POS Systems

PCI DSS Compliance for Gas Stations: Complete SAQ Guide

October 8, 2026|6 min read

Figures in this article are being re-verified.

Penalty amounts, deadlines and regulatory citations are being checked against primary sources. Until this notice clears, confirm any figure with your state program before acting on it. Not yet verified. Not legal advice.

Why PCI DSS Compliance Is Non-Negotiable at the Pump

Every time a customer swipes, dips, or taps a payment card at your dispenser or inside your c-store, that transaction is governed by the Payment Card Industry Data Security Standard (PCI DSS)—a contractual requirement enforced by the card brands (Visa, Mastercard, and others) through your acquiring bank. Non-compliance does not carry a federal statutory penalty the way UST violations do, but your processor can impose monthly non-compliance fees, raise your interchange rates, or ultimately terminate your merchant account. A confirmed breach can trigger forensic investigation costs, card-replacement assessments, and fines from the card brands that can reach into the hundreds of thousands of dollars.

For gas station and convenience store operators, PCI DSS compliance is complicated by a unique architecture: you have an indoor point-of-sale (POS) system, outdoor payment terminals (OPTs) mounted on each dispenser, a site controller tying them together, a back-office network, and often a corporate or franchisor network connection layered on top. Understanding exactly which Self-Assessment Questionnaire (SAQ) applies to your environment—and what controls each one demands—is the starting point for a defensible compliance program.

If you want to understand how your POS and dispenser communicate within that architecture, our guide on Passport POS & Dispenser Integration: Compliance Guide covers the technical integration layer that sits beneath your payment security controls.

PCI DSS Versions: Where Things Stand

PCI DSS v4.0.1 is the active standard. Version 3.2.1 was retired on March 31, 2024. If your last assessment was conducted under 3.2.1, your next validation cycle must use v4.0.1. Several requirements that were "best practice" under v4.0 became mandatory on March 31, 2025—including enhanced multi-factor authentication rules and updated e-commerce script controls. Fuel retailers should confirm with their acquiring bank which version governs their current merchant agreement and when their next annual validation is due.

For a detailed breakdown of what changed between versions and the specific deadlines that applied to fuel retailers, see our companion article on PCI DSS v4.0.1 for Fuel Retailers: What Changed and Deadlines.

Understanding the SAQ Framework

The PCI Security Standards Council (PCI SSC) publishes several SAQ forms, each designed for a specific merchant environment. Choosing the wrong form—either because you mischaracterized your environment or because your processor assigned one without reviewing your actual setup—leaves you either over-burdened with irrelevant controls or, more dangerously, under-assessed against real risks.

The SAQ Forms Most Relevant to Fuel Retailers

SAQ Form Who It Fits Key Condition
SAQ A Card-not-present merchants; fully outsourced payment pages No card data touches your systems at all; rarely applies to fuel retail
SAQ B Imprint-only or standalone dial-up terminals with no electronic cardholder data storage Terminal is not connected to any other system or the internet; uncommon in modern fuel retail
SAQ B-IP Standalone IP-connected terminals using a validated P2PE solution Terminal connects via IP but uses a PCI-listed Point-to-Point Encryption solution; no cardholder data on your network
SAQ C Payment application systems connected to the internet; no electronic cardholder data storage POS is internet-connected but does not store card data; common for smaller c-store-only operators
SAQ C-VT Virtual terminal accessed via web browser on an isolated device Rarely applicable to fuel retail
SAQ D (Merchant) All merchants not covered by another SAQ The most comprehensive form; applies to most multi-lane fuel retailers with integrated OPTs and a site controller

Why Most Gas Stations Land on SAQ D

A typical fuel retail site has a site controller (such as a Verifone Commander) connecting indoor POS lanes to outdoor payment terminals (such as Gilbarco FlexPay units or Verifone UX-series terminals) over an IP network. That integrated architecture—where cardholder data flows across your local network between the OPT, the site controller, and potentially a back-office system—almost always disqualifies you from the simpler SAQ forms. SAQ D for Merchants contains over 200 requirements spanning all twelve PCI DSS control domains.

The one significant exception: if your site uses a PCI-listed Point-to-Point Encryption (P2PE) solution that encrypts card data at the OPT before it ever reaches your network, and your processor confirms that solution is validated, you may qualify for SAQ P2PE—a substantially shorter form. Confirm P2PE solution listing status at pcisecuritystandards.org before assuming eligibility.

The Twelve PCI DSS Control Domains: A Fuel Retail Lens

1. Install and Maintain Network Security Controls

Your payment network must be segmented from your general business network, your loyalty systems, your surveillance system, and any guest Wi-Fi. A flat network where the POS, the back-office PC, and the employee Wi-Fi router all share the same subnet is a common finding at fuel retail sites. Firewalls must be configured with documented rulesets, and all default vendor passwords must be changed before equipment goes live.

