// Free tool

PCI DSS compliance quiz

If your business takes card payments, you have PCI obligations, but how heavy they are depends entirely on how you handle the cards. Answer twelve plain-language questions and get a readiness score plus the gaps to close. Most small businesses that fully outsource payments have the lightest path; this shows whether you are on it.

The 12 checks in this quiz

Answer each one No, In progress, or Yes. Anything not fully in place comes with a concrete next step.

How you take payments

  1. Do all card payments go through a fully outsourced hosted payment page or a standalone terminal, so card data never touches your own website or systems?

    Move all card handling to a hosted payment page or standalone terminal so card data never enters your systems. This keeps you in the smallest, cheapest PCI scope (SAQ A).

  2. Have you confirmed which SAQ (Self-Assessment Questionnaire) type applies to how you accept payments?

    Confirm your SAQ type with your payment provider or acquiring bank, it determines exactly which requirements apply to you.

Card data

  1. Do you use only PCI-validated payment providers, gateways and terminals?

    Use only payment providers and devices on the PCI-validated lists. It shifts most of the heavy lifting to them.

  2. Do you avoid storing full card numbers anywhere, no spreadsheets, emails, call recordings, or written notes with card data?

    Never store full card numbers. Purge any spreadsheets, emails, recordings or notes that contain them, storing card data hugely expands your obligations and risk.

Systems

  1. Is anything that handles payments kept separate from general office systems and consistently patched?

    Separate payment systems/terminals from general office IT and keep them patched. It shrinks what is in scope and what an attacker can reach.

  2. Is access to anything payment-related limited to specific people and protected with MFA?

    Restrict payment-system access to named individuals and require MFA. PCI expects unique IDs and strong authentication.

  3. Do you change default passwords on payment terminals and devices and keep their firmware up to date?

    Change vendor default passwords and keep terminal firmware current, default credentials are a classic point of compromise.

  4. If you take payments online, is your site on HTTPS with a current TLS certificate and a maintained platform?

    Serve checkout over HTTPS with a valid certificate and keep your platform and plugins updated. Outdated e-commerce software is heavily targeted for card skimming.

  5. Do you run anti-malware / endpoint protection on any systems involved in payments?

    Run reputable, updated anti-malware on any system touching payments.

Process

  1. Do you complete the PCI self-assessment (SAQ) and any required scan each year?

    Complete your SAQ annually and run any quarterly scans your bank requires. PCI is a yearly cycle, not a one-time task.

  2. Do staff who handle payments know how to spot card-skimming and handle card data safely?

    Train payment-handling staff to inspect terminals for skimmers and follow safe card-handling rules.

  3. If a breach involved card data, do you know your obligations to your acquirer and the card brands?

    Know your incident obligations to your acquiring bank and the card brands in advance, response timelines are tight.

About this quiz. PCI DSS compliance is formally established through the Self-Assessment Questionnaire (SAQ) that matches how you accept payments, plus any scans your acquiring bank requires, this short quiz is a readiness check, not the SAQ itself and not a compliance determination. The single biggest factor is whether card data ever touches your own systems: fully outsourced/hosted payments keep you in the smallest scope. Everything here runs in your browser and is not saved. Confirm your exact requirements with your payment provider or acquiring bank.
// What this means for your business

Stay in the smallest scope you can

The cheapest PCI programme is the one where card data never touches your systems, and the controls around it are simple and well run. We help Canadian merchants keep payments out of scope, close the gaps above, and handle the yearly paperwork so it is not a scramble.