Your company may not be technical, but its payments already are
Terminals, payment links, online stores, applications and external providers are part of everyday operations. Understanding their role and protecting the data they use is now a business responsibility.
- Author
- Federico Arenas
- Last reviewed
- August 11, 2026
A company does not need to think of itself as a technology company to depend on technology.
A travel agency takes payments through a terminal at its office, sends payment links to certain customers and accepts reservations by phone. A school collects tuition through its portal. A nonprofit organization receives card donations. A retailer sells both at the counter and online. None of these organizations necessarily describes itself as a technology company.
Yet every payment can depend on devices, websites, applications, networks and external companies. It can also involve employees who view a screen, answer a call, enter information or resolve a declined transaction. What management sees as a simple act—taking a payment—is actually part of a technological journey.
The question is no longer whether a company wants to participate in a digital economy separate from the everyday economy. Technology is already embedded in how it sells, gets paid and interacts with customers. The real question is this: does the organization understand how its payments work and what it needs to do to protect them?
Money has changed, and security must keep pace
This transformation is not abstract. Banco de México reported that, between 2015 and 2025, the volume of transactions made through point-of-sale terminals grew by an annual average of 16.9%. By March 2025, 6.7 million terminals were being operated by bank and non-bank acquirers and payment aggregators in Mexico.
E-commerce advanced even faster. Between 2016 and 2025, card transactions in this channel grew by an annual average of 45.7% in volume and 32.1% in real value. These figures do not describe a future practice or one reserved for large companies. They describe the infrastructure already used by retailers, schools, organizations, travel agencies and service providers.
Money has changed. Business security must keep pace.
Accepting cards allows businesses to sell remotely, automate collections, simplify renewals, receive donations and reach new markets. But every new payment method also introduces decisions: which provider to engage, what information employees may receive, which devices are used, what happens to receipts, who updates the website and how the organization responds to an incident.
Every payment follows a journey
A transaction does not take place only inside a terminal, nor does it disappear when the word “approved” appears. Depending on the channel, the journey may involve the customer, their card data, the employee assisting them, a device, a network, an internal system, a website, a gateway, a processor, an aggregator and an acquiring bank.
In a normal operation, data could appear in places management has never connected with the payment process: a notebook used to record information during a call, a messaging conversation, a recording, an email, a screenshot, a downloaded report or a computer used to access a virtual terminal.
Not every scenario exists in every company. That is precisely why the first task is not to adopt a generic checklist of controls, but to reconstruct the actual payment journey: where it begins, who can see it, which systems it touches, who processes it and what information remains afterward.
Understanding payments is the first step toward protecting them.
When that journey is unknown, an organization may protect what it assumes is important while overlooking the point where exposure actually exists. It may also select a questionnaire that does not match its operation, respond based on what its provider does rather than what the company itself does, or claim to maintain a practice that no one has actually assigned or documented.
Technology can be delegated; responsibility cannot be delegated completely
Engaging a terminal provider, payment gateway or specialized platform is often a sound decision. The right provider can significantly reduce a company's exposure and simplify its compliance effort. Outsourcing processing, however, does not eliminate every responsibility.
The PCI Security Standards Council explains that even when a merchant outsources all payment processing and does not directly store, process or transmit card data, it must ensure that the provider is compliant for the services offered, maintain agreements that define responsibilities, monitor the provider's compliance status and understand any shared responsibilities.
This requires more than asking, “Is my provider PCI DSS compliant?” The company needs to understand which service it contracted, which portion of the payment journey the third party performs, which activities remain within the business and what evidence is available to support that relationship.
Using third-party technology can reduce scope; it does not replace an understanding of your own operation.
Why PCI DSS can feel so distant
For many small and medium-sized businesses, PCI DSS first appears as an unexpected request: a bank, customer, card brand, business partner or acquirer asks for an SAQ, an attestation or evidence of compliance. The company receives lengthy documents, specialized terminology and several possible questionnaires, but little guidance for connecting them with its everyday operation.
That distance is real. A small organization may not have a security department, a dedicated compliance owner or personnel accustomed to interpreting technical standards. The same people who manage the business, sell, assist customers or coordinate providers must also determine what applies to them.