2. Apply Secure Configurations to All System Components

Every device in your cardholder data environment (CDE)—including the site controller, OPTs, and any back-office servers—must be hardened. Disable unused services and ports. Remove unnecessary software. Document your baseline configuration for each device type.

3. Protect Stored Account Data

Most fuel retailers should not be storing primary account numbers (PANs) at all. If your system logs transaction data, confirm with your POS vendor that PANs are either not stored or are rendered unreadable through truncation or tokenization. Full PANs must never appear in log files, receipts, or database exports.

4. Protect Cardholder Data with Strong Cryptography During Transmission

All cardholder data transmitted across open, public networks must be encrypted using strong cryptography. This applies to the connection between your site controller and your payment processor, and to any remote management sessions into your network. TLS 1.2 is the current minimum; TLS 1.3 is preferred. Older protocols (SSL, TLS 1.0, TLS 1.1) are prohibited.

5. Protect All Systems and Networks from Malicious Software

Anti-malware must be deployed on all system components susceptible to malware. This includes back-office PCs and any Windows-based site controllers. Definitions must be kept current, and scans must run at a defined frequency.

6. Develop and Maintain Secure Systems and Software

Apply security patches to operating systems and payment applications promptly—PCI DSS v4.0.1 sets a risk-based patching timeline. Critical patches must be applied within a defined period after release. Work with your POS vendor and site controller vendor to ensure you are running supported, patched firmware and software versions.

7. Restrict Access to System Components and Cardholder Data by Business Need to Know

Implement role-based access controls. Not every employee needs access to the back-office system, and no employee should have access to cardholder data beyond what their job requires. Document your access control policy.

8. Identify Users and Authenticate Access to System Components

Every user must have a unique ID. Shared logins are prohibited. Multi-factor authentication (MFA) is required for all non-console administrative access into the CDE and for all remote access. Under PCI DSS v4.0.1, MFA is also required for all access into the CDE, not just remote access—a significant expansion that became mandatory on March 31, 2025.

9. Restrict Physical Access to Cardholder Data

This domain is particularly important for fuel retailers. OPTs on dispensers are high-value skimmer targets. PCI DSS requires physical security controls including: tamper-evident seals on OPTs, periodic inspection of terminals for evidence of tampering or substitution, and a documented inspection log. Inspections should occur at a frequency defined in your security policy—many operators conduct them daily during opening or closing routines.

Skimmer detection is also a physical security obligation. Train staff to recognize signs of tampering: loose bezels, misaligned card readers, unexpected overlays, or unusual wiring. For a broader look at physical security at your site, see our guide on Gas Station Cybersecurity: Protect POS, Dispensers & Data.

10. Log and Monitor All Access to System Components and Cardholder Data

Audit logs must be enabled on all in-scope systems. Logs must capture who did what, when, and from where. They must be protected from modification and retained for at least twelve months, with the most recent three months available for immediate analysis. Review logs daily—automated log management tools make this feasible for small operators.

11. Test Security of Systems and Networks Regularly

This domain includes vulnerability scanning and penetration testing. External vulnerability scans must be conducted quarterly by a PCI SSC-approved Authorized Scanning Vendor (ASV). Internal vulnerability scans must also be conducted quarterly. Penetration testing is required at least annually and after significant infrastructure changes. Many independent fuel retailers are surprised to learn that penetration testing is not optional under SAQ D.

12. Support Information Security with Organizational Policies and Programs

You must maintain a documented information security policy, conduct annual security awareness training for all personnel, and have an incident response plan. The incident response plan must be tested at least annually. If you use third-party service providers (payment processors, managed IT vendors, POS support companies), you must maintain a list of them, confirm their PCI DSS compliance status annually, and have written agreements defining their security responsibilities.

The Outdoor Payment Terminal Problem

Fuel retail has a dispenser-specific vulnerability that indoor merchants do not face: the OPT is physically accessible to the public, often in low-supervision conditions, around the clock. The card brands have responded with specific requirements for fuel dispenser OPTs.

EMV at the Dispenser

The card brand liability shift for fuel dispensers has already occurred. If your OPTs are not EMV-capable and a counterfeit card fraud event occurs at your pump, the liability shifts to you rather than the card issuer. Confirm that your OPTs support EMV chip reading and that EMV is enabled and active—not just installed. Processors can confirm whether your terminal IDs are reporting EMV transactions.

PCI PTS and SRED Requirements

OPTs must be on the PCI SSC's list of approved PIN Transaction Security (PTS) devices. Devices must support Secure Reading and Exchange of Data (SRED) to encrypt PIN and card data at the point of capture. Check the PCI SSC's approved device list at pcisecuritystandards.org and confirm that every OPT model deployed at your site appears on that list with a current approval status. Approvals expire, and running an expired-approval device is a compliance finding.

