Skip to main content

Introducing Loss Radar: see which shift cost you money.Learn more

All posts

StationPro playbook

Field-tested workflow
Operator review
12 minute read
Compliance12 min readPublished

PCI DSS 4.0 compliance for gas stations: what the March 2025 deadline actually changed.

On March 31, 2025, fifty-one previously future-dated PCI DSS 4.0 requirements became mandatory for every merchant accepting cards. New password length rules, multi-factor authentication, expanded logging. Your processor is sending notice letters. The plain-English checklist for an independent operator who has never read a PCI document.

Written by
StationPro Editorial
Reviewed by
StationPro operator team

What PCI DSS is and why it matters for gas stations

PCI DSS is the Payment Card Industry Data Security Standard. It is a set of requirements set by Visa, Mastercard, Discover, and American Express that every merchant who accepts payment cards must follow. It is not a federal law. It is a contractual obligation through your processor agreement.

Independent gas stations almost always qualify as Level 4 merchants (the smallest category, under 20,000 e-commerce or 1 million total Visa transactions per year). Level 4 merchants self-attest via a Self Assessment Questionnaire (SAQ) once per year, submitted to the processor.

Most gas station SAQs are completed in 30 minutes by an office manager who checks "yes" on every box without reading. That worked under PCI DSS 3.2.1. It does not work under 4.0, and processors are starting to audit SAQs against actual configuration. False attestations are a contract violation that voids your PCI insurance.

51
Future-dated PCI DSS 4.0 requirements that became enforceable March 31, 2025
The PCI Security Standards Council published these as 'future dated' when 4.0 launched in March 2024, giving merchants a 12-month runway. That runway ended. Every requirement is now active and reviewed in SAQs.

The 7 things you need to do

1. Update all passwords to 12 characters minimum

PCI DSS 4.0 raises the password minimum from 7 to 12 characters. This applies to:

  • POS manager and cashier logins
  • Back-office software
  • Processor merchant portal
  • Router and Wi-Fi admin
  • Camera DVR if it shares the cardholder network
  • Any device or app that handles cardholder data

Passwords also must be changed at least every 90 days OR the system must continuously monitor account behavior for suspicious activity. Most small merchants pick the 90-day rotation because it is easier to attest.

2. Turn on multi-factor authentication

MFA is now required for every login that has access to the cardholder data environment. Email + a code from an authenticator app, or password + SMS code, or password + hardware token. Single-password access is no longer compliant.

Most gas station POS systems added MFA support in 2024. If your POS does not support it, ask the vendor when they will. If they will not, that is a sign you need to plan a POS migration before your processor flags you.

3. Segment the cardholder network from everything else

Your POS and payment terminals should be on a separate network from your office computer, your back-office printer, your camera DVR, and your customer Wi-Fi. This is called network segmentation and it is required.

Most independent operators discover at their first honest PCI review that everything is on one flat network. Fix: ask your IT contractor or POS vendor to set up a separate VLAN for payment devices. Cost: $200 to $800 one time.

4. Enable and retain audit logs

Every system that touches cardholder data must log who accessed what, when, and from where. Logs must be retained for 12 months minimum, with at least 3 months immediately accessible.

Most POS systems generate these logs but do not retain them by default. Enable extended retention. If your back-office software is a spreadsheet, you cannot produce PCI-grade logs. That is a compliance gap.

5. Document a written security policy

PCI DSS 4.0 requires a written information security policy reviewed at least annually. Most small operators do not have one. A 4 to 8 page policy covering:

  • Who has access to cardholder data and why
  • How accounts are created and removed
  • What devices are approved for the cardholder network
  • Incident response: what to do if a card breach is suspected
  • Annual review and update process

Templates are available free from the PCI Security Standards Council. The policy does not need to be long; it needs to be specific to your environment and signed by the owner annually.

6. Train every employee with system access

Annual security awareness training is required for every employee who logs into a POS, back office, or any system that touches cardholder data. Most processors offer free 20-minute online training that satisfies the requirement. Keep the completion certificates in employee files.

7. Run vulnerability scans

If you accept cards through any internet-connected device, you must run quarterly Approved Scanning Vendor (ASV) scans. Your processor typically offers this through a partner like Trustwave or Sysnet for $100 to $300 per year. If you skip the scans, your processor will eventually flag the SAQ.

$5,000 to $100,000
Monthly non-compliance penalty range from card processors
Penalties scale with merchant volume and time out of compliance. Most independent operators see $5K to $25K per month as a starting point. Penalties stop when the SAQ is completed honestly with corrected configuration.

