If your garden centre, pool shop, or specialty retail business takes card payments — and whose doesn’t? — then PCI DSS v4.0.1 applies to you. It became the sole active payment security standard in March 2025, and it’s fundamentally different from what came before.
The old approach was essentially a checkbox exercise: pass an annual audit and you’re good for another year. PCI v4.0.1 moves away from that entirely. It requires continuous, outcome-based security — meaning your systems need to be compliant all the time, not just on audit day.
Here are the key changes that affect independent retailers:
Multi-factor authentication is now required for all access to cardholder data environments, not just remote access. If your staff can access payment data with just a password, you’re non-compliant.
The minimum password length has increased to 12 characters where systems support it. Eight characters no longer meets the standard.
Public-facing web applications — including ecommerce checkout pages — must now have automated firewall protection rather than relying on periodic manual reviews.
DMARC email authentication must be implemented on your domain to protect against phishing and spoofing.
The consequences of non-compliance are real. Your acquiring bank can impose fines, you can lose the ability to process card payments entirely, and if a breach occurs while you’re non-compliant, the liability falls squarely on you.
At ITS4, PCI compliance consulting is a core competency we’ve built over 25 years with our US parent company Accelerando. We audit POS environments, identify gaps, and implement compliant configurations — particularly for NCR Counterpoint deployments.
If you’re not sure where you stand, we offer a free 30-minute POS compliance review. No jargon, no hard sell — just a clear picture of what needs attention.
