A PCI DSS assessment shows you what a business that accepts credit or debit cards must protect and prove every year to its payment processor. For most small businesses that proof is a Self-Assessment Questionnaire (SAQ). The hard part is not the form. It is knowing which SAQ applies, what the questions are really asking and what to fix before you sign.

Zippie IT, a veteran-owned company in Meridian, Idaho, helps small businesses work through PCI DSS, the Payment Card Industry Data Security Standard, without the jargon.
Start with the right questionnaire
There are several SAQs, and the right one depends on how you take payments, not on how big you are. A business that sends customers to a fully hosted checkout page has a short questionnaire. A business with card terminals on the same network as its office computers has a much longer one. Choosing too narrow a form is a common mistake, and the form is all-or-nothing: if one eligibility condition is not met, you move to a broader SAQ.
We walk through how you take payments, confirm which SAQ fits and check the answer with what your processor expects.
What the PCI DSS assessment includes
- Scoping. Where card data enters, travels and rests, including places people forget such as email, spreadsheets and call recordings.
- A requirement review against the parts of PCI DSS v4.0.1 that apply to your SAQ: network controls, secure settings, account data protection, malware protection, patching, access control, strong sign-in, physical security, logging, testing and security policies.
- A scans and testing check. Whether you need quarterly external vulnerability scans from an Approved Scanning Vendor and penetration tests, and whether they are current.
- A findings list with the fix, who owns it and a target date.
- Draft answers for your SAQ and a written report within about 30 days of getting access.
Fixing what the PCI DSS assessment finds
Remediation is separate from the assessment. Many gaps are routine IT work that our managed IT services already cover, such as patching, firewall settings, multi-factor authentication and logging. Others are about how you take payments, and the cheapest fix is often to change the process so card data never touches your systems. If a vulnerability scan is part of the plan, we can arrange it through an approved vendor.
What this is not
Zippie IT is not a Qualified Security Assessor (QSA) or an Approved Scanning Vendor (ASV). Our PCI DSS assessment is a readiness assessment, not a validation or an Attestation of Compliance. You sign your own SAQ and attestation, and your payment processor or card brand decides what validation it requires. Some larger merchants must have a QSA complete a full Report on Compliance, and we will tell you if that looks likely.
Get started
To book a PCI DSS assessment, tell us how you take payments and where. Contact us or call (208) 810-1795, and we will explain the fixed fee, which depends on how complex your payment setup is. A free network review is a good first step if you also want a look at your wider security.
We use your details to respond to your request. If you want details, see our Privacy Policy.
Frequently asked questions
Does a small business really need to follow PCI DSS?
Yes, if you accept cards. Your merchant agreement with your processor requires it, and the questionnaire you complete depends on how you take payments.
How do I know which SAQ to complete?
It depends on whether you sell online or in person, whether you store card data, and whether a third party handles the payment page or terminal. We walk through it with you and confirm it with your processor.
Does using Square, Stripe or a similar provider make me exempt?
No, but it can make your obligations much smaller. A fully hosted checkout or a validated point-to-point encryption terminal usually qualifies for a short questionnaire.
How often must I complete the SAQ?
Every year, and after significant changes. External vulnerability scans, where your SAQ requires them, must be run every three months.
Can Zippie IT run my PCI vulnerability scans or penetration test?
Required external scans must come from an Approved Scanning Vendor, and we can arrange that. We can also arrange penetration testing, though a firm that is independent of the systems it tests may be required for some SAQs.
Will this make us PCI compliant?
It shows you where you stand and what to fix. You complete and sign your own SAQ once the requirements are met.