What the processor sends you and what to do with it

Once a year (usually 60 days before your processor contract anniversary), you will receive an email titled something like "PCI Compliance Required: Action Needed." The email links to your processor's compliance portal where you complete:

  • The SAQ (the questionnaire)
  • The Attestation of Compliance (you sign, under penalty of contract breach)
  • The ASV scan report (if applicable)

Most operators delegate this to the office manager. The office manager checks every box "yes" without reading. The portal accepts the submission. The processor files it. Nothing happens until a breach.

Under 4.0, processors are starting to spot-check SAQs by requesting evidence. If the SAQ says "passwords are 12 characters or longer" and the requested screenshot shows a 7-character password policy, the processor flags the merchant. Penalties start.

The 4 highest-risk gaps at independent gas stations

1. Default passwords on the router and DVR

The router that came with your internet service has a default admin password printed on a sticker. Same for most camera DVRs. Default passwords are PCI non-compliance and they are the #1 entry point for skimmer-related breaches. Change them. 12 characters minimum, written in your password policy.

2. Customer Wi-Fi on the same network as the POS

If your customer Wi-Fi shares a network with your POS, every customer device is technically on the cardholder data environment. Set up a separate guest network. Most consumer routers support this in 5 minutes of setup.

3. Employees sharing logins

Three cashiers using the same "cashier" login is a PCI violation and makes shrink investigation impossible. Every employee gets their own login. POS systems support this; some operators just do not enforce it.

4. Skimmer-prone gas pumps

Forecourt skimmers remain the largest single source of card breaches in c-store. Daily pump inspection, tamper-evident seals, and EMV chip readers on the pump (federally required since 2020) reduce risk dramatically. Operators with non-EMV pumps in 2025 are absorbing 100 percent of fraud liability and probably failing PCI anyway.

The honest SAQ shortcut

The fastest path to an honest, compliant SAQ:

  1. Schedule a 1-hour call with your processor's compliance team. Most offer this free.
  2. Ask which SAQ type applies to your merchant setup (most c-stores are SAQ B-IP or SAQ C).
  3. Walk through the questionnaire with the compliance rep on the phone, marking honest answers.
  4. Identify the gaps.
  5. Fix the gaps over 30 to 60 days.
  6. Complete the SAQ and submit.

Most operators are surprised that the processor compliance team is helpful. Their job is to keep you compliant; they do not benefit from your non-compliance.

Frequently asked questions

What is PCI DSS 4.0?

The current version of the Payment Card Industry Data Security Standard, in effect since March 31, 2024. The 51 future-dated requirements (passwords, MFA, logging) became enforceable on March 31, 2025. Every merchant accepting cards must comply.

Am I required to comply with PCI DSS?

Yes if you accept payment cards. PCI compliance is a contractual obligation through your processor agreement, not a federal law. Non-compliance triggers monthly fines from your processor and voids your PCI breach insurance.

What is an SAQ?

Self-Assessment Questionnaire. Small merchants (Level 4, under 1 million Visa transactions per year) self-attest annually using an SAQ submitted to their processor. Most gas stations qualify as Level 4 and use SAQ B-IP or SAQ C.

How long does it take to become PCI 4.0 compliant?

For a typical independent gas station: 30 to 60 days. Most of the work is updating passwords, enabling MFA, setting up network segmentation, and writing a security policy. Cost is usually $500 to $2,500 in IT contractor time plus the ongoing ASV scan fee.

What are the penalties for PCI non-compliance?

Monthly fines from your processor range $5,000 to $100,000 depending on merchant volume and time out of compliance. If a breach occurs while non-compliant: $50 to $90 per compromised card record, plus class action exposure, plus loss of card acceptance privilege.

Does my back-office software need to be PCI compliant?

If it accesses cardholder data (full card numbers, CVV, etc.) yes. If it only accesses aggregated sales data and the last 4 of card numbers, it is not in scope but it should still produce audit logs, support MFA, and use 12-character passwords as part of overall environment compliance.

My POS vendor says they handle PCI for me. Is that true?

Partially. POS vendors can provide a compliant payment terminal and certain network setup, but the merchant is always responsible for the SAQ, the user access controls, the password policy, the network architecture, and the employee training. Read your vendor agreement to see exactly what they cover.

Sources & methodology

This playbook draws on operator workflows observed in StationPro pilot stations and on anonymized product data from live pilot tenants. Figures are illustrative examples, not promises about your stores. Procedures were reviewed against the workflows of the StationPro operator team before publication. Questions or corrections: talk to the team.

Written by

StationPro Editorial

The operator team behind StationPro. We write the procedures we ship: every playbook comes from real close, reconciliation, and loss-attribution workflows in pilot stations.

See where your station is leaking money.

A 30-minute call. We build the demo around your stations, not a generic deck.