ISO 9001 certifiedPCI DSS compliantServing business since 1997320,000+ hosted domains99.9% guaranteed uptime24/7 supportISO 9001 certifiedPCI DSS compliantServing business since 1997320,000+ hosted domains99.9% guaranteed uptime24/7 support
Security

PCI DSS Explained for Online Merchants

PCI DSS compliance explained for small to medium e-commerce businesses in Bahrain. What SAQ type you need, the 12 requirements and practical steps to stay compliant without overcomplicating it.

What Is PCI DSS?

PCI DSS (Payment Card Industry Data Security Standard) is a set of 12 security requirements that any business accepting credit card payments must follow. It was created by the major card brands — Visa, Mastercard, American Express, Discover and JCB — to protect cardholder data from theft and fraud.

The standard applies to every business that processes, stores or transmits credit card information, regardless of size. A home-based business selling handmade crafts online must comply. A multinational retailer must comply.

PCI DSS is not a law in most countries, including Bahrain. However, it is mandated by the payment card networks through your acquiring bank. If you accept credit cards, your bank requires PCI DSS compliance as a condition of your merchant account.

Who Needs to Be Compliant?

Any business that accepts credit card payments needs PCI DSS compliance. This includes e-commerce stores, retail businesses with online payments, service businesses that invoice by credit card and subscription-based businesses.

The level of validation depends on your transaction volume. Businesses processing fewer than 20,000 card transactions per year complete a Self-Assessment Questionnaire (SAQ) annually. Larger volumes require more rigorous assessment.

If you use a payment gateway like Stripe, PayTabs or Tap that handles the entire payment process, your compliance burden is significantly lower. The gateway takes responsibility for the card data.

Hosting plays a role too. A PCI DSS-compliant hosting provider (like Almada) ensures the server environment meets the security requirements. Our hosting infrastructure is designed with PCI compliance in mind.

SAQ Types — Which One Applies to You

The Self-Assessment Questionnaire (SAQ) is the compliance validation form for most small to medium businesses. Choosing the right SAQ type is important.

SAQ A — For businesses that fully outsource card processing and do not store, process or transmit any card data on their own systems. This is the simplest SAQ, with only 22 requirements. Most Bahrain businesses using a redirect-to-gateway payment method qualify.

SAQ A-EP — For e-commerce businesses that use a payment form embedded on their website. The card data passes through your server, requiring more controls.

SAQ B — For businesses using only imprint or dial-up terminals with no electronic card data storage. Rare for online businesses.

SAQ D — The most comprehensive SAQ, with over 250 requirements. Required for businesses that store, process or transmit card data on their own systems. Most small businesses should avoid this by using a redirect payment gateway.

The 12 Requirements Overview

PCI DSS is organised around 12 core requirements. Here is a simplified overview.

1. Install and maintain a firewall. Protect cardholder data with properly configured firewalls and network segmentation.

2. Change vendor defaults. Remove default passwords and configurations from all systems. One of the simplest and most overlooked requirements.

3. Protect stored cardholder data. Do not store card data unless absolutely necessary. If you must store it, encrypt it using strong cryptography.

4. Encrypt transmission. Cardholder data sent across public networks must be encrypted with strong TLS.

5. Use anti-virus software. Protect all systems against malware.

6. Secure systems and applications. Keep all software up to date with security patches.

7. Restrict access by need-to-know. Only employees who need cardholder data should have access to it.

8. Assign unique IDs. Every person with system access must have a unique username and password.

9. Restrict physical access. For cloud-hosted environments, this is managed by the hosting provider.

10. Track and monitor all access. Log all access to cardholder data and review logs regularly.

11. Test security systems. Conduct quarterly network scans by an Approved Scanning Vendor and annual penetration testing.

12. Maintain a security policy. Document your security policies and review them annually.

Steps to Achieve and Maintain Compliance

Here is a practical step-by-step process to achieve and maintain PCI DSS compliance for your Bahrain business.

Step 1: Determine your SAQ type with help from your acquiring bank or payment gateway. Most small Bahrain businesses qualify for SAQ A or SAQ A-EP.

Step 2: Complete the Self-Assessment Questionnaire. Work through each requirement honestly.

Step 3: Remediate any gaps the SAQ identifies. Common gaps include outdated software, missing firewall rules, weak passwords and missing security policies.

Step 4: Schedule quarterly network scans with an Approved Scanning Vendor if your SAQ type requires it.

Step 5: Submit your completed SAQ, scan results and Attestation of Compliance to your acquiring bank.

Step 6: Repeat annually. PCI compliance is not a one-time project. Set a calendar reminder to revalidate every 12 months.

Your hosting provider can help with many of these steps.

Your Hosting Provider’s Role in PCI Compliance

Your hosting provider plays a significant role in your PCI compliance. Many of the 12 requirements relate to the server environment, which the hosting provider manages.

A PCI-compliant hosting provider maintains firewalls, applies security patches, monitors access logs, restricts physical access to servers and provides secure network architecture. Using a compliant provider automatically satisfies several requirements.

When evaluating a host for your e-commerce site, ask whether their infrastructure is PCI compliant. If they cannot answer clearly, that is a red flag. Almada’s hosting environment is built with PCI DSS requirements in mind, which simplifies compliance for our clients.

Even with a PCI-compliant host, your business remains responsible for requirements related to your application layer. The host covers the infrastructure; you cover the application.

Need help putting this into practice? We build, host and market business websites from Bahrain and across the Gulf. Talk to us.
Questions

Frequently asked questions

PCI DSS (Payment Card Industry Data Security Standard) is a set of 12 security requirements that any business that accepts, transmits or stores credit card data must follow. It is mandated by the major card brands.

Any business that accepts credit card payments must comply, regardless of size. Micro-businesses using a payment form embedded by their gateway still need to complete the relevant SAQ.

SAQ A is for fully outsourced processing. SAQ A-EP for embedded forms. SAQ B for dial-up terminals. SAQ D is the most comprehensive, for businesses that store card data.

Non-compliance can result in fines from your acquiring bank, increased transaction fees, and potentially the loss of your ability to accept credit card payments.

No. You must complete the SAQ annually, pass quarterly network scans and maintain security controls throughout the year.

Put this to work on your site

Send us the brief and we will tell you what it takes, what it costs and how long it will run.

WhatsApp us