PCI compliance services in Tulsa — take card payments without making your whole network the problem
Every year your processor sends the questionnaire, and every year someone in the office clicks through it hoping the answers are true. Meanwhile the card terminals share a network with the front-desk PC, the guest Wi‑Fi, and a printer nobody has updated since it was installed. You should not need to be a network engineer to accept a credit card.
Who PCI DSS applies to
PCI DSS is not a law — it is the contract you agreed to with your merchant bank. If you accept Visa, Mastercard, Discover, or American Express, it applies to you.
- Any business that stores, processes, or transmits cardholder data, or whose systems could affect its security — retail, restaurants, medical and dental practices, contractors, professional services, nonprofits, and e-commerce alike
- Merchant level is set by transaction volume; most Tulsa businesses of 10 to 100 people are Level 4 (or Level 3) and validate with an annual Self-Assessment Questionnaire and, depending on the SAQ, quarterly external vulnerability scans by an Approved Scanning Vendor
- The SAQ you complete depends on how you take payments: SAQ A for fully outsourced e-commerce, SAQ B or B-IP for standalone terminals, SAQ P2PE for validated point-to-point encryption, SAQ C for payment applications on the network, SAQ D for everything else — and the fewer systems that touch card data, the shorter the questionnaire
- Non-compliance is enforced by your acquirer: monthly fees, higher rates, and — after a breach — fines, forensic investigation costs, card-reissuance costs, and possibly losing the ability to accept cards at all
What PCI DSS requires
PCI DSS v4.0.1 has 12 requirements in six groups. Most of them are the same good hygiene a well-run network already has — the difference is that they must be in place on every system in scope and you must be able to show it.
- Build and maintain a secure network — Firewalls and network security controls at the boundary and between segments; no vendor default passwords or settings on any device in scope, including terminals, routers, and Wi‑Fi.
- Protect account data — Do not store what you do not need; render stored card numbers unreadable; encrypt cardholder data over open, public networks — including your own Wi‑Fi.
- Maintain a vulnerability management program — Anti-malware on systems in scope, and a patching process that closes critical vulnerabilities on a defined timeline; secure configuration of payment applications.
- Implement strong access control — Access to cardholder data limited to people who need it; unique IDs; multi-factor authentication for all access into the cardholder-data environment (a v4.0 change that catches many small businesses); physical access to terminals and media controlled.
- Monitor and test networks — Logging and log review; quarterly internal and external vulnerability scans; annual penetration testing for some SAQs; file-integrity and change detection where the SAQ requires it.
- Maintain an information security policy — A written policy, a risk assessment, security awareness training, screening, incident-response procedures, and oversight of the third parties — processors, gateways, IT providers — that touch card data.
What NSN Management does for PCI compliance
Shrink what is in scope, harden what remains, and keep the evidence — so the annual questionnaire is a review, not a guess.
- Cardholder-data scoping: how card data enters, moves through, and leaves your business, and which systems and people touch it — then reducing that footprint (P2PE terminals, outsourced payment pages, no stored card numbers)
- Network segmentation with WatchGuard firewalls and managed switching so payment terminals and applications are isolated from the office network, guest Wi‑Fi, and everything else
- Secure configuration of firewalls, Wi‑Fi, and payment workstations; vendor defaults removed; encryption on wireless in scope
- Patch management, anti-malware, and endpoint detection and response on every in-scope system
- Unique accounts, least-privilege access, and multi-factor authentication for administrative and remote access to the cardholder-data environment
- Centralized logging with retention and review for in-scope systems
- Coordination of quarterly external vulnerability scans with an Approved Scanning Vendor and remediation of findings; internal scanning where your SAQ requires it
- Documentation: network and data-flow diagrams, an in-scope asset inventory, the written security policy, and evidence organized against your SAQ so the annual attestation is straightforward
- Support answering your processor’s or acquiring bank’s questions, and a review whenever how you take payments changes
What this service is — and isn’t
NSN Management is a managed IT provider, not a PCI Qualified Security Assessor or an Approved Scanning Vendor. For most Tulsa businesses no QSA is required — you self-assess — and we make sure the technical requirements behind that self-assessment are genuinely met and documented. If your volume or your acquirer requires a formal Report on Compliance, we prepare the environment and work with the QSA you engage. Your payment processor and gateway remain responsible for their part of the chain.
How it starts
Where you stand today, what the rule actually asks of a business your size, and the shortest honest path between the two.
Book a Discovery Call
A focused conversation about how PCI DSS touches your business, what you already have in place, and what is being asked of you — no obligation, no scare tactics.
Get a gap assessment
We compare the rule’s requirements to your actual environment and documentation and hand you a plain-language plan: what is done, what is missing, and what to fix first.
Implement, document, maintain
The safeguards go in, the documentation gets written, your people get trained — and the same team keeps it current as the rule and your business change.
What changes for you
- Less in scope — The fewer systems that touch card data, the shorter the questionnaire and the smaller the blast radius.
- A questionnaire you can sign — Answers backed by configurations, scan reports, and diagrams — not hope.
- Fewer surprises on the statement — No non-compliance fees, and no scramble when the acquirer asks a question.
