AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

Nine Terminals, Five Stores, One Holiday Peak: PCI DSS 4.0.1 for Atlanta Retail

PCI DSS for multi-location retail in Atlanta: what 4.0.1 asks of nine terminals across five stores, and the six checks to finish before the holiday peak.

Sam KhanSam Khan The Cyber ExpertFounder and CEOOctober 26, 2026 · 6 min read

Nine terminals, five stores and a man in a branded polo

The operations director of a five-store coffee and provisions company in metro Atlanta takes a call from the Decatur shop at 9:40 on a Tuesday. A man in a branded polo arrived before the morning rush, said the processor had sent him to swap the card terminal for a newer model, and left with the old one under his arm. The shift lead, three weeks into the job and looking at a line to the door, signed nothing and asked nothing.

Nobody at the company scheduled that visit.

By lunch she is doing arithmetic she has never done before. Nine card devices across five stores, two of them readers clipped to countertop tablets. A website that sells gift cards and holiday boxes. A back office PC on Buford Highway that runs the reporting software and last took an update in April. Twenty seasonal hires starting the week after Halloween, all of whom will use the same manager login on the point of sale because that is how it has always worked.

The acquiring bank's annual questionnaire is due in January. The holiday peak starts in three weeks. She asks the question nobody at the company has ever asked out loud: which of these things is the bank actually asking about?

All of them.

What the heck does this mean

PCI DSS is the card brands' rulebook for any business that accepts card payments. It is not a law. It is a term of the contract you signed with your acquiring bank, which is why the bank, not a regulator, is the one that writes to you.

Version 4.0.1 is the current edition. Its future-dated requirements, the ones merchants were given two years to prepare for, became mandatory on 31 March 2025.

Cardholder data environment: every device, system and network segment that stores, processes or transmits card data, plus anything connected to them. The Wi-Fi that serves both the terminals and the customer laptops is inside it.

Self-assessment questionnaire: the form you complete instead of an on-site audit. There is more than one version, and which one applies depends on how the card is read and whether your website touches the payment page. Your acquiring bank confirms which one your merchant account is validated on. For e-commerce merchants the short questionnaire changed in January 2025, and the new question is about the scripts running on the page where a customer types a card number.

Tampering: someone physically swapping or opening a terminal to capture card data. It is a polo shirt, a busy Tuesday and a new shift lead.

The numbers that matter

The retail sector recorded 806 breaches in the Verizon 2026 Data Breach Investigations Report, with third parties involved in 68% of them and the human element in 58%. For a five-store operator the two most likely doors are your vendors and your staff.

Fifty-one future-dated requirements in PCI DSS v4.x became mandatory on 31 March 2025, according to the PCI Security Standards Council. A questionnaire completed on an older form is simply out of date.

Median time to patch an exploited vulnerability now sits at 43 days, per the Verizon 2026 DBIR. Put that next to a holiday change freeze and a back office PC goes eleven weeks without an update during the busiest trading of the year.

What to do this week

  1. Count the hardware. Every terminal, reader, tablet and back office PC that touches a card gets a line: store, lane, make, serial number, and a photograph of the device and its cables taken today. Print the sheet and tape it inside the manager's binder at each store. (CIS 1 Inventory and Control of Enterprise Assets)
  2. Give the counter a two-line script for visitors: no device is swapped, opened or taken without a call to the processor number on the sheet, and the serial on the new unit is checked against the photo before the visitor leaves. Seasonal hires get it on day one. (CIS 1 Inventory and Control of Enterprise Assets)
  3. Ask your processor in writing whether your terminals encrypt card data inside the reader, and ask your acquiring bank in writing which questionnaire your merchant ID is validated on. Two emails, one afternoon, and the answers decide how much of the rest of this applies. (CIS 3 Data Protection)
  4. Set the patch date before the freeze starts. Every back office PC, the reporting server and the point of sale software get their updates in the first week of November, and one named person signs the sheet when it is done. (CIS 7 Continuous Vulnerability Management)
  5. End the shared manager login. Individual accounts on the point of sale and the e-commerce admin, multi-factor authentication on both, and a standing rule that seasonal accounts are switched off the week the season ends. (CIS 6 Access Control Management)
  6. Go looking for card numbers where they should not be. Catering orders in the shared inbox, gift card requests forwarded from the website, the notepad by the phone in the back room, receipts that print more than the last four digits. Delete them, then change the process that created them. (CIS 3 Data Protection)

Where AccuSights fits

We start by telling you what is actually in scope, which for multi-location retail is usually smaller than the owner fears and larger than the IT provider assumed. Our assessment maps your terminals, your store networks and your checkout page against PCI DSS 4.0.1, then hands you a ranked plan instead of a findings dump. Our team implements the controls at a reasonable rate, from data loss prevention to scanning to protection of the assets that run the stores. The Cyber Hygiene Test takes three minutes; a call with an engineer takes fifteen, and it is the same engineer who would do the work. We hear the same questions from retailers across Atlanta every autumn.

Questions people ask

Do I file one PCI questionnaire for all my stores or one per store? One assessment covers the merchant account, and most multi-store operators run every location under a single merchant ID with the same acquiring bank. The catch is that the questionnaire has to describe every location as it really operates, so a single store that takes card numbers over the phone or on a back office PC pulls the whole company onto a longer form. Ask your acquiring bank which questionnaire your merchant ID is validated on, then check that all five stores actually match the description on it.

Does using chip readers put my stores out of PCI scope? No. Chip and contactless make card data harder to copy at the counter, and a terminal that encrypts inside the reader shortens the questionnaire, but the terminals, the network they sit on and the people who use them stay in scope. Nothing takes you out of scope entirely while you are accepting cards, and the parts you control, the store network, the back office PC and the accounts your managers log in with, are where a retail breach usually starts.

What should staff do if someone shows up to swap a card terminal? Nothing until the visit is confirmed by phone to the processor number your office already has on file, not a number the visitor supplies. Terminals are swapped by appointment, with a ticket number and a serial number that should match your inventory. If a device was already taken or replaced without that check, call your processor and your acquiring bank the same day and pull the transaction log for that lane.

You will spend December counting cups, staff hours and gift boxes. Spend one hour in November counting the nine machines that handle everyone's money.

Controls this post maps to

CIS 1 Inventory and Control of Enterprise AssetsCIS 3 Data ProtectionCIS 6 Access Control Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.