
PCI DSS 4.0.1: What Small Merchants Still Need to Fix in 2026
PCI DSS compliance is not only a concern for large retailers and major e-commerce companies. Small merchants that accept payment cards also need to protect payment account data, regardless of their transaction volume.
For small businesses, the challenge in 2026 is often not understanding that PCI DSS matters. The bigger challenge is knowing what still needs to be fixed, documented, monitored, or verified under PCI DSS 4.0.1.
PCI DSS 4.0.1 is the updated version of the Payment Card Industry Data Security Standard. Several requirements that were previously future-dated became effective on March 31, 2025.
That means merchants entering or maintaining compliance in 2026 need to account for those requirements rather than treating them as optional future changes.
What Is PCI DSS 4.0.1?

PCI DSS 4.0.1 is a security standard designed to help protect payment account data.
It applies to organizations involved in storing, processing, or transmitting payment card information, as well as environments that can affect the security of payment account data.
The specific requirements that apply to a merchant depend on its payment environment.
For example, a business that completely outsources payment processing may have a different PCI DSS scope than a business that stores card information or operates its own payment systems.
This is why small merchants should avoid assuming that another company's PCI setup automatically applies to their own business.
7 PCI DSS 4.0.1 Areas Small Merchants Should Check in 2026
1. Review Your PCI DSS Scope
One of the first things a small merchant should review is what systems, websites, devices, applications, and service providers are actually in scope.
Your payment environment may include more than your credit card terminal.
Depending on how you accept payments, your scope could involve:
Point-of-sale systems
E-commerce websites
Payment pages
Virtual terminals
Payment applications
Cloud services
Employee computers
Networks
Third-party payment processors
Service providers with access to payment-related systems
Outsourcing payment processing does not automatically eliminate a merchant's PCI DSS responsibilities. Merchants still need to understand their responsibilities and ensure that third-party providers are appropriately compliant.
What to fix in 2026
Review your current payment flow and document:
Customer → Website or POS → Payment Processor → Acquirer
Then determine which systems touch, transmit, or can affect payment account data.
If your payment environment has changed since your last assessment, your PCI DSS scope may need to be reviewed again.
2. Don't Assume Your Payment Processor Handles Everything
A common misconception among small businesses is:
"We use a PCI-compliant payment processor, so we're automatically PCI compliant."
That's not necessarily the case.
When payment processing is outsourced, merchants still have responsibilities.
Small businesses should understand which responsibilities belong to the payment processor and which remain with the merchant.
What to fix in 2026
Create a current list of your payment-related service providers.
For each provider, document:
Company name
Services provided
PCI DSS responsibilities
Compliance status
Contract or agreement
Date compliance was last verified
Your responsibilities versus the provider's responsibilities
Small businesses often work with multiple vendors, including payment processors, website providers, POS vendors, SaaS platforms, and IT providers.
Knowing what each provider does and how it affects your payment environment can help you better understand your PCI DSS responsibilities.
3. Check Your Website and E-Commerce Payment Setup
For online merchants, website security remains an important PCI DSS consideration in 2026.
This is especially important if your website:
Hosts payment forms
Redirects customers to a payment processor
Uses embedded payment forms
Uses payment-related scripts
Connects to third-party payment services
PCI DSS 4.0.1 includes requirements addressing security risks associated with e-commerce payment pages and scripts.
What to fix in 2026
Review the scripts and third-party services running on payment-related pages.
Ask:
Who controls the payment page?
Are third-party scripts being used?
Can those scripts affect the payment process?
Is the payment processor providing protections against script-based attacks?
Does your current implementation still qualify for the SAQ you are using?
Don't assume that using an embedded payment processor automatically removes website security responsibilities.
4. Don't Forget Vulnerability Scanning
Another area small e-commerce merchants should review is vulnerability scanning.
Depending on the merchant's environment and applicable PCI DSS requirements, external vulnerability scanning may be required.
If your environment requires ASV scanning, the scanning should be performed by a PCI SSC Approved Scanning Vendor.
What to fix in 2026
If your environment requires vulnerability scanning, verify that:
Your scans are being performed by an approved vendor.
The correct external systems are included.
Scans are completed according to the required schedule.
Failed scans are remediated.
Evidence of passing scans is retained.
Outsourcing payment processing does not automatically mean your website is outside the scope of PCI DSS.
5. Review User Access and Authentication
PCI DSS 4.0.1 also places significant emphasis on access control and authentication.
Small businesses should review who has access to:
POS systems
Payment platforms
Administrative dashboards
E-commerce websites
Payment applications
Cloud systems
Business networks
What to fix in 2026
Review employee and administrator accounts.
Remove accounts that are no longer needed.
Make sure users have individual credentials rather than sharing a single login.
Also review authentication requirements applicable to your environment, including password policies and multi-factor authentication where required.
The goal is simple: people should only have the access they need to perform their job.
6. Keep Security Policies and Documentation Current

PCI DSS compliance isn't only about technology.
Documentation matters too.
Small businesses should maintain policies and procedures covering areas such as:
Information security
Passwords and authentication
Access control
Incident response
Payment data handling
Employee responsibilities
Third-party service providers
Security awareness training
Data retention and disposal
A policy that was created several years ago may no longer reflect how your business actually operates.
What to fix in 2026
Review your documentation and ask:
"Does this policy describe what we actually do today?"
If the answer is no, update it.
Compliance documentation should reflect your real environment rather than simply existing for an audit.
7. Make Sure You Are Completing the Correct SAQ
Small merchants may use a Self-Assessment Questionnaire, or SAQ, when eligible.
However, there isn't one universal SAQ for every small business.
PCI SSC provides different SAQs based on the merchant's payment environment.
For example, SAQ A applies to certain merchants that completely outsource applicable cardholder-data functions, while SAQ A-EP applies to certain e-commerce merchants whose websites can affect the security of payment transactions.
What to fix in 2026
Don't choose an SAQ simply because another business uses it.
Review the eligibility criteria for your specific payment setup.
If you're unsure, consult your acquiring bank, payment brand, qualified security professional, or PCI compliance provider.
What Changed After March 31, 2025?
One important reason merchants should revisit PCI DSS in 2026 is that several future-dated PCI DSS v4.x requirements became effective after March 31, 2025.
These include requirements related to:
Automated technical solutions for detecting and preventing certain web-based attacks against public-facing web applications
Authentication for certain customer user access
Detection, alerting, and prompt response to failures of critical security control systems
For merchants still relying on older PCI DSS checklists, this is an important area to review.
A Simple PCI DSS 4.0.1 Checklist for Small Merchants
Use this checklist as a starting point for your 2026 PCI DSS review.
Payment Environment
Identify how customers pay
Document payment data flows
Review systems connected to payment processing
Confirm your PCI DSS scope
Third-Party Providers
List payment processors and service providers
Verify current PCI DSS compliance
Review contracts and responsibilities
Monitor provider compliance annually
Website and E-Commerce
Review payment pages
Review third-party scripts
Check website security
Confirm SAQ eligibility
Review required vulnerability scanning
Access and Authentication
Review user accounts
Remove unnecessary access
Avoid shared credentials
Review authentication requirements
Protect administrative accounts
Policies and Procedures
Review security policies
Update incident response procedures
Review employee security responsibilities
Document payment data handling
Maintain compliance evidence
PCI DSS Compliance Is Not a One-Time Task
One of the biggest mistakes a small merchant can make is treating PCI DSS compliance as something to complete once a year and forget.
Your payment environment can change when you:
Add a new payment processor
Launch a new website
Add an e-commerce platform
Change POS systems
Install new software
Add third-party integrations
Change vendors
Add employees or administrators
Change how customers pay
Any of these changes can affect your PCI DSS scope or responsibilities.
That's why PCI DSS compliance should be treated as an ongoing security process rather than a one-time checkbox.
What Should Small Merchants Do Next?
If you're still unsure whether your business is meeting PCI DSS 4.0.1 requirements in 2026, start with three steps.
1. Understand your payment environment.
Know where payment information enters your business and which systems or providers are involved.
2. Review your current PCI documentation.
Check your SAQ, policies, vendor records, vulnerability scans, and compliance evidence.
3. Identify gaps and fix them.
Don't wait until a compliance request, security incident, or assessment exposes an outdated control.
For small merchants, PCI DSS doesn't have to be overwhelming. The key is understanding your environment, knowing your responsibilities, and addressing the security controls that apply to your business.
Need Help With PCI DSS Compliance?
If your business needs help understanding PCI DSS requirements, payment security, or what you still need to address in 2026, ECI can help you take a closer look at your payment environment and compliance needs.
Learn more and get started with ECI :
Protect your payment environment, understand your requirements, and stay prepared for PCI DSS compliance in 2026.
Frequently Asked Questions About PCI DSS 4.0.1
Does PCI DSS apply to small businesses?
Yes. PCI DSS applies to entities involved in payment processing regardless of business size or transaction volume. However, the specific compliance validation requirements can vary depending on the merchant's environment and applicable payment brand requirements.
Do I need PCI DSS compliance if I outsource payment processing?
Outsourcing payment processing can reduce the PCI DSS requirements applicable directly to your environment, but it does not automatically eliminate your responsibilities.
Merchants still need to understand their responsibilities and verify that their service providers are compliant for the services they provide.
Does using a third-party payment processor make my website PCI compliant?
Not automatically.
Your website may still be in scope depending on how payment processing is implemented. Certain e-commerce implementations involving redirects, embedded payment forms, or payment-related scripts can have specific PCI DSS requirements.
What is the difference between SAQ A and SAQ A-EP?
They apply to different e-commerce environments.
SAQ A is intended for certain merchants that fully outsource applicable cardholder-data functions, while SAQ A-EP applies to certain merchants whose websites can impact the security of payment transactions even though the website does not directly receive cardholder data.
Is PCI DSS 4.0.1 still relevant in 2026?
Yes. PCI DSS 4.0.1 remains relevant in 2026, and merchants should ensure that applicable requirements are incorporated into their current security and compliance processes.
Conclusion
PCI DSS 4.0.1 is not just something large companies need to worry about.
For small merchants, 2026 is a good time to review your payment environment, third-party providers, website security, access controls, documentation, vulnerability scanning, and SAQ eligibility.
The most important step is understanding what applies to your specific business and addressing any gaps before they become larger security or compliance problems.
Need help reviewing your payment security and PCI DSS needs?
Visit ECI to learn more.