Who needs to comply
Any business that accepts credit or debit cards must comply with PCI DSS, regardless of size. Requirements scale by 'merchant level,' determined largely by annual transaction volume — most small and mid-size merchants fall into the lower-volume levels, which typically allow a self-assessment questionnaire (SAQ) rather than a full on-site audit.
