Request a quote
Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglishESEspañolFRFrançaisTRTürkçe
Close-up of two monitors showing log lines and coloured terminal output

PCI DSS is about your network, not about your card reader

Most business owners think PCI DSS is something for the bank or for the device on the counter. It is not: the standard applies to anyone who takes card payments, and most of it consists of ordinary IT requirements. Separation on the network, admin access, patching, logging. This page says what the standard asks of your network, how you save yourself work by keeping the scope small, and what we do and do not do in it.

What it is

Four things that are often misunderstood

They explain why the standard feels bigger than it needs to be.

  • It applies to the small shop tooThere is no lower limit. Anyone taking card payments falls under it, from the chain with two hundred branches to the restaurant with one card reader. What differs is not whether it applies but how much you have to demonstrate.
  • It is all about the scopeThe standard covers everything that touches card data or can reach it. That last part is the trap: a till network that also carries the guest network, the cameras and the advertising screen drags the whole lot into scope. The smaller you make that scope, the less there is to do.
  • Most of the requirements are IT requirementsSegmentation, a firewall that is actually closed, patching, no default passwords, named admin access with multi-factor authentication, and logging you can look back through. That is not payment technology, that is the work you ought to be doing anyway.
  • You usually fill it in yourselfFor most businesses it runs through a questionnaire you complete and sign yourself. That is convenient and it is also the risk: an over-optimistic questionnaire is invisible to everyone until something happens and somebody looks back.
On the network

Four things the questionnaire demands

In this order, because the first one makes the other three smaller.

The till apart from the rest

Payment traffic does not belong on the same network as the guest network, the cameras, the advertising screen and the office workplaces. This is the most important measure and at the same time the one most often skipped, because one flat network simply works.

Named admin access

No shared administrator accounts and no default password on the router, the switch or the camera system. Administration by name, with multi-factor authentication, and access that disappears when somebody leaves.

Keeping up with what is attached

Patching whatever sits on that network, including the devices nobody thinks about: the self-checkout kiosk, the receipt printer, the clock on the wall. A device that no longer gets updates belongs off that network or behind something.

Being able to look back

Logging that is retained and that somebody looks at. Without it there is no answer after an incident to the only question that gets asked, namely what exactly happened and when.

What we do

The network and the workplace, and where it stops

The boundary is sharper here than on most pages, because the rest of this world is a licence and not a service.

  • Measuring what is really attachedIn an existing shop or venue the first answer is almost never the right one: more turns out to hang off the till network than anybody thought. We map what is there and what talks to what, and from that follows how large the scope currently is.
  • Separating and closing downPayment traffic apart, the guest network apart, the cameras and the screens apart, and a record of what may pass between those parts. That is network work and it is exactly what we already do in hospitality and retail.
  • Keeping it up after handoverPatching, logging, access that really goes when somebody leaves, and a yearly check that the separation is still standing. A standard is not a project with an end date, and the questionnaire comes round every year.
  • Where our boundary sitsWe are not a QSA and we certify nobody: an audit that requires a qualified assessor is done by that assessor. We do not process payments and we do not supply card readers; those come from your payment provider, as does the encryption in the terminal that makes your scope smaller. You sign the questionnaire yourself. We make sure that what you put on it about the network is true.

What goes with this

The measures PCI asks for are largely already somewhere else on this site.

Frequently asked

Questions we get about this

The ones that come up most, answered briefly.

Does PCI DSS apply to us too, with one card reader?

Yes. There is no lower limit: anyone taking card payments falls under it. What differs is not whether it applies but how much you have to demonstrate, and that depends on how large your scope is. One flat network carrying the till, the guest network and the cameras makes that scope as large as your whole business.

What is the first thing we should do?

Separate the payment traffic from the rest. That is the most important measure and the one most often skipped, because one flat network simply works. After that the rest gets smaller: fewer devices in scope means less patching, less logging and less to demonstrate.

Can you certify us for PCI DSS?

No. We are not a QSA and we certify nobody; an audit that requires a qualified assessor is done by that assessor. We also do not process payments and do not supply card readers. What we do is the network and the workplace: separating, closing down, patching, logging and keeping it up. You sign the questionnaire yourself.

First know how large your scope is

Say how many sites are involved and who your payment provider is. We check what hangs off the till network and say what needs separating before you fill in the questionnaire.

Practical IT knowledge in your inbox

New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.

We use your address for the newsletter only. Privacy policy.

Request a quote Call