The 12 checks in this quiz
Answer each one No, In progress, or Yes. Anything not fully in place comes with a concrete next step.
How you take payments
-
Do all card payments go through a fully outsourced hosted payment page or a standalone terminal, so card data never touches your own website or systems?
Move all card handling to a hosted payment page or standalone terminal so card data never enters your systems. This keeps you in the smallest, cheapest PCI scope (SAQ A).
-
Have you confirmed which SAQ (Self-Assessment Questionnaire) type applies to how you accept payments?
Confirm your SAQ type with your payment provider or acquiring bank, it determines exactly which requirements apply to you.
Card data
-
Do you use only PCI-validated payment providers, gateways and terminals?
Use only payment providers and devices on the PCI-validated lists. It shifts most of the heavy lifting to them.
-
Do you avoid storing full card numbers anywhere, no spreadsheets, emails, call recordings, or written notes with card data?
Never store full card numbers. Purge any spreadsheets, emails, recordings or notes that contain them, storing card data hugely expands your obligations and risk.
Systems
-
Is anything that handles payments kept separate from general office systems and consistently patched?
Separate payment systems/terminals from general office IT and keep them patched. It shrinks what is in scope and what an attacker can reach.
-
Is access to anything payment-related limited to specific people and protected with MFA?
Restrict payment-system access to named individuals and require MFA. PCI expects unique IDs and strong authentication.
-
Do you change default passwords on payment terminals and devices and keep their firmware up to date?
Change vendor default passwords and keep terminal firmware current, default credentials are a classic point of compromise.
-
If you take payments online, is your site on HTTPS with a current TLS certificate and a maintained platform?
Serve checkout over HTTPS with a valid certificate and keep your platform and plugins updated. Outdated e-commerce software is heavily targeted for card skimming.
-
Do you run anti-malware / endpoint protection on any systems involved in payments?
Run reputable, updated anti-malware on any system touching payments.
Process
-
Do you complete the PCI self-assessment (SAQ) and any required scan each year?
Complete your SAQ annually and run any quarterly scans your bank requires. PCI is a yearly cycle, not a one-time task.
-
Do staff who handle payments know how to spot card-skimming and handle card data safely?
Train payment-handling staff to inspect terminals for skimmers and follow safe card-handling rules.
-
If a breach involved card data, do you know your obligations to your acquirer and the card brands?
Know your incident obligations to your acquiring bank and the card brands in advance, response timelines are tight.
Stay in the smallest scope you can
The cheapest PCI programme is the one where card data never touches your systems, and the controls around it are simple and well run. We help Canadian merchants keep payments out of scope, close the gaps above, and handle the yearly paperwork so it is not a scramble.