
If you take card payments, you are in scope for PCI DSS. Most small businesses either have no idea, or have filled in a self assessment questionnaire their payment provider sent, picked the wrong one, and answered it optimistically.
I am a qualified PCI implementer. I can tell you which questionnaire actually applies to how you take payments, which is the single decision that determines whether this is an afternoon of work or a project.
Then the practical part: keeping your checkout in a form that keeps you out of the hardest scope, what to do if staff take card details over the phone, why card numbers should never sit in email or a CRM, and what your provider is and is not doing for you.
Useful for online sellers, anyone taking payments over the phone, and businesses whose acquirer has started asking for a compliance certificate.
Take the first step to successfully starting and growing your business.