Scoping Your Cardholder Data Environment

Accurate scoping is the foundation of your SAQ. Your CDE includes every system component that stores, processes, or transmits cardholder data, plus every system that could affect the security of those components. Common scoping errors at fuel retail sites include:

  • Forgetting that the site controller is in scope even if it does not store card data, because it routes transactions
  • Treating the back-office PC as out of scope when it shares a network segment with the POS
  • Assuming that loyalty or fleet card systems are out of scope when they share infrastructure with the payment network
  • Overlooking remote access connections used by POS vendors or IT support companies

Network segmentation—implemented correctly with firewalls and verified through penetration testing—is the primary tool for reducing scope. If your loyalty platform, your back-office reconciliation system, and your payment network are all on the same flat network, everything is in scope.

Third-Party Service Providers and Shared Responsibility

Most fuel retailers rely on third parties for critical payment functions: payment processors, POS vendors, managed IT providers, and cloud-based back-office platforms. PCI DSS v4.0.1 requires you to maintain a written list of all third-party service providers (TPSPs) that could affect the security of your CDE, confirm their PCI DSS compliance annually (typically by obtaining their Attestation of Compliance or a letter from their QSA), and document which PCI DSS requirements each party is responsible for versus which you retain.

Do not assume that because your processor is PCI-compliant, you are. Processor compliance covers their infrastructure. Your network, your OPTs, your physical security, your staff training, and your policies remain your responsibility.

SAQ Completion: Step-by-Step Checklist

  1. Confirm your SAQ type with your acquiring bank or payment processor before beginning. Do not self-select without processor confirmation.
  2. Scope your CDE: diagram every system that touches cardholder data and every system connected to those systems.
  3. Inventory all OPTs: model, serial number, PCI PTS approval status, and physical location.
  4. Verify EMV is active on all dispensers, not just installed.
  5. Confirm P2PE solution listing if you are claiming P2PE scope reduction.
  6. Review network segmentation: confirm firewall rules isolate the payment network.
  7. Audit user accounts: remove shared logins, confirm MFA is active for all CDE access.
  8. Check patch levels on all in-scope systems.
  9. Schedule ASV scan if required by your SAQ type.
  10. Conduct or schedule penetration test if required.
  11. Review TPSP list and obtain current AOCs or compliance letters.
  12. Complete the SAQ, sign the Attestation of Compliance, and submit to your processor by the required date.

Consequences of Non-Compliance

PCI DSS penalties are contractual, not statutory, and are assessed by the card brands through your acquiring bank. Consequences can include:

  • Monthly non-compliance fees assessed by your processor
  • Increased interchange rates or surcharges
  • Mandatory forensic investigation costs following a breach
  • Card replacement assessments charged back through your acquirer
  • Suspension or termination of your ability to accept card payments

A breach at an unprotected dispenser—particularly one involving a skimming device—can affect hundreds or thousands of cardholders and trigger assessments that are existential for a small independent operator. The cost of maintaining compliance is a fraction of the cost of a confirmed breach event.

Annual Compliance Calendar

Frequency Activity
Daily Inspect OPTs for physical tampering; review automated log alerts
Quarterly ASV external vulnerability scan; internal vulnerability scan; review firewall rules
Annually Complete and submit SAQ; penetration test; security awareness training for all staff; review and update incident response plan; confirm TPSP compliance status; review and update information security policy
Upon change Re-scope CDE after any significant infrastructure change; re-test after network changes; update TPSP list when vendors change

Sources

  • PCI Security Standards Council, PCI DSS v4.0.1: pcisecuritystandards.org
  • PCI SSC, Self-Assessment Questionnaire Instructions and Guidelines
  • PCI SSC, Approved PTS Devices list
  • PCI SSC, Validated P2PE Solutions list
  • Visa, Mastercard, and card brand merchant compliance program documentation

Next Steps

  1. This week: Contact your acquiring bank or payment processor and confirm which SAQ type applies to your site and when your next submission is due.
  2. This month: Walk every dispenser and inspect each OPT for tamper evidence. Document the inspection. Cross-reference every OPT model against the PCI SSC approved device list.
  3. This quarter: If you have not had an ASV scan in the past 90 days, schedule one. If your network has not been segmented and documented, engage a qualified security assessor or managed IT provider with PCI experience.
  4. Before your next SAQ: Obtain current Attestations of Compliance from every third-party service provider that touches your payment environment. Confirm MFA is active for all CDE access. Verify EMV is enabled and reporting at every dispenser.
  5. Ongoing: Train every employee who handles payment systems or interacts with customers at the pump on skimmer recognition and your incident response procedures. Document the training.
Was this helpful?
Disclaimer: Always verify with your state UST program. Regulations change.