Founder narrative
Anya Petrova10 min read96 views

The month PCI compliance turned out to be a statute at 76K MRR

A composite founder diary. Everyone says PCI compliance is contractual and not law. In September 2026 I read three state statutes and found Nevada making the current version of a private standard a legal duty, Minnesota deeming me in violation for my processor's act, and Washington inverting both.

Updated on September 27, 2026

Flat vector diagram on off-white. A long solid charcoal rule near the top. Below it a tall empty band containing nothing. In the lower third a short terracotta bar stands on a dashed warm sand rule and stops far below the charcoal rule. A shorter pale grey rectangle sits to its right.
Flat vector diagram on off-white. A long solid charcoal rule near the top. Below it a tall empty band containing nothing. In the lower third a short terracotta bar stands on a dashed warm sand rule and stops far below the charcoal rule. A shorter pale grey rectangle sits to its right.
In this story
“Your processor says you're PCI compliant. That's a contract thing, right? Not a law thing.”

That was our new head of support, three weeks in, reading a customer questionnaire. I told her she was right, because that is what I had believed for four years. Then a lawyer in Nevada sent us two sentences of statute, and I spent a weekend discovering that the thing I had been calling "just a contract" is written into the law of at least three states, which disagree with each other so completely that one breach would produce three incompatible outcomes. We were at 76,000 dollars a month and I had never once thought of card rules as legislation.

Quick answer (2026). This diary is a composite. I write these from patterns across several small software companies I have worked in and advised, with the numbers and the timeline changed, so no single company here is any one real company. The finding is not a composite: PCI DSS is usually described as a purely contractual obligation, and in Nevada it is a statutory one, in Washington it is a statutory defence, and in Minnesota a closely related rule creates a statutory debt you owe to a bank you have never met. Nevada, Washington and Minnesota were each read from their own legislature's text in September 2026.

The sentence everybody repeats

Search for the phrase and you get a very confident answer. Google's own AI summary told me, in September 2026, that PCI compliance "is not enforced by federal or state laws, but it is contractually mandatory". Every one of the top ten results said something similar or said nothing about legal force at all. The top question people also ask is literally whether PCI compliance is a legal requirement, and the answer being handed to them is no.

It is a good summary of the ordinary case. In most states the card rules really do reach you through your merchant agreement and nowhere else. The trouble is that it is offered as a general fact about American law, and as a general fact it is false.

Nevada writes a private document into the statute

Nevada Revised Statutes 603A.215 does not reference PCI DSS as background colour. It makes it the duty. A business taking cards "shall comply with the current version of the Payment Card Industry (PCI) Data Security Standard, as adopted by the PCI Security Standards Council or its successor organization".

There are three delegations in that one sentence. The content of your legal obligation is whatever a private document says. It is the current version, so the obligation changes when the document changes, with no legislature involved. And "or its successor organization" delegates forward to an entity that does not yet exist.

And the deadline is delegated too. The statute requires compliance "not later than the date for compliance set forth in the Payment Card Industry (PCI) Data Security Standard or by the PCI Security Standards Council or its successor organization". So the private body sets both what you must do and when you must have done it.

This is not a forgotten provision nobody has looked at. The history line reads "(Added to NRS by 2009, 1603; A 2011, 2002; 2025, 1968, 3570)". A legislature amended it last year and left the delegation exactly where it was.

Five card brands to a state injunction

I wanted to know who writes the document my legal duty points at, so I read the Council's own description of itself. It says it "was founded in 2006 by American Express, Discover, JCB International, MasterCard and Visa Inc." and that those "Founding Members share equally in ownership, governance, and execution of the organization's work". It is "led by a policy-setting Executive Committee composed of representatives from the Founding Members and Strategic Members". There is an elected body, but note carefully what it does: "A Board of Advisors, representing and elected by Participating Organizations, provides input to the organization and feedback on the evolution of the PCI Standards". Input and feedback. The policy-setting committee is the owners.

Now follow the chain. Five card companies own a council. Its policy committee publishes a document and sets its own deadline. A statute says you shall comply with whatever that document currently says. And NRS 603A.260 provides that a violation of 603A.010 to 603A.290 "constitutes a deceptive trade practice for the purposes of NRS 598.0903 to 598.0999, inclusive". Under NRS 603A.290, "the Attorney General or district attorney may bring an action against that person to obtain a temporary or permanent injunction against the violation".

Five private companies at one end, a state injunction at the other, and after 2009 no legislature has to do anything for the obligation in the middle to change.

Minnesota: no floor, no defence, and your vendor's act is your violation

Minnesota Statutes 325E.64 is short and brutal. Nobody accepting a card there may "retain the card security code data, the PIN verification code number, or the full contents of any track of magnetic stripe data" after authorisation. Sensible enough. Then the next sentence: "A person or entity is in violation of this section if its service provider retains such data subsequent to the authorization of the transaction". Your processor's retention is your violation. The statute defines a service provider as an entity "that stores, processes, or transmits access device data on behalf of another person or entity", which is a description of exactly the vendor you chose precisely so that you would not have to touch this data.

And once there is a breach, "that person or entity shall reimburse the financial institution that issued any access devices affected by the breach" for reissuance, account closure, refunds and notification. The plaintiff is an issuing bank: no contract with you, nothing to negotiate, and you probably cannot name it in advance.

