PCI compliance basics for merchants
What PCI DSS is
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements created by the major card networks to protect cardholder data. Any business that accepts, processes, transmits or stores card data is expected to comply, regardless of which processor or gateway it uses — including Elavon, Stripe, Square or any other provider.
What most small and mid-sized merchants need to do
- Complete a Self-Assessment Questionnaire (SAQ) matching how you process payments.
- Use payment terminals, gateways or software that are themselves PCI-validated.
- Avoid storing full card numbers on your own systems where possible.
- Keep software and payment devices updated with current security patches.
- Train staff on secure handling of card data and phishing awareness.
How it connects to your processor
Most acquirers, including Elavon, charge an annual PCI compliance fee and provide a portal or partner tool to complete the SAQ. If you're comparing providers, ask what's included in that fee and how much support you'll get completing the questionnaire — see our Elavon pricing guide for the specific questions to ask.
Note: This is a general overview, not compliance advice for your specific business. For your official compliance status and requirements, consult your processor and, if needed, a qualified security assessor.