Restaurant PCI Compliance: What You Must Do

Restaurant PCI compliance is one of those obligations that arrives as a form from your payment processor, gets filled in as fast as possible, and is never thought about again until something goes wrong.

That is understandable and it is a mistake, because the consequences of a card breach fall on the restaurant far more heavily than most owners expect. This article explains what the requirements actually are, without the jargon.

EMV chip card reader with a credit card inserted
Chip readers keep card data out of your systems — the single biggest compliance win.

What PCI DSS is, briefly

PCI DSS is a security standard written by the card brands — Visa, Mastercard, American Express and others. It is not a law. It is a contractual condition of being allowed to accept cards, which in practice makes it just as binding.

It applies to every business that accepts card payments. There is no small-business exemption. What changes with size is how you demonstrate compliance, not whether you must.

Why it matters more than the paperwork suggests

If card data is stolen through your restaurant, the costs land in several places at once: forensic investigation, card brand fines, reissuing costs for affected cards, potential liability for fraudulent transactions, and the reputational damage of being named.

Restaurants are a repeated target for a specific reason. They take a high volume of card payments, often run older equipment, frequently share a network between the POS and the guest wi-fi, and rarely have anyone whose job is security.

The uncomfortable truth is that the cheapest way to be compliant is also the cheapest way to be secure: never let card data into your systems in the first place.

Which SAQ applies to you

Most restaurants demonstrate compliance with a Self-Assessment Questionnaire. Which one depends on how you take payments:

SituationQuestionnaireDifficulty
Standalone terminal on a phone lineSAQ BEasiest
Terminal with point-to-point encryptionSAQ B-IP or P2PEEasy
POS connected to the internet, no card storageSAQ CModerate
Online ordering handled entirely by a third partySAQ AEasiest
Online ordering partly on your own siteSAQ A-EPHarder
Card data stored or processed on your systemsSAQ DHardest

The practical implication is worth stating plainly: the further card data stays from your own equipment, the shorter your questionnaire and the smaller your risk. Using point-to-point encrypted readers and a fully hosted payment page for online orders can move you from a several-hundred-question assessment to a couple of dozen.

Diagram showing how card payments are processed through ORO POS
The fewer of your own systems that touch card data, the smaller your compliance burden.

The practical restaurant card data security checklist

Ignoring the formal control numbers, this is what genuinely improves restaurant card data security in a working venue:

  • Never write card numbers down. Not on a pad, not in the reservation notes, not in a text message. This is still the most common failure in restaurants.
  • Separate your networks. Guest wi-fi must not be on the same network as the POS. This is one setting on most routers and it removes an entire category of risk.
  • Change default passwords. On the router, on the POS, on the card terminals. Default credentials are published online for every device model.
  • Use chip and contactless. Encrypted readers mean the card number never reaches your POS in usable form.
  • Inspect terminals. Skimming devices get physically attached to card readers. Check them, and log that you checked.
  • Keep the software updated. POS, operating system and terminal firmware.
  • Limit who has admin access. Individual logins for every member of staff, so activity is attributable.
  • Do not store what you do not need. No full card numbers, and never the security code. Ever.

Most restaurants that fail an assessment fail on the first three items, and all three are free to fix.

Who is actually responsible

A common misunderstanding is that using a well-known POS or processor makes the restaurant compliant. It does not. Compliance is shared: the vendor is responsible for their software and hardware being validated, and the restaurant is responsible for how it is deployed and operated.

A validated, PCI-compliant terminal plugged into a flat network shared with guest wi-fi, using a default password, is a non-compliant installation of a compliant product. The certificate belongs to the vendor; the obligation stays with you.

Online ordering and the extra exposure

Taking orders through your own website adds a second place card data can leak. The safest arrangement is that payment happens on a page hosted by the payment provider rather than on your own server, which keeps you on the shortest questionnaire.

If you are setting this up, our guide to POS and website integration covers the connection, and online ordering management systems covers the wider setup. The payments page lists the processors ORO POS works with, all of which support encrypted readers and hosted payment pages.

Close-up of a card payment terminal in a restaurant
Terminals are physical assets — inspect them as routinely as you count the till.

The part that is about people, not technology

Most restaurant card incidents do not involve sophisticated hacking. They involve someone being helpful.

The recurring pattern is a phone call to a busy venue from someone claiming to be from the POS vendor or the processor, asking a staff member to read out a code, install a remote-access tool, or confirm a password. During service, with a queue building, people comply.

The defence is a standing rule that every member of staff knows: nobody gives out system access over the phone, ever, regardless of who they claim to be. Calls get taken as a message and returned on a number you already hold. Make it a rule rather than a judgement call, because judgement is exactly what a busy service erodes.

The same applies to card details. A guest who phones and offers a card number over the phone is creating a record you should not hold. Take the booking, take payment on arrival.

What happens if there is a breach

It is worth knowing the sequence, because it explains why the preventative work is cheap by comparison. A breach is usually detected not by the restaurant but by the card brands noticing a pattern of fraud with your venue as the common point of purchase.

From there: your processor is notified, a forensic investigator is appointed at your cost, your card acceptance may be suspended while the investigation runs, and fines and card-reissuing costs are assessed afterwards. Restaurants have closed over this, and the operational disruption of losing card acceptance mid-investigation is often worse than the fines.

Restaurant PCI compliance done properly is, in practice, insurance against a sequence that is disproportionately expensive relative to the effort of avoiding it.

What to do this month

  • Ask your processor which SAQ you are on and when it was last completed.
  • Confirm guest wi-fi is on a separate network from the POS.
  • Change every default password on network and payment equipment.
  • Confirm your card readers use point-to-point encryption.
  • Give each staff member their own POS login.
  • Write down who is responsible for this. In most restaurants the honest answer is nobody, and that is the actual problem.

Restaurant PCI compliance is not really a paperwork exercise. It is a small set of habits that keep card data out of your building, and the annual questionnaire is just the moment you confirm those habits are still in place.

Related guides

Leave a Reply

Your email address will not be published. Required fields are marked *