PCI DSS 4.0.1: What Small Merchants Still Need to Fix in 2026

PCI DSS 4.0.1: What Small Merchants Still Need to Fix in 2026

October 05, 2026•9 min read

PCI DSS compliance is not only a concern for large retailers and major e-commerce companies. Small merchants that accept payment cards also need to protect payment account data, regardless of their transaction volume.

For small businesses, the challenge in 2026 is often not understanding that PCI DSS matters. The bigger challenge is knowing what still needs to be fixed, documented, monitored, or verified under PCI DSS 4.0.1.

PCI DSS 4.0.1 is the updated version of the Payment Card Industry Data Security Standard. Several requirements that were previously future-dated became effective on March 31, 2025.

That means merchants entering or maintaining compliance in 2026 need to account for those requirements rather than treating them as optional future changes.

What Is PCI DSS 4.0.1?

PCI DSS 4.0.1 is a security standard designed to help protect payment account data.

It applies to organizations involved in storing, processing, or transmitting payment card information, as well as environments that can affect the security of payment account data.

The specific requirements that apply to a merchant depend on its payment environment.

For example, a business that completely outsources payment processing may have a different PCI DSS scope than a business that stores card information or operates its own payment systems.

This is why small merchants should avoid assuming that another company's PCI setup automatically applies to their own business.

7 PCI DSS 4.0.1 Areas Small Merchants Should Check in 2026

1. Review Your PCI DSS Scope

One of the first things a small merchant should review is what systems, websites, devices, applications, and service providers are actually in scope.

Your payment environment may include more than your credit card terminal.

Depending on how you accept payments, your scope could involve:

  • Point-of-sale systems

  • E-commerce websites

  • Payment pages

  • Virtual terminals

  • Payment applications

  • Cloud services

  • Employee computers

  • Networks

  • Third-party payment processors

  • Service providers with access to payment-related systems

Outsourcing payment processing does not automatically eliminate a merchant's PCI DSS responsibilities. Merchants still need to understand their responsibilities and ensure that third-party providers are appropriately compliant.

What to fix in 2026

Review your current payment flow and document:

Customer → Website or POS → Payment Processor → Acquirer

Then determine which systems touch, transmit, or can affect payment account data.

If your payment environment has changed since your last assessment, your PCI DSS scope may need to be reviewed again.

2. Don't Assume Your Payment Processor Handles Everything

A common misconception among small businesses is:

"We use a PCI-compliant payment processor, so we're automatically PCI compliant."

That's not necessarily the case.

When payment processing is outsourced, merchants still have responsibilities.

Small businesses should understand which responsibilities belong to the payment processor and which remain with the merchant.

What to fix in 2026

Create a current list of your payment-related service providers.

For each provider, document:

  • Company name

  • Services provided

  • PCI DSS responsibilities

  • Compliance status

  • Contract or agreement

  • Date compliance was last verified

  • Your responsibilities versus the provider's responsibilities

Small businesses often work with multiple vendors, including payment processors, website providers, POS vendors, SaaS platforms, and IT providers.

Knowing what each provider does and how it affects your payment environment can help you better understand your PCI DSS responsibilities.

3. Check Your Website and E-Commerce Payment Setup

For online merchants, website security remains an important PCI DSS consideration in 2026.

This is especially important if your website:

  • Hosts payment forms

  • Redirects customers to a payment processor

  • Uses embedded payment forms

  • Uses payment-related scripts

  • Connects to third-party payment services

PCI DSS 4.0.1 includes requirements addressing security risks associated with e-commerce payment pages and scripts.

What to fix in 2026

Review the scripts and third-party services running on payment-related pages.

Ask:

  • Who controls the payment page?

  • Are third-party scripts being used?

  • Can those scripts affect the payment process?

  • Is the payment processor providing protections against script-based attacks?

  • Does your current implementation still qualify for the SAQ you are using?

Don't assume that using an embedded payment processor automatically removes website security responsibilities.

4. Don't Forget Vulnerability Scanning

Another area small e-commerce merchants should review is vulnerability scanning.

Depending on the merchant's environment and applicable PCI DSS requirements, external vulnerability scanning may be required.

If your environment requires ASV scanning, the scanning should be performed by a PCI SSC Approved Scanning Vendor.

What to fix in 2026

If your environment requires vulnerability scanning, verify that:

  • Your scans are being performed by an approved vendor.

  • The correct external systems are included.

  • Scans are completed according to the required schedule.

  • Failed scans are remediated.

  • Evidence of passing scans is retained.

Outsourcing payment processing does not automatically mean your website is outside the scope of PCI DSS.

5. Review User Access and Authentication

PCI DSS 4.0.1 also places significant emphasis on access control and authentication.

Small businesses should review who has access to:

  • POS systems

  • Payment platforms

  • Administrative dashboards

  • E-commerce websites

  • Payment applications

  • Cloud systems

  • Business networks

What to fix in 2026

Review employee and administrator accounts.

Remove accounts that are no longer needed.

Make sure users have individual credentials rather than sharing a single login.

Also review authentication requirements applicable to your environment, including password policies and multi-factor authentication where required.

The goal is simple: people should only have the access they need to perform their job.

6. Keep Security Policies and Documentation Current

PCI DSS compliance isn't only about technology.

Documentation matters too.

Small businesses should maintain policies and procedures covering areas such as:

  • Information security

  • Passwords and authentication

  • Access control

  • Incident response

  • Payment data handling

  • Employee responsibilities

  • Third-party service providers

  • Security awareness training

  • Data retention and disposal

A policy that was created several years ago may no longer reflect how your business actually operates.

