PCI DSS applies to any entity that stores, processes, or transmits cardholder data, or that could affect the security of the cardholder data environment. Industry is irrelevant. A cash-only dispensary is out of scope; the moment you run PIN debit, take cards for delivery or online orders, or accept them at an ancillary business, you are in — and your acquirer, not the PCI Council, decides how you have to prove it.
The short version
- Scope follows the card data. "We are cannabis so PCI does not apply" is not how the standard works.
- Validation requirements come from your acquirer or payment brand, not from PCI SSC.
- Payment workarounds are unstable. Mastercard halted cannabis debit purchases in 2023, and operators lost roughly 20% of in-store transactions overnight.
Who has to comply with PCI DSS?
The PCI Security Standards Council's own language is the clearest test. PCI DSS applies to "entities that store, process, or transmit cardholder data and/or sensitive authentication data or could impact the security of the cardholder data environment," including merchants, processors, acquirers, issuers, and service providers.
There is no cannabis carve-out, because the standard was never written by industry. It follows the data.
Our dispensary is cash-only. Are we out of scope?
For the retail floor, yes. For the business, check again before you answer.
Card data has a habit of appearing in places nobody mapped: a delivery service that takes payment online, an ancillary storefront selling non-cannabis goods, a ticketed event, an e-commerce site for merchandise, a phone order taken at the front desk and written on a sticky note. Any one of those brings a piece of your environment into scope.
Do the walk before you claim exemption. "Cash-only" is usually a description of the register, not of the company.
What about PIN debit and cashless ATM setups?
Those are card transactions, and they carry card obligations.
They are also the least stable part of a dispensary's operation. When Mastercard moved in 2023 to halt cannabis purchases on its debit cards, retailers reported that Mastercard transactions had accounted for close to 20% of in-store volume, and they went back to directing customers to the ATM. More recent reporting describes the same pattern continuing as loosely coded merchant accounts get shut down without warning and funds are frozen while payroll waits.
The security lesson is a continuity lesson. If a payment method can disappear on a Tuesday, your cash-handling procedure, your queue plan, and your reconciliation process need to already exist.
Who decides what we have to do to prove compliance?
Not the PCI Council. Its documentation is explicit: whether an entity must comply with or validate compliance to a PCI standard "is at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity."
In practice that means read your merchant agreement. It names your validation obligation — typically a Self-Assessment Questionnaire of a specific type, sometimes quarterly scanning by an approved vendor — and it sets the penalties. Two dispensaries with identical setups can owe different paperwork because they signed with different acquirers.
Which SAQ applies to us?
It depends on how card data flows, and getting this wrong is the most common mistake.
The general shape: a merchant using a standalone, validated payment terminal with no electronic cardholder-data storage faces a much shorter questionnaire than one whose POS software touches card data or whose website accepts payment directly. Redirecting checkout to a hosted page reduces scope; embedding a payment form in your own page does not reduce it nearly as much as people assume.
Ask your acquirer to confirm the SAQ type in writing. Then have someone technical confirm the answer matches how your system actually works, because the sales engineer's diagram and the deployment are not always the same document.
What does PCI DSS v4.0.1 change for a small merchant?
Version 4.x raised the floor in ways that reach small merchants, mostly around authentication and payment-page integrity.
The headline items: multi-factor authentication expectations for access into the cardholder data environment, stronger password requirements, and — for anyone with an e-commerce payment page — requirements to manage and monitor the scripts loaded on that page. That last one catches operators who never think of their website as in-scope, because a compromised marketing script on a checkout page is a card-skimming path.
What happens if we are non-compliant and something goes wrong?
The consequences are contractual and they arrive faster than regulatory ones.
Depending on the agreement, an acquirer can impose fines, pass through forensic investigation costs, raise your rates, or terminate processing. For a cannabis operator, termination is the one that hurts, because replacing a processor in this industry is not a same-week exercise. There is also the state-law layer: a card-data compromise involving Connecticut residents triggers the breach-notification analysis under § 36a-701b independently of anything PCI-related.
What should we do first?
Three steps, in order.
- Map the flow. Draw every path a card number could travel through your business, including the ones that only happen occasionally. Most operators find at least one they forgot.
- Reduce it. Every system you can remove from that path is scope you never have to assess again. Point-to-point encrypted terminals and hosted checkout pages exist for this reason.
- Get the requirement in writing. Email your acquirer, ask which SAQ applies and what scanning is required, and file the reply where your renewal evidence lives.
Where to go next
- Protecting cannabis POS systems from attackers
- Cybersecurity requirements for dispensaries
- Downtime Prevention: incident response and resilience
