a shorter SAQ, and less that can go wrong.
Which PCI DSS version applies now?
PCI DSS v4.0.1 is the current standard. Version 4.0 fully replaced 3.2.1, and its future-dated requirements became mandatory on March 31, 2025 — so “we’ll deal with 4.0 later” is no longer an option. v4.0.1 is a maintenance update that fixes wording; the substantive obligations come from 4.0, including stronger authentication, expanded logging, and targeted risk analyses.
Which of the 12 requirements does CRC Cloud actually operate?
The technical core: segmented networks and managed firewalls (Req 1), secure configuration with no vendor defaults (Req 2), anti-malware and EDR (Req 5), patching and secure systems (Req 6), least-privilege access with MFA (Req 7–8), centralized logging and monitoring with SIEM (Req 10), and vulnerability scanning and testing (Req 11). We support the written security policy (Req 12) and coordinate the pieces that require your acquirer or a scanning vendor.
Do you provide the quarterly vulnerability scans PCI requires?
We run internal vulnerability scanning and remediation as part of the plan. PCI also requires external scans by an Approved Scanning Vendor (ASV) for many merchants; we coordinate those, fix what they find, and keep the evidence organized so the passing scans are on file when your bank asks. Where a penetration test is required, we scope and manage it with a qualified tester.
How does this fit with your regular plans?
The controls PCI examines — monitoring, SIEM evidence, EDR, MFA, patching — are the substance of Secure IT; managed firewalls and network segmentation are quoted with your infrastructure at the assessment. The result is that PCI stops being a separate annual panic and becomes a byproduct of how your IT is already run.
Priced openly, like everything else we do. PCI DSS work carries a published uplift of +10% on the per-user plan and per-server management fee — documentation, evidence and audit support are real recurring hours, so we price them instead of hiding them in a quote. Secure IT is the starting point for compliance work — Core IT is not an option for a regulated environment, because the frameworks lean on the monitored layer it adds. On Secure IT that is $275 per user per month — covering scope segmentation, scan coordination and questionnaire support. Backup, private cloud resources and add-ons stay at their flat published rates. See the full compliance uplift table →