📝 Overview
The Payment Card Industry Data Security Standard (PCI DSS) is managed by the PCI Security Standards Council (PCI SSC) — founded in 2006 by the five major credit card providers: Mastercard, Visa, Discover, American Express, and JCB International. The Council ensures that merchants meet required security standards when storing, processing, and transmitting cardholder data.
While PCI compliance is not required by law, merchants who accept card payments are strongly advised to follow PCI SSC regulations to avoid potential data breaches and non-compliance fees. Requirements vary based on how your business operates.
💡 Please Note: For questions or assistance, contact payment support at [email protected] or call +1 (800) 982-6419.
📋 Compliance Requirements
Each compliance level requires merchants to complete the following:
The relevant PCI DSS Self Assessment Questionnaire (SAQ)
A vulnerability scan completed and passed with a PCI SSC Approved Scanning Vendor (ASV)
The Attestation of Compliance (AOC), submitted to your acquirer
🛠️ How To Access Your PCI Compliance Portal
Your PCI Compliance Portal is supported by Secure Trust. To access it:
Log in to your Cardpointe Merchant Portal at Cardpointe.com
Using the top navigation bar, select My Account
On the Account sub-tab, locate and select the Not Compliant hyperlink to open the Secure Trust Portal.
💡 Need help accessing your Merchant Portal? Click the button below.
👤 How To Create Your Business Profile
Before completing your Compliance Survey, you must first create your business profile.
Enter your Contact Email, Contact Name, and Mobile Number, then select your Language Preference. Optionally, you may add an additional contact email
Select Next
On the following page, select Start Business Profile
On the Before You Begin page, select Next to continue
On the Pick an Assessment Method page, choose Expert, then select Next
On the following page, select No for both questions to be sorted into the correct survey type, then select Next
On the A Summary of How and Where You Handle Card Payments page, answer the questions as follows:
Question 1: Enter your type of retail location (e.g., Salon, Spa, Grooming Salon, Recreation Facility, Veterinary Clinic, or Tattoo Salon).
Question 2: Enter your type of card processing device (e.g., Clover Flex or Clover Mini).
Question 3: Enter your industry type (e.g., Spa, Vet, Pet, Salon, Recreation, Tattoo).
📊 How To Complete Your PCI Questionnaire
⚠️ Warning: Failure to complete your PCI Compliance within 60 days of your account being approved will result in an additional fee on your merchant statement.
After completing your business profile, you will be taken to your Secure Trust Portal.
Under Your Business Profile, confirm that the SAQ type displayed is P2PE.
If the SAQ type is not P2PE, select Manage and follow the business profile steps above to re-sort your business type to the correct SAQ
Once the correct SAQ type is confirmed, select Begin Step under the Complete Your Security Assessment section
You will be taken to your Compliance Survey. Depending on your industry, expect approximately 25–30 questions
As you answer questions, they will clear from the form. Your section progress is displayed on the right side of the screen
If prompted to fill in a Completion Date, enter the current date for your first-time completion, then answer any remaining questions.
💡 Please Note: To become compliant, you must answer Yes to each question.
✅ How To Confirm Your Compliance
Under Your Organization Information Details, enter your Title (e.g., Owner, Manager, or Co-Owner)
Under Merchant Executive Officer, enter your Title again
Under Information for Submission, select Confirm Your Attestation
⚠️ You do not need to enter a telephone number, email, or business address in this section.
Once confirmed, you will be returned to the main menu where you will see "You're Compliant."
🔔 Congratulations! Your Compliance Survey is complete.
❓ Frequently Asked Questions (FAQs)
Find answers to common questions or additional details that may not be covered in the main instructions.
How often does the PCI survey need to be completed?
Your PCI compliance is valid for a full calendar year from the date of completion.
How can I receive a notification when I need to become compliant again?
You can opt in to receive an email notification when you become non-compliant again from your notification configuration under your Dashboard. For additional support, click here.
My SAQ type isn't P2PE — what should I do?
Select the Manage button on your Business Profile section and follow the business profile setup steps above, making sure your correct industry type and device type are entered. If you are still sorted incorrectly, please contact our support team
What happens if I do not complete my PCI compliance?
Failure to complete your PCI Compliance within 60 days of your account being approved will result in an additional fee on your merchant statement. Please note that refunds for these fees are typically not available. Contact support if you experience any issues completing your PCI compliance.