What the gap costs
- A card-data breach traced to a terminal on the same network as an infected office PC — with forensic costs, fines, and card-reissuance charges that dwarf what compliance would have cost
- An SAQ signed with answers nobody verified — no protection when the acquirer asks for evidence after an incident
- Non-compliance fees quietly added to every processing statement
- Card numbers stored in a spreadsheet, an email folder, or a practice-management system because someone once needed them
- Vendor default passwords still on the router, the terminal, or the Wi‑Fi
Compliance from the team that runs your IT
NSN Management is a Tulsa-owned managed IT provider that has run technology for regulated Tulsa-area businesses since 2012. PCI DSS compliance is delivered by the same people who manage your identity, email, devices, network, and backups — so the safeguards are not a binder that drifts away from reality, and the evidence is a by-product of how your IT is run, with timely response and resolution, a truly local team, and regular meetings and communication.
PCI DSS compliance sits under our IT compliance services and leans on cybersecurity services and backup and disaster recovery. Not sure where you stand? Book a Discovery Call.
- 4.8★ Google · 31 reviews
- Kaseya/Datto MSP of the Year 2025
- Inc. 5000 2026
- Tulsa-owned since 2012

Service at a glance
| Framework | PCI DSS (Payment Card Industry Data Security Standard) |
|---|---|
| Part of | IT compliance services · Cybersecurity · Managed IT |
| Also see | HIPAA compliance · FTC Safeguards compliance |
| Service area | Across the Tulsa metro: Tulsa, Broken Arrow, Jenks, Bixby, Sand Springs, Sapulpa, and Owasso |
| Best fit | Organizations with 10–100 people |
| Phone | 918-770-9150 |
Where PCI DSS compliance connects
Cybersecurity services
The firewall, endpoint, identity, and monitoring layers PCI’s requirements describe
Learn more →IT support for CPA & financial firms
Where PCI and the FTC Safeguards Rule usually show up together
Learn more →Managed IT services
Patching, monitoring, and documentation as part of the monthly agreement
Learn more →Your PCI DSS questions, answered
What is PCI compliance, and does a small business really need it?
PCI DSS is the security standard the card brands require of every business that accepts their cards, enforced through your agreement with your merchant bank or processor. Size sets how you validate — most small businesses self-assess with an annual questionnaire — but not whether the standard applies. Yes, a five-person shop with one terminal is expected to comply.
Which SAQ do we need to complete?
It depends on how card data flows through your business. Fully outsourced e-commerce is usually SAQ A; standalone dial-up or IP terminals SAQ B or B-IP; validated point-to-point-encryption terminals SAQ P2PE; payment applications on your network SAQ C; and anything that stores card data electronically or doesn’t fit the others SAQ D. Part of our work is moving you to a simpler SAQ by taking card data off your systems wherever possible.
What does “reducing scope” mean and why does it matter?
Scope is every system, network, and person that stores, processes, transmits, or could affect the security of cardholder data. If your terminals sit on the same flat network as your office PCs, your whole office is in scope. Segmenting payments onto their own network, using P2PE terminals, and never storing card numbers can shrink scope to a handful of devices — which shrinks the questionnaire, the scans, and the risk.
Do we need quarterly vulnerability scans?
If your SAQ requires them — A-EP, B-IP, C, and D do; A, B, and P2PE generally don’t — you need passing quarterly external scans from a PCI Approved Scanning Vendor. We coordinate the scans, fix what they find, and keep the reports with your other evidence.
Does PCI compliance require multi-factor authentication?
PCI DSS v4.0 requires MFA for all access into the cardholder-data environment — not just remote or administrative access, which was the older rule. It is one of the requirements that most often trips up small businesses that were fine under v3.2.1.
Are you a QSA? Can you certify us?
No. NSN Management is a managed IT provider. Most Tulsa businesses do not need a QSA — they self-assess — and our job is to make the technical requirements behind that self-assessment true and documented. If your acquirer requires a formal assessment, we prepare the environment and work alongside the QSA you engage.
We take cards through our practice-management or invoicing software. Are we in scope?
Usually yes, and how much depends on the software and the terminal. Many systems can be configured so card data goes straight from a P2PE terminal or a hosted payment page to the processor and never touches your workstation or database; some store it. We look at the actual data flow and change it where we can.
Do you provide PCI compliance services outside Tulsa?
Yes. NSN Management serves businesses across the Tulsa metro, including Broken Arrow, Jenks, Bixby, Sand Springs, Sapulpa, and Owasso — remotely for the configuration and documentation work, and on-site for network segmentation and terminal placement.
Guides on security and compliance
Plain-language guides for the owner who has to make the technology call without a technology department. All guides →
Azure AD Is Now Microsoft Entra ID: A 2026 Guide for Small Business Owners
You searched for Azure AD and every answer talks about something called Microsoft Entra ID. Same product, new name — here is what it does, what it costs, and which settings actually protect your business.
Read the guide →Cybersecurity Compliance Requirements for Oklahoma Healthcare Practices: HIPAA & Beyond
The EHR vendor wants a signed agreement, the insurance renewal asks about MFA and backups, the card processor sends its annual questionnaire — and somewhere there is supposed to be a risk analysis. Here is what actually applies to an Oklahoma practice, and where to start.
Read the guide →What HIPAA Actually Requires for Business Phone Systems (and What Your Current System Probably Doesn’t Do)
Your phone system takes voicemails about test results, texts patients about appointments, and receives faxes all day. Nobody has ever told you whether any of that is a HIPAA problem — and your phone provider is not volunteering the answer.
Read the guide →Want a questionnaire you can sign with a straight face?
Book a Discovery Call and we’ll map how card data moves through your business and what it would take to shrink and secure it. Or call 918-770-9150.