Free Self-Assessment

PCI DSS Readiness Check

How This Check Helps

Any business that accepts credit or debit cards must meet the PCI Data Security Standard, and several requirements became mandatory on 31 March 2025, including multi-factor authentication into card systems and automated anti-phishing protection. This check turns PCI DSS v4.0.1 into 24 plain-language questions for restaurants, retailers, practices and other merchants.

You see your score instantly and get a prioritized list of gaps. Questions that only apply to online payments or only to card terminals can be marked Not applicable, so the score fits the way you actually take cards.

Customer tapping a contactless card on a countertop payment terminal

Answer 24 Questions

Choose Yes, No, Unknown or Not applicable for each question. It takes about 6 minutes, and you see your score as soon as you finish.

Know Your Scope and Protect Cardholder Data

Do you know which PCI Self-Assessment Questionnaire (SAQ) type fits how your business accepts cards, or have you confirmed it with your processor?

The SAQ you must complete depends on how you accept cards; using the wrong one leaves real gaps unaddressed. PCI DSS Requirement 12.5.1.

Do you avoid storing full card numbers in email, spreadsheets, paper files, or your point-of-sale system unless there is a clear business need?

Card data kept without a documented business need is exposed card data. Keep it only where required and protect it. PCI DSS Requirement 3.2.1.

Do you and your staff never write down, save, or store the 3- or 4-digit security code (CVV) after a transaction is approved?

Storing the security code after authorization is never allowed under any circumstance, even encrypted. PCI DSS Requirement 3.3.1.2.

When card numbers appear on receipts, screens, or reports, are they masked so staff never see more than the first six and last four digits?

Full card numbers should rarely be visible to employees; masking limits exposure if a device or report is lost. PCI DSS Requirement 3.4.1.

Do you keep a current list or diagram of every system, app, and device that stores, processes, or transmits card data?

You cannot secure what you have not identified; this scope inventory is the starting point for every other control. PCI DSS Requirement 12.5.1.

Network and System Security

Are the firewalls, routers, or cloud network settings protecting your payment systems configured to a written standard and reviewed periodically?

Undocumented, ad-hoc network settings are hard to verify and easy to misconfigure without anyone noticing. PCI DSS Requirement 1.2.1.

Have you changed or disabled every default password on your POS systems, routers, Wi-Fi access points, and payment software?

Default vendor passwords are publicly known and are one of the most common ways attackers gain access. PCI DSS Requirement 2.2.2.

Are the computers and networks that process card payments kept separate from general office Wi-Fi, guest Wi-Fi, and other business systems?

Without separation, a breach anywhere on the network can reach payment systems. Not applicable if you use one intentionally flat network. PCI DSS Requirement 1.3.1.

Are critical security patches for your POS software, servers, and payment applications installed within about one month of release?

Attackers look for known, unpatched vulnerabilities; critical security patches must be installed within one month of release. PCI DSS Requirement 6.3.3.

Access Control and Authentication

Does every employee who touches payment systems log in with their own unique username, never a shared or generic login?

Shared logins make it impossible to trace who did what if something goes wrong. PCI DSS Requirement 8.2.1.

Is each employee's access to payment systems and card data limited to only what their specific job requires?

Broad, unnecessary access increases the damage a mistake, stolen password, or insider can cause. PCI DSS Requirement 7.2.1.

Is multi-factor authentication required for any remote or administrative access into systems that store or process card data?

A password alone is not enough; MFA has been mandatory for all such access since March 2025. PCI DSS Requirement 8.4.2.

Are passwords for payment systems at least 12 characters long and unique to each individual user?

Short or shared passwords are easily guessed or cracked; 12 characters is the current minimum standard. PCI DSS Requirement 8.3.6.

Monitoring, Scanning and Testing

Is anti-malware software installed, actively running, and automatically updated on computers and servers that touch card data?

Malware is a common route to stolen card data; anti-malware tools must stay active and current to catch it. PCI DSS Requirements 5.2.1 and 5.3.

Does your email system automatically detect and block phishing emails before they reach your staff?

Automated mechanisms to detect and protect personnel against phishing have been required since 31 March 2025. PCI DSS Requirement 5.4.1.

If any payment system is internet-facing, do you get quarterly external vulnerability scans from a PCI-approved scanning vendor? (N/A if none are internet-facing.)

A passing quarterly scan by an Approved Scanning Vendor is required whenever a system touching card data is reachable from the internet. PCI DSS Requirement 11.3.2.

If your SAQ requires it, has a tester run an external penetration test on your payment environment in the past year? (N/A if not required.)

Penetration testing finds exploitable weaknesses that scans alone can miss; required for higher-risk merchant environments. PCI DSS Requirement 11.4.3.

