EPISODE · Aug 20, 2026 · 33 MIN
PCI FAQs When You’re Starting Your Compliance Program - Episode 230
from Compliance Unfiltered With Adam Goslin · host Total Compliance Tracking
Think PCI compliance is something you can outsource? Think again. Todd Coshow and Adam Goslin break down the biggest misconceptions about PCI DSS, from third-party payment processors and SAQs to merchant versus service provider responsibilities. Learn why outsourcing payment processing doesn't eliminate your compliance obligations, how scope really works, and why treating PCI as a one-time paperwork exercise creates unnecessary risk. This episode is essential listening for merchants, service providers, and anyone navigating PCI compliance for the first time.Episode Transcript:Now, Adam, a long time ago in a land far, far away, there was a time where you asked the question, “What is PCI?” So bring the listeners up to speed on that.Adam Goslin:Everybody gets their start somewhere, and PCI was definitely mine.I had kinda made my way up the IT management ranks. Boss comes by. Don’t ask me why, he decided to print the entirety of the PCI standards, but literally drops a four-inch deck of paper on my desk and says, “Hey, we need to get compliant with this.”I’m looking at the cover page, and it says PCI on it, and I literally said, “What’s PCI?”So that was my entree into the land of security and compliance.I sat there staring at this volume of information and wondering, “What the hell do I do with this? Where do I go? How do I start?” etc.It’s part of why I decided to step into the space to help people, because I clearly remember just how overwhelming it felt to be looking at that much stuff, not having any clue what the hell it was, what it meant, what it’s for, does it even apply to us, etc.All the way around, it was very overwhelming to step into the compliance arena not already having been initiated.TCT has, both I and TCT have kinda specialized in PCI since our inception, and the consulting work that I was doing for folks in the space, the history of the consulting practice goes back even further than PCI’s existence.As we were sitting there and contemplating the types of things that organizations new to the space are facing, we decided to put together this almost like a frequently asked questions when you’re getting a compliance program off the ground.Frequently asked PCI questions when you’re getting a compliance program off the ground.Todd Coshow:Does PCI apply to merchants who outsource all payment processing?Adam Goslin:It’s one of the common questions that I’ll get.They’ll be like, “Oh, well, we don’t touch anything. We go ahead and outsource all of our payment stuff to blabbity-blah. That’s not my problem, and PCI doesn’t apply to us.”The answer is you’re wrong.Companies that are not storing, processing, transmitting, or receiving cardholder data, they still are subject to the PCI DSS.One of the biggest misunderstandings is, sure, there’s some technical elements of how you’ve done what you’ve done in terms of the connectivity. The devil’s always in the details.If you have a merchant account that is in any way, shape, or form receiving payments via credit cards, then you too get to fill out your PCI paperwork.That’s one of the biggest misunderstandings that organizations have.Honestly, a lot of the big names that have come out in the space over time, the Stripes, the Squares, the Intuits, if you will, back in the day, it was like the Wild West.“Well, I’ll just go get a Stripe account, so I don’t have to worry about this.”“Go process my stuff through Intuit, that way I don’t have to worry about it.”The unfortunate part is that those organizations were on this mad race to get people to jump over to their platform and process their stuff via their platform, but they weren’t really doing a great job with enforcing, mandating that people were actually following the PCI DSS.That kind of became a problem for a while because they were able to go in and easily turn it on, etc., and there wasn’t any enforcement arm that was coming at them.
Embed this episode
Ready to play
PCI FAQs When You’re Starting Your Compliance Program - Episode 230
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.