I searched the whole operative text for every escape I could think of. Business to business, de minimis, small business, small entity, fewer than, revenue threshold, annual revenue, number of employees, exempt. All nine return zero. Then every tier that would reward care: willful, negligence, reckless, good faith, safe harbor. Also zero. "Encrypt" and "compliant" do not appear at all, there is no cap, and the only two occurrences of "limit" are "not limited to", which expands rather than bounds. The history reads 2007 c 108 s 1, and nothing after it.

So in Minnesota, being certified compliant is worth nothing as a defence, encrypting is worth nothing as a defence, being careful is worth nothing as a defence, and being tiny is worth nothing as a defence.

Washington: the same breach, the opposite statute

Then I read Washington's RCW 19.255.020, which inverts on every axis. It has a safe harbour: processors, businesses and vendors "are not liable under this section if (a) the account information was encrypted at the time of the breach", or if they were certified compliant with PCI DSS, validated within the previous year. It has a liability standard built on care, attaching only where a party "fails to take reasonable care to guard against unauthorized access to account information". It preserves ordinary defences including comparative negligence, it has the trier of fact apportion fault, and the prevailing party "is entitled to recover its reasonable attorneys' fees and costs".

And one clause I have not seen anywhere else: for the purposes of the safe harbour, "a processor, business, or vendor's security assessment of compliance is nonrevocable". The standard fear after a breach is that a forensic investigator looks backwards and decides you were never compliant at all. Washington has legislated that away, at least here.

Washington also splits the vendor question the opposite way from Minnesota. Where Minnesota deems you the violator for your service provider's retention, Washington says "a vendor, instead of a processor or business, is liable to a financial institution for the damages described in (a) of this subsection to the extent that the damages were proximately caused by the vendor's negligence". Same failure by the same kind of supplier. One state moves the liability onto you, the other moves it off you.

Six million transactions a year, or one

Then I found the definition, and it is the part I have thought about most since. Washington's protections and its liability both hang on the word "business", defined as an entity that "processes more than six million credit card and debit card transactions annually".

Six million a year is 16,438 a day. If you bill monthly, that means five hundred thousand active subscribers. At 76,000 dollars a month, five hundred thousand subscribers is an average of about fifteen cents each. We were not in the same conversation.

Minnesota's threshold, by contrast, is one transaction. Its statute opens with "No person or entity conducting business in Minnesota that accepts an access device", and that is the whole test.

Here is the catch I would have missed. The Washington threshold attaches to the category a merchant falls into. The other category, "processor", covers anyone who "directly processes or transmits account information for or on behalf of another person as part of a payment processing service", and it carries no transaction threshold at all. So the same six person company is outside the statute when it charges its own customers and inside it when it moves card data on behalf of somebody else's. What moves you across that line is not your size. It is whose customers are paying.

The same fact, two grammars

One last thing, because it is the sort of detail that decides a case and reads like nothing. Both statutes deal with money the bank recovers from the card companies. Minnesota says "Costs do not include any amounts recovered from a credit card company by a financial institution". Washington says "a trier of fact may reduce damages awarded to a financial institution by any amount the financial institution recovers from a credit card company in connection with the breach".

Same fact, same purpose, and completely different force. Minnesota's is a definitional exclusion: those amounts are not costs, so they are never in the claim. Washington's is a discretion: a trier of fact may reduce, and may not. I have read a lot of contracts and I still would have skimmed past that.

What actually happened

Scroll to see more

What I assumedWhat the text said
PCI is contractual, never legalNevada requires compliance by statute and makes a violation a deceptive trade practice
The standard is fixed when I read itNevada incorporates "the current version", plus any successor organisation
Being certified protects meTrue in Washington, and the word "compliant" appears zero times in Minnesota's statute
Encryption is a universal defenceNine occurrences in Washington's section, zero in Minnesota's
My processor's mistakes are my processor'sMinnesota deems me in violation for my service provider's retention
Small companies are below the lineWashington's line is six million transactions, Minnesota's is one
The newer law would be the harsher oneWashington, 2010, is the protective one on every axis I measured

What I got wrong

Three things, and I was confident about the first two.

I assumed the size threshold would be the founder's friend. It is, in Washington, and only if you sell to your own customers. The category with no threshold is the one a small platform lands in, and nothing about that is visible from the word "business" in the headline.

I assumed the later statute would be the tougher one, because that is how this normally goes. Minnesota's is from 2007 and has no safe harbour, no mental state and no floor. Washington's is from 2010 and has all three. Being early is not the same as being mild.

And I assumed that reading carefully was the point. In Washington it is exactly the point, because care is the liability standard. In Minnesota it buys nothing, because there is no tier for care to move. I now ask a cruder question first: does this rule contain a word for being careful? If not, diligence avoids the harm but does not reduce the bill.

Limits

I read three states. Others may well have analogous provisions and I make no claim about the other forty seven. I did not read PCI DSS itself, which sits behind a click through, so I quote no requirement number and assert nothing about its contents. Neither statute prints a figure for what a card reissuance costs, so I do not give one. Nevada's legislature blocks ordinary fetching tools, so I read that page in a browser and checked each quotation against the live page rather than against a copy. I am not a lawyer and this is not legal advice. Every quotation here comes from the linked source and you can check all of them in an afternoon.

The one thing I would tell you

Stop asking whether a rule is "legally required" and start asking who wrote it, who can sue you under it, and what its smallest unit is.

For the card rules the answers were: a council owned by five card brands, an issuing bank you have never dealt