This difficulty does not mean that PCI DSS is reserved for large corporations. PCI SSC states that the standard is intended for merchants regardless of their size or transaction volume. It also recognizes that small merchants often have simpler environments, with fewer systems and less data to protect, which can reduce the compliance effort. The specific obligation to validate and report compliance must be confirmed with the relevant acquirer or payment brand.
The answer is not to simplify the standard artificially or complete it on behalf of the company. The answer is to translate the applicable requirements into the company's reality: decisions, owners, tasks, evidence and practices that can be sustained.
What PCI DSS actually proposes
PCI DSS provides a common baseline of technical and operational requirements designed to protect payment account data. It applies not only to those that store, process or transmit card data, but also to organizations and systems that could affect the security of the environment where that data is handled.
Viewed only as an annual questionnaire, the standard can seem like a collection of questions. Viewed through the operation, it proposes a logical order: understand where payment data exists, reduce its exposure, protect systems and devices, control access, manage third parties appropriately, detect problems, assign responsibilities and retain evidence of what the organization does.
This change in perspective is decisive. An affirmative answer in an SAQ does not create the control it declares; it has value only when it corresponds to an actual practice. Likewise, collecting documents without connecting them to the operation may create the appearance of compliance, but not an effective security capability.
PCI DSS also does not guarantee that an attack or incident will never occur. Its value lies in establishing a consistent baseline for reducing risk, protecting information more effectively and demonstrating that applicable controls have been understood, implemented and maintained.
Payment security is a business decision
Payments are often assigned to finance or technology, but protecting them extends across the organization. Management authorizes providers and resources. Operations defines procedures. Human resources incorporates responsibilities and training. Customer service determines what may be received by phone or messaging. E-commerce manages the website. Procurement formalizes contracts and obtains third-party documentation.
PCI DSS should therefore not remain a task that someone resolves once a year in front of a form. Management needs to ensure that the organization has a complete view of its payment channels, that every responsibility has an owner and that controls do not disappear after the declaration is submitted.
One simple question can reveal how prepared the organization is: if an incident involving card data occurred tomorrow, would the company know which people, systems, providers and procedures were involved?
If the answer is unclear, the problem is not limited to IT. It is a gap in business knowledge and coordination.
The first step is not completing a questionnaire
Before determining which SAQ applies or beginning to answer it, a company needs to build a reliable picture of its operation. Five questions can begin that work:
- Through which channels does the organization accept card payments?
- Can anyone see, hear, write down or receive card data at any point?
- Which devices, websites, applications, networks or systems are involved?
- Which providers participate, and what function does each one perform?
- Who within the company oversees the security and continuity of this operation?
These answers do not determine the entire PCI DSS route on their own, but they reveal the true shape of the payment environment. They also help uncover common contradictions: a channel no one had included, a provider whose responsibility is not documented, an informal employee practice or a system believed to be unrelated to the transaction.
Operating today means understanding and protecting payments
Your company may not build technology or sell digital services. But if it accepts cards, a critical part of its operation already depends on technological systems, devices and providers. Understanding that environment does not require turning management into technical specialists. It requires starting with the right questions, assigning responsibilities and following an orderly route.
The fact that no one has yet requested a compliance declaration does not mean the organization is protected. Nor does it mean the company must operate under a constant sense of threat. It means the organization has an opportunity to strengthen a capability it already needs: understanding how it gets paid, reducing unnecessary exposure and sustaining practices that protect its customers and its own business.
PCI DSS can provide that route. Entavira helps turn it into understanding, implementation, evidence and follow-up connected with the reality of each organization.
Identify your PCI DSS route
Answer a few questions about how your organization accepts payments, which channels it uses and which providers participate. Receive initial guidance about your starting point and the route that may apply.
Initial guidance must be confirmed against the actual operation and the requirements of the entity requesting validation.
Sources and review
- Banco de México — Annual report on financial services and payments, July 2024 to June 2025Reviewed: August 11, 2026
- PCI SSC FAQ 1092 — Responsibilities when payment processing is outsourcedReviewed: August 11, 2026
- PCI SSC FAQ 1022 — PCI DSS applicability to small merchantsReviewed: August 11, 2026
- PCI SSC — PCI Data Security StandardReviewed: August 11, 2026
This content is informational and is not legal advice. The applicable route and validation method depend on the operation and requesting party.
Leer en español