Compliance · PCI DSS

PCI compliance services in Tulsa — take card payments without making your whole network the problem

Every year your processor sends the questionnaire, and every year someone in the office clicks through it hoping the answers are true. Meanwhile the card terminals share a network with the front-desk PC, the guest Wi‑Fi, and a printer nobody has updated since it was installed. You should not need to be a network engineer to accept a credit card.

Quick answer: NSN Management provides PCI DSS compliance services for Tulsa-metro businesses that accept card payments: cardholder-data scoping and reduction, network segmentation, firewall and Wi‑Fi configuration, patching and endpoint protection, access controls and MFA, logging, quarterly vulnerability scanning support, and the documentation behind your Self-Assessment Questionnaire — implemented and maintained by a Tulsa-owned IT team.
Who it applies to

Who PCI DSS applies to

PCI DSS is not a law — it is the contract you agreed to with your merchant bank. If you accept Visa, Mastercard, Discover, or American Express, it applies to you.

  • Any business that stores, processes, or transmits cardholder data, or whose systems could affect its security — retail, restaurants, medical and dental practices, contractors, professional services, nonprofits, and e-commerce alike
  • Merchant level is set by transaction volume; most Tulsa businesses of 10 to 100 people are Level 4 (or Level 3) and validate with an annual Self-Assessment Questionnaire and, depending on the SAQ, quarterly external vulnerability scans by an Approved Scanning Vendor
  • The SAQ you complete depends on how you take payments: SAQ A for fully outsourced e-commerce, SAQ B or B-IP for standalone terminals, SAQ P2PE for validated point-to-point encryption, SAQ C for payment applications on the network, SAQ D for everything else — and the fewer systems that touch card data, the shorter the questionnaire
  • Non-compliance is enforced by your acquirer: monthly fees, higher rates, and — after a breach — fines, forensic investigation costs, card-reissuance costs, and possibly losing the ability to accept cards at all
What the rule says

What PCI DSS requires

PCI DSS v4.0.1 has 12 requirements in six groups. Most of them are the same good hygiene a well-run network already has — the difference is that they must be in place on every system in scope and you must be able to show it.

  • Build and maintain a secure networkFirewalls and network security controls at the boundary and between segments; no vendor default passwords or settings on any device in scope, including terminals, routers, and Wi‑Fi.
  • Protect account dataDo not store what you do not need; render stored card numbers unreadable; encrypt cardholder data over open, public networks — including your own Wi‑Fi.
  • Maintain a vulnerability management programAnti-malware on systems in scope, and a patching process that closes critical vulnerabilities on a defined timeline; secure configuration of payment applications.
  • Implement strong access controlAccess to cardholder data limited to people who need it; unique IDs; multi-factor authentication for all access into the cardholder-data environment (a v4.0 change that catches many small businesses); physical access to terminals and media controlled.
  • Monitor and test networksLogging and log review; quarterly internal and external vulnerability scans; annual penetration testing for some SAQs; file-integrity and change detection where the SAQ requires it.
  • Maintain an information security policyA written policy, a risk assessment, security awareness training, screening, incident-response procedures, and oversight of the third parties — processors, gateways, IT providers — that touch card data.
Included

What NSN Management does for PCI compliance

Shrink what is in scope, harden what remains, and keep the evidence — so the annual questionnaire is a review, not a guess.

  • Cardholder-data scoping: how card data enters, moves through, and leaves your business, and which systems and people touch it — then reducing that footprint (P2PE terminals, outsourced payment pages, no stored card numbers)
  • Network segmentation with WatchGuard firewalls and managed switching so payment terminals and applications are isolated from the office network, guest Wi‑Fi, and everything else
  • Secure configuration of firewalls, Wi‑Fi, and payment workstations; vendor defaults removed; encryption on wireless in scope
  • Patch management, anti-malware, and endpoint detection and response on every in-scope system
  • Unique accounts, least-privilege access, and multi-factor authentication for administrative and remote access to the cardholder-data environment
  • Centralized logging with retention and review for in-scope systems
  • Coordination of quarterly external vulnerability scans with an Approved Scanning Vendor and remediation of findings; internal scanning where your SAQ requires it
  • Documentation: network and data-flow diagrams, an in-scope asset inventory, the written security policy, and evidence organized against your SAQ so the annual attestation is straightforward
  • Support answering your processor’s or acquiring bank’s questions, and a review whenever how you take payments changes

What this service is — and isn’t

NSN Management is a managed IT provider, not a PCI Qualified Security Assessor or an Approved Scanning Vendor. For most Tulsa businesses no QSA is required — you self-assess — and we make sure the technical requirements behind that self-assessment are genuinely met and documented. If your volume or your acquirer requires a formal Report on Compliance, we prepare the environment and work with the QSA you engage. Your payment processor and gateway remain responsible for their part of the chain.

The plan

How it starts

Where you stand today, what the rule actually asks of a business your size, and the shortest honest path between the two.

  1. Book a Discovery Call

    A focused conversation about how PCI DSS touches your business, what you already have in place, and what is being asked of you — no obligation, no scare tactics.