What to fix in 2026

Review your documentation and ask:

"Does this policy describe what we actually do today?"

If the answer is no, update it.

Compliance documentation should reflect your real environment rather than simply existing for an audit.

7. Make Sure You Are Completing the Correct SAQ

Small merchants may use a Self-Assessment Questionnaire, or SAQ, when eligible.

However, there isn't one universal SAQ for every small business.

PCI SSC provides different SAQs based on the merchant's payment environment.

For example, SAQ A applies to certain merchants that completely outsource applicable cardholder-data functions, while SAQ A-EP applies to certain e-commerce merchants whose websites can affect the security of payment transactions.

What to fix in 2026

Don't choose an SAQ simply because another business uses it.

Review the eligibility criteria for your specific payment setup.

If you're unsure, consult your acquiring bank, payment brand, qualified security professional, or PCI compliance provider.

What Changed After March 31, 2025?

One important reason merchants should revisit PCI DSS in 2026 is that several future-dated PCI DSS v4.x requirements became effective after March 31, 2025.

These include requirements related to:

  • Automated technical solutions for detecting and preventing certain web-based attacks against public-facing web applications

  • Authentication for certain customer user access

  • Detection, alerting, and prompt response to failures of critical security control systems

For merchants still relying on older PCI DSS checklists, this is an important area to review.

A Simple PCI DSS 4.0.1 Checklist for Small Merchants

Use this checklist as a starting point for your 2026 PCI DSS review.

Payment Environment

  • Identify how customers pay

  • Document payment data flows

  • Review systems connected to payment processing

  • Confirm your PCI DSS scope

Third-Party Providers

  • List payment processors and service providers

  • Verify current PCI DSS compliance

  • Review contracts and responsibilities

  • Monitor provider compliance annually

Website and E-Commerce

  • Review payment pages

  • Review third-party scripts

  • Check website security

  • Confirm SAQ eligibility

  • Review required vulnerability scanning

Access and Authentication

  • Review user accounts

  • Remove unnecessary access

  • Avoid shared credentials

  • Review authentication requirements

  • Protect administrative accounts

Policies and Procedures

  • Review security policies

  • Update incident response procedures

  • Review employee security responsibilities

  • Document payment data handling

  • Maintain compliance evidence

PCI DSS Compliance Is Not a One-Time Task

One of the biggest mistakes a small merchant can make is treating PCI DSS compliance as something to complete once a year and forget.

Your payment environment can change when you:

  • Add a new payment processor

  • Launch a new website

  • Add an e-commerce platform

  • Change POS systems

  • Install new software

  • Add third-party integrations

  • Change vendors

  • Add employees or administrators

  • Change how customers pay

Any of these changes can affect your PCI DSS scope or responsibilities.

That's why PCI DSS compliance should be treated as an ongoing security process rather than a one-time checkbox.

What Should Small Merchants Do Next?

If you're still unsure whether your business is meeting PCI DSS 4.0.1 requirements in 2026, start with three steps.

1. Understand your payment environment.

Know where payment information enters your business and which systems or providers are involved.

2. Review your current PCI documentation.

Check your SAQ, policies, vendor records, vulnerability scans, and compliance evidence.

3. Identify gaps and fix them.

Don't wait until a compliance request, security incident, or assessment exposes an outdated control.

For small merchants, PCI DSS doesn't have to be overwhelming. The key is understanding your environment, knowing your responsibilities, and addressing the security controls that apply to your business.

Need Help With PCI DSS Compliance?

If your business needs help understanding PCI DSS requirements, payment security, or what you still need to address in 2026, ECI can help you take a closer look at your payment environment and compliance needs.

Learn more and get started with ECI :

https://ecisecurepay.com

Protect your payment environment, understand your requirements, and stay prepared for PCI DSS compliance in 2026.

Frequently Asked Questions About PCI DSS 4.0.1

Does PCI DSS apply to small businesses?

Yes. PCI DSS applies to entities involved in payment processing regardless of business size or transaction volume. However, the specific compliance validation requirements can vary depending on the merchant's environment and applicable payment brand requirements.

Do I need PCI DSS compliance if I outsource payment processing?

Outsourcing payment processing can reduce the PCI DSS requirements applicable directly to your environment, but it does not automatically eliminate your responsibilities.

Merchants still need to understand their responsibilities and verify that their service providers are compliant for the services they provide.

Does using a third-party payment processor make my website PCI compliant?

Not automatically.

Your website may still be in scope depending on how payment processing is implemented. Certain e-commerce implementations involving redirects, embedded payment forms, or payment-related scripts can have specific PCI DSS requirements.

What is the difference between SAQ A and SAQ A-EP?

They apply to different e-commerce environments.

SAQ A is intended for certain merchants that fully outsource applicable cardholder-data functions, while SAQ A-EP applies to certain merchants whose websites can impact the security of payment transactions even though the website does not directly receive cardholder data.

Is PCI DSS 4.0.1 still relevant in 2026?

Yes. PCI DSS 4.0.1 remains relevant in 2026, and merchants should ensure that applicable requirements are incorporated into their current security and compliance processes.

Conclusion

PCI DSS 4.0.1 is not just something large companies need to worry about.

For small merchants, 2026 is a good time to review your payment environment, third-party providers, website security, access controls, documentation, vulnerability scanning, and SAQ eligibility.

The most important step is understanding what applies to your specific business and addressing any gaps before they become larger security or compliance problems.

Need help reviewing your payment security and PCI DSS needs?

Visit ECI to learn more.

Back to Blog