If customers enter card numbers on your website, do you monitor the payment page's scripts for tampering? (N/A if you take no online payments.)

Malicious scripts injected into checkout pages can silently steal card data as customers type it; required for e-commerce since March 2025. PCI DSS Requirements 6.4.3 and 11.6.1.

Physical Security for Card-Present Payments

Do you keep an up-to-date list of every card-swipe terminal and PIN pad, including location and serial number? (N/A if online-only.)

An accurate device inventory makes it possible to notice if a terminal has been swapped for a tampered one. PCI DSS Requirement 9.5.1.1.

Are card terminals and PIN pads regularly inspected for tampering, unfamiliar attachments, or signs of substitution? (N/A if online-only.)

Skimming devices are often added to legitimate-looking terminals; regular physical inspection catches them before large losses occur. PCI DSS Requirement 9.5.1.

Policy, People and Vendors

Do you have a written information security policy that staff have read and acknowledged?

A documented policy sets expectations and gives staff something concrete to follow and be held to. PCI DSS Requirement 12.1.1.

Do employees receive security awareness training, including phishing and social engineering, at hire and at least once a year?

Untrained staff are the easiest target for attackers; annual refreshers keep awareness current as tactics change. PCI DSS Requirement 12.6.3.1.

Do you keep a list of every vendor that can access card data, with a signed agreement covering their security responsibilities?

Payment processors, POS vendors, and IT providers all extend your risk; agreements clarify who is responsible for what. PCI DSS Requirement 12.8.1.

Do you have a written plan for who to call and what to do first if you suspect a card data breach?

Confusion in the first hours of a breach increases cost and exposure; a plan speeds containment and required notifications. PCI DSS Requirement 12.10.1.

This self-assessment is educational. It is not an audit, a certification, legal advice or an insurance underwriting decision. Your answers stay in your browser and are not sent to Triton unless you contact us.

How Your Score Works

Each Yes earns points, weighted by how much the requirement matters. No and Unknown earn none, because a PCI assessor or your processor treats an unconfirmed control as missing. Not applicable removes a question from your total.

A score of 85 percent or higher, with every high-priority requirement in place, is a strong result. High-priority requirements include never storing the card security code after approval, changing every default password, multi-factor authentication into card systems and passing quarterly external scans where required.

Your official compliance is recorded on the Self-Assessment Questionnaire your processor or bank asks for. This check helps you see where you stand before you complete it.

What Happens After You Finish

A strong score: congratulations. Your PCI DSS controls are where reviewers expect them to be. If you are happy with your current IT provider, they are doing their job. If you are not, Triton would be a good fit: we can take over without losing what you have built.

Gaps or a failing score: set up a meeting with Triton. We walk through your answers, confirm what is really in place and give you a prioritized plan to close the gaps.

PCI DSS Readiness Check: Common Questions

No. Your official record is the Self-Assessment Questionnaire (SAQ) or report your acquiring bank or payment processor requires. This check helps you prepare for it.

It depends on how you accept cards: online, through a standalone terminal, through a point-of-sale system, or a mix. Your processor can confirm the right SAQ, and Triton can help you work it out.

Choose Not applicable for questions that do not fit, such as terminal inspections for an online-only business or website script monitoring for an in-person-only business.

No. Your answers stay in your browser, and nothing is sent to Triton unless you choose to contact us.

The owner, the manager responsible for payments or your IT provider. If you are not sure, choose Unknown: an assessor would treat it the same way.

Set up a meeting with Triton. We walk through your answers, confirm what is really in place and give you a prioritized plan to close the gaps.

How Triton Delivers

The Sophos XDR Mandate

We deploy Sophos Firewalls as the non-negotiable perimeter standard. Any firm operating without synchronized endpoint protection is an insurance liability. Sophos Endpoint (EDR/XDR) is the mandatory internal security layer.

AWS Scalability

We deploy on AWS because downtime is not an option. When a critical system goes down, AWS support responds with enterprise urgency, not a ticket queue. Every dollar of downtime is a dollar your IT provider owes you an answer for.

The AI Autonomous Advantage

Axiom, Triton’s proprietary AI monitoring system, gives our engineers real-time visibility that off-the-shelf tools cannot replicate. It is not for sale, it is how we deliver.

Founded in 2001

25 Years of IT Expertise

Serving New England

5 Regional Offices + Dublin & BVI

Under 10 Minute Response

84th Percentile · MSPbots Verified

Sophos Silver · Microsoft Solutions Partner

Security & Cloud Partners

HIPAA · CMMC · SOC 2 · PCI

Multi-Framework Compliance

Let's Discuss Your IT Needs

Triton Technologies delivers managed IT services, cybersecurity, and IT support for businesses across New England. Contact our team today to start a conversation about your technology environment.

Triton Technologies support engineer at workstation