  2. Get a gap assessment

    We compare the rule’s requirements to your actual environment and documentation and hand you a plain-language plan: what is done, what is missing, and what to fix first.

  3. Implement, document, maintain

    The safeguards go in, the documentation gets written, your people get trained — and the same team keeps it current as the rule and your business change.

Outcomes

What changes for you

  • Less in scopeThe fewer systems that touch card data, the shorter the questionnaire and the smaller the blast radius.
  • A questionnaire you can signAnswers backed by configurations, scan reports, and diagrams — not hope.
  • Fewer surprises on the statementNo non-compliance fees, and no scramble when the acquirer asks a question.

What the gap costs

  • A card-data breach traced to a terminal on the same network as an infected office PC — with forensic costs, fines, and card-reissuance charges that dwarf what compliance would have cost
  • An SAQ signed with answers nobody verified — no protection when the acquirer asks for evidence after an incident
  • Non-compliance fees quietly added to every processing statement
  • Card numbers stored in a spreadsheet, an email folder, or a practice-management system because someone once needed them
  • Vendor default passwords still on the router, the terminal, or the Wi‑Fi

Compliance from the team that runs your IT

NSN Management is a Tulsa-owned managed IT provider that has run technology for regulated Tulsa-area businesses since 2012. PCI DSS compliance is delivered by the same people who manage your identity, email, devices, network, and backups — so the safeguards are not a binder that drifts away from reality, and the evidence is a by-product of how your IT is run, with timely response and resolution, a truly local team, and regular meetings and communication.

PCI DSS compliance sits under our IT compliance services and leans on cybersecurity services and backup and disaster recovery. Not sure where you stand? Book a Discovery Call.

An NSN Management team member working across service dashboards

Service at a glance

Key facts about NSN Management’s PCI DSS compliance services
FrameworkPCI DSS (Payment Card Industry Data Security Standard)
Part ofIT compliance services · Cybersecurity · Managed IT
Also seeHIPAA compliance · FTC Safeguards compliance
Service areaAcross the Tulsa metro: Tulsa, Broken Arrow, Jenks, Bixby, Sand Springs, Sapulpa, and Owasso
Best fitOrganizations with 10–100 people
Phone918-770-9150
FAQ

Your PCI DSS questions, answered

What is PCI compliance, and does a small business really need it?

PCI DSS is the security standard the card brands require of every business that accepts their cards, enforced through your agreement with your merchant bank or processor. Size sets how you validate — most small businesses self-assess with an annual questionnaire — but not whether the standard applies. Yes, a five-person shop with one terminal is expected to comply.

Which SAQ do we need to complete?

It depends on how card data flows through your business. Fully outsourced e-commerce is usually SAQ A; standalone dial-up or IP terminals SAQ B or B-IP; validated point-to-point-encryption terminals SAQ P2PE; payment applications on your network SAQ C; and anything that stores card data electronically or doesn’t fit the others SAQ D. Part of our work is moving you to a simpler SAQ by taking card data off your systems wherever possible.

What does “reducing scope” mean and why does it matter?

Scope is every system, network, and person that stores, processes, transmits, or could affect the security of cardholder data. If your terminals sit on the same flat network as your office PCs, your whole office is in scope. Segmenting payments onto their own network, using P2PE terminals, and never storing card numbers can shrink scope to a handful of devices — which shrinks the questionnaire, the scans, and the risk.

Do we need quarterly vulnerability scans?

If your SAQ requires them — A-EP, B-IP, C, and D do; A, B, and P2PE generally don’t — you need passing quarterly external scans from a PCI Approved Scanning Vendor. We coordinate the scans, fix what they find, and keep the reports with your other evidence.

Does PCI compliance require multi-factor authentication?

PCI DSS v4.0 requires MFA for all access into the cardholder-data environment — not just remote or administrative access, which was the older rule. It is one of the requirements that most often trips up small businesses that were fine under v3.2.1.

Are you a QSA? Can you certify us?

No. NSN Management is a managed IT provider. Most Tulsa businesses do not need a QSA — they self-assess — and our job is to make the technical requirements behind that self-assessment true and documented. If your acquirer requires a formal assessment, we prepare the environment and work alongside the QSA you engage.

We take cards through our practice-management or invoicing software. Are we in scope?

Usually yes, and how much depends on the software and the terminal. Many systems can be configured so card data goes straight from a P2PE terminal or a hosted payment page to the processor and never touches your workstation or database; some store it. We look at the actual data flow and change it where we can.

Do you provide PCI compliance services outside Tulsa?

Yes. NSN Management serves businesses across the Tulsa metro, including Broken Arrow, Jenks, Bixby, Sand Springs, Sapulpa, and Owasso — remotely for the configuration and documentation work, and on-site for network segmentation and terminal placement.

Want a questionnaire you can sign with a straight face?

Book a Discovery Call and we’ll map how card data moves through your business and what it would take to shrink and secure it. Or call 918-770-9150.