Which PCI self-assessment questionnaire applies to your store?
The PCI self-assessment questionnaire is the annual form that documents how your store handles card data, and there is more than one version. Which one applies to you depends on how cards reach your system: a counter terminal on a dedicated line, a terminal connected to a wider network, a website, or a phone order typed into a computer. Picking the wrong one is the most common way a small merchant completes compliance paperwork that does not describe their business.
The good news is that the shortest questionnaires exist precisely for the simplest setups, which is what most small stores actually have.
Why are there different versions?
Because the questions that matter change with the architecture. A store whose card data never touches its own computers has a much smaller surface to attest to than one running payment software on a shared network. Rather than asking every merchant every question, the standard splits the form by acceptance method.
The full set and the current versions are published by the PCI Security Standards Council, which is the authority that writes the standard rather than any processor.
What decides which one you get?
Three questions, in this order. Do you take cards in person, online, or both? Does card data ever touch a system you own and administer? And is your payment terminal isolated, or does it share a network with your back office, your surveillance recorder and the staff wifi?
Answer those honestly and the choice usually resolves itself. The trap is the third one: a store that added a wifi-connected terminal to the same router as everything else has quietly changed its answer without anyone updating the paperwork.
That third question deserves a walk around the store rather than a guess. Look at what is physically plugged into the same router or joined to the same wifi as the payment terminal: the office computer, the camera recorder, the music player, the staff phones, the tablet the vendor rep uses. Every one of those shares a network with card acceptance, and every one of them is part of the answer.
Who actually picks it — you or your processor?
Your processor's compliance portal usually proposes one based on what it knows about your account, and that proposal is a starting point rather than a finding. The portal does not know that you started taking phone orders in March, or that the new terminal shares the office router.
You are attesting to the accuracy of the form, which means the choice is yours. If the portal's suggestion does not match how your store actually works, say so and ask for the right one.
What happens if you never complete it?
Most processors apply a monthly non-compliance fee, and many merchants pay it for years without knowing what it is. It is not a fine from the card networks; it is your processor's charge, and completing the questionnaire generally removes it.
The more serious consequence is not the fee. It is that a store which never worked through the questions has never checked the basics — default passwords, who can reach the terminal's network, whether anybody is writing card numbers down — and those are the things that turn an incident into a catastrophe.
How long does it actually take?
For a small store with an isolated terminal and no card data on its own systems, less than an afternoon, and less than that the second year. The questionnaires written for that situation are short by design.
The time goes into the two or three questions where the honest answer is "I do not know" — who can access the router, what the terminal's network is connected to, whether anyone has the credentials that came with the equipment. Those are worth the afternoon on their own merits.
Frequently asked questions
Does using a certified terminal make my store compliant automatically?
No. Good equipment narrows what you have to attest to, sometimes dramatically, but compliance is about your whole environment: who has access, how the network is arranged, what your staff do with card details. Hardware handles one part of it.
Do I need a scan of my network?
That depends on which questionnaire applies. Some acceptance methods require a quarterly external scan by an approved vendor; the simplest in-person setups often do not. This is one of the practical differences between the versions and a good reason to identify yours correctly.
What if my setup changed during the year?
Then your questionnaire should change with it. Adding online ordering, taking phone orders on an office computer, or putting the terminal on the shop wifi are all changes that can move you to a different form. Compliance describes the current year, not the year you first signed up.
Is the questionnaire audited?
For most small merchants it is a self-assessment, which is what the name says: you are attesting rather than being examined. That does not make it ceremonial. An inaccurate attestation is a bad document to be holding if an incident occurs.
Can my processor complete it for me?
They can help, and many provide a guided portal. They cannot know your store's internal arrangements, and the attestation is signed by you. Treat assistance as assistance rather than delegation.
Does accepting only chip and tap reduce the work?
It helps, because card data is encrypted at the reader and never sits in readable form on your systems. Combined with a terminal that does not share a network with your other devices, it puts most small stores in the simplest category available.
Who at my store should own this?
One named person, and for most small stores that is the owner. Compliance questions arrive by email once a year, look like marketing, and get deleted. Somebody has to be the person who recognises the message, and delegating it to whoever opens the mail is how a store ends up paying a monthly fee for six years.