StationPro playbook

PCI DSS 4.0 compliance for gas stations: what the March 2025 deadline actually changed.
On March 31, 2025, fifty-one previously future-dated PCI DSS 4.0 requirements became mandatory for every merchant accepting cards. New password length rules, multi-factor authentication, expanded logging. Your processor is sending notice letters. The plain-English checklist for an independent operator who has never read a PCI document.
What PCI DSS is and why it matters for gas stations
PCI DSS is the Payment Card Industry Data Security Standard. It is a set of requirements set by Visa, Mastercard, Discover, and American Express that every merchant who accepts payment cards must follow. It is not a federal law. It is a contractual obligation through your processor agreement.
Independent gas stations almost always qualify as Level 4 merchants (the smallest category, under 20,000 e-commerce or 1 million total Visa transactions per year). Level 4 merchants self-attest via a Self Assessment Questionnaire (SAQ) once per year, submitted to the processor.
Most gas station SAQs are completed in 30 minutes by an office manager who checks "yes" on every box without reading. That worked under PCI DSS 3.2.1. It does not work under 4.0, and processors are starting to audit SAQs against actual configuration. False attestations are a contract violation that voids your PCI insurance.
The 7 things you need to do
1. Update all passwords to 12 characters minimum
PCI DSS 4.0 raises the password minimum from 7 to 12 characters. This applies to:
- POS manager and cashier logins
- Back-office software
- Processor merchant portal
- Router and Wi-Fi admin
- Camera DVR if it shares the cardholder network
- Any device or app that handles cardholder data
Passwords also must be changed at least every 90 days OR the system must continuously monitor account behavior for suspicious activity. Most small merchants pick the 90-day rotation because it is easier to attest.
2. Turn on multi-factor authentication
MFA is now required for every login that has access to the cardholder data environment. Email + a code from an authenticator app, or password + SMS code, or password + hardware token. Single-password access is no longer compliant.
Most gas station POS systems added MFA support in 2024. If your POS does not support it, ask the vendor when they will. If they will not, that is a sign you need to plan a POS migration before your processor flags you.
3. Segment the cardholder network from everything else
Your POS and payment terminals should be on a separate network from your office computer, your back-office printer, your camera DVR, and your customer Wi-Fi. This is called network segmentation and it is required.
Most independent operators discover at their first honest PCI review that everything is on one flat network. Fix: ask your IT contractor or POS vendor to set up a separate VLAN for payment devices. Cost: $200 to $800 one time.
4. Enable and retain audit logs
Every system that touches cardholder data must log who accessed what, when, and from where. Logs must be retained for 12 months minimum, with at least 3 months immediately accessible.
Most POS systems generate these logs but do not retain them by default. Enable extended retention. If your back-office software is a spreadsheet, you cannot produce PCI-grade logs. That is a compliance gap.
5. Document a written security policy
PCI DSS 4.0 requires a written information security policy reviewed at least annually. Most small operators do not have one. A 4 to 8 page policy covering:
- Who has access to cardholder data and why
- How accounts are created and removed
- What devices are approved for the cardholder network
- Incident response: what to do if a card breach is suspected
- Annual review and update process
Templates are available free from the PCI Security Standards Council. The policy does not need to be long; it needs to be specific to your environment and signed by the owner annually.
6. Train every employee with system access
Annual security awareness training is required for every employee who logs into a POS, back office, or any system that touches cardholder data. Most processors offer free 20-minute online training that satisfies the requirement. Keep the completion certificates in employee files.
7. Run vulnerability scans
If you accept cards through any internet-connected device, you must run quarterly Approved Scanning Vendor (ASV) scans. Your processor typically offers this through a partner like Trustwave or Sysnet for $100 to $300 per year. If you skip the scans, your processor will eventually flag the SAQ.
What the processor sends you and what to do with it
Once a year (usually 60 days before your processor contract anniversary), you will receive an email titled something like "PCI Compliance Required: Action Needed." The email links to your processor's compliance portal where you complete:
- The SAQ (the questionnaire)
- The Attestation of Compliance (you sign, under penalty of contract breach)
- The ASV scan report (if applicable)
Most operators delegate this to the office manager. The office manager checks every box "yes" without reading. The portal accepts the submission. The processor files it. Nothing happens until a breach.
Under 4.0, processors are starting to spot-check SAQs by requesting evidence. If the SAQ says "passwords are 12 characters or longer" and the requested screenshot shows a 7-character password policy, the processor flags the merchant. Penalties start.
The 4 highest-risk gaps at independent gas stations
1. Default passwords on the router and DVR
The router that came with your internet service has a default admin password printed on a sticker. Same for most camera DVRs. Default passwords are PCI non-compliance and they are the #1 entry point for skimmer-related breaches. Change them. 12 characters minimum, written in your password policy.
2. Customer Wi-Fi on the same network as the POS
If your customer Wi-Fi shares a network with your POS, every customer device is technically on the cardholder data environment. Set up a separate guest network. Most consumer routers support this in 5 minutes of setup.
3. Employees sharing logins
Three cashiers using the same "cashier" login is a PCI violation and makes shrink investigation impossible. Every employee gets their own login. POS systems support this; some operators just do not enforce it.
4. Skimmer-prone gas pumps
Forecourt skimmers remain the largest single source of card breaches in c-store. Daily pump inspection, tamper-evident seals, and EMV chip readers on the pump (federally required since 2020) reduce risk dramatically. Operators with non-EMV pumps in 2025 are absorbing 100 percent of fraud liability and probably failing PCI anyway.
The honest SAQ shortcut
The fastest path to an honest, compliant SAQ:
- Schedule a 1-hour call with your processor's compliance team. Most offer this free.
- Ask which SAQ type applies to your merchant setup (most c-stores are SAQ B-IP or SAQ C).
- Walk through the questionnaire with the compliance rep on the phone, marking honest answers.
- Identify the gaps.
- Fix the gaps over 30 to 60 days.
- Complete the SAQ and submit.
Most operators are surprised that the processor compliance team is helpful. Their job is to keep you compliant; they do not benefit from your non-compliance.
Frequently asked questions
What is PCI DSS 4.0?
Am I required to comply with PCI DSS?
What is an SAQ?
How long does it take to become PCI 4.0 compliant?
What are the penalties for PCI non-compliance?
Does my back-office software need to be PCI compliant?
My POS vendor says they handle PCI for me. Is that true?
Sources & methodology
This playbook draws on operator workflows observed in StationPro pilot stations and on anonymized product data from live pilot tenants. Figures are illustrative examples, not promises about your stores. Procedures were reviewed against the workflows of the StationPro operator team before publication. Questions or corrections: talk to the team.
StationPro Editorial
The operator team behind StationPro. We write the procedures we ship: every playbook comes from real close, reconciliation, and loss-attribution workflows in pilot stations.
Keep reading
California's July 2026 gas tax increase: what 63.4 cents a gallon does to your margin and your daily close.
California's excise tax rose to 63.4 cents on gasoline and 48.2 cents on diesel on July 1, 2026, indexed to inflation with no legislative vote. The tax is not your margin, but it inflates your fuel liability, your deposits, and the size of any variance you fail to catch. How the increase flows through your close and what to reconcile.
SNAP candy and soda restrictions hit in 2026: the c-store POS and compliance scramble.
Eighteen states began restricting candy and soda purchases with SNAP/EBT in 2026, which means new POS eligibility rules on some of your highest-velocity SKUs. What changed, which items are affected, how the POS side breaks, and why clean item-level records are now a compliance asset, not just a back-office nicety.
Disposable vape enforcement is intensifying in 2026: the tobacco exposure most c-stores are missing.
Federal and state action against illegal disposable vapes stepped up in 2026, and the FDA under-30 ID rule reaches its September 30 enforcement date. The exposure most operators miss is not the ID check, it is the missing paper trail. What to have documented before an inspector walks in.
