What PCI DSS asks of card-accepting businesses, annual requirements, and how CMS keeps education on CMS pages.
PCI details →Protect payment data. Stay PCI current.
Accepting cards means protecting customer payment data. This page is your one stop for PCI compliance and practical payment security. Stay validated each year and CMS lists PCI at $0.00. Miss annual validation and an avoidable Non-Compliant fee of $99.00 / year may apply — so staying current protects both customers and your bottom line.
Why PCI matters for merchants
PCI DSS is the industry standard for businesses that accept, process, store, or transmit card data. Most merchants validate once a year through a Self-Assessment Questionnaire (SAQ) or the path your payment provider requires. Completing that validation on time keeps customers safer and helps you avoid fees that only show up when compliance lapses.
CMS does not self-certify merchants. We explain requirements in plain language, can flag related fees on a statement review, and point you to the PCI Security Standards Council portal to complete compliance. Status is confirmed through your enrolled payment setup — not a checkbox on this website.
Use the PCI SSC Portal to protect payment data with industry-driven security standards, training, and programs. This is an external standards body, not a CMS payment-processor partner.
Open PCI SSC Portal →Related security topics
Short guides when you want more detail beyond annual PCI validation.
Chip cards (EMV), tokenization, encryption, and safer acceptance practices explained without the jargon maze.
Security tips →How CMS collects, uses, and protects merchant information across the site and tools.
Privacy policy →