At a glance
| Item | Detail |
|---|---|
| Also called | PCI compliance, PCI standard |
| French term | Norme PCI DSS |
| Where it sits in the payment flow | Around the whole flow, wherever card data is handled |
| Who controls it | The PCI Security Standards Council writes it. Card brands and your processor require it |
| Does it cost the merchant | Possibly. Some agreements charge PCI fees, and a breach can cost far more |
How it works
The PCI Security Standards Council was founded in 2006 by American Express, Discover, JCB, Mastercard and Visa. It says PCI DSS applies to every business that stores, handles or sends card account data. Size and volume do not matter. The Council itself does not enforce it. It says the card brands, your acquirer or another program owner decide if you must prove it. The current version in the Council's library is PCI DSS v4.0.1.
- Your processor tells you what it requires. Ask which questionnaire applies.
- You answer a Self-Assessment Questionnaire, or SAQ. The Council says there are several. Each fits a type of setup and has its own eligibility rules.
- You send your answers to your processor, which can ask for them under its merchant agreement.
- You repeat it on the schedule your processor sets. You fix anything you are asked to fix.
A Canadian example
A florist in Gatineau runs a Clover terminal and takes no card numbers by hand. Her processor sends a PCI questionnaire. She leaves it unanswered. Three months later, her statement shows a charge named PCI non-compliance. If that line were $25 a month, it would cost $300 over a year. That amount is invented for the arithmetic. This is an example only, not a quote. Her contract sets the real figure, and finishing the questionnaire may remove the line. She should ask her processor.
What is different in Canada and Québec
- Little differs between Québec and the rest of Canada. PCI DSS is a global standard and the card brands apply it here too.
- Your Canadian processor sets the details in its own contract. The Moneris agreement names PCI DSS as a standard you must follow. It can ask for an expert report or a questionnaire.
- Fiserv Canada's terms say you must follow PCI security standards at all times. You must tell Fiserv Canada within 24 hours of learning of a breach, real or suspected.
- Under the same terms, you pay for a forensic probe and any fixes after a breach. Fiserv Canada may also audit you at your cost.
- The Council says its standards also cover the people who make payment software and devices. Your terminal maker has duties too.
What it costs and where it shows on your statement
The standard itself is free to read. The cost comes from your agreement. Some accounts have a monthly PCI fee. Some add a higher fee if the questionnaire is not done. The Fiserv Canada terms say pending PCI-related fees, fines or assessments can be debited from your account. Look for a line with PCI in its name. Compare it with the fee schedule in your contract. Our card processing fees guide lists these account fees.
Where CleverPays fits in this step
The PCI Security Standards Council writes the standard. The card brands and your processor decide what proof you give. CleverPays does not write PCI DSS. It does not certify anyone as compliant. It does not set Visa, Mastercard or Interac rules. CleverPays is operated by Groupe Heo Inc., an Agent of Fiserv Canada Ltd.
We can read a recent statement with you and show each fee line, including any PCI line. We can explain a fee. We can recommend and set up Clover and other terminals or gateways. We will walk you through what your processor asks for. We answer questions in English and French. We cannot promise a result or guarantee that you are compliant.
Common mistakes
- Ignoring the questionnaire. Left undone, it can lead to a monthly fee.
- Storing card numbers on paper or in a spreadsheet. The Fiserv Canada terms say not to keep card security codes, stripe data or PIN data.
- Thinking one pass is enough. The Moneris agreement asks for proof from time to time. Keep your answers current.
Related terms
- SAQ: the self-check form you fill in to show you follow the rules.
- Tokenization: swapping a card number for a stand-in, so you do not store the real number.
- P2PE: a lock on card data that starts at the terminal.
- PCI non-compliance fee: a charge some processors add when the questionnaire is not done.
- Payment processor: the company that sets your PCI needs.
- Payment gateway: the link that carries online card data, which affects your SAQ.
Common questions
Do small businesses have to follow PCI DSS?
Yes. The Council says PCI DSS applies to every business that handles card account data. Size and volume do not matter. Small merchants often have simpler setups with less card data, so their questionnaire can be shorter.
Who enforces PCI DSS in Canada?
The Council says it does not enforce the rules. Card brands, acquirers and other program owners decide. In practice, your processor asks for proof under its agreement.
What is a SAQ?
It is a Self-Assessment Questionnaire. The Council offers several, each for a different type of setup. Your processor can tell you which one applies to you.
Sources
- PCI Security Standards Council, About us, read 6 October 2026.
- PCI Security Standards Council, Merchants, read 6 October 2026.
- PCI Security Standards Council, Document library, read 6 October 2026.
- Moneris, Merchant Agreement Terms and Conditions, April 2026, read 6 October 2026.
- Fiserv Canada Ltd., Merchant Terms and Conditions (FCL_2810_TC), sections 3.4 and 9.2, read 6 October 2026.
- CleverPays, Card processing fees in Canada, for the list of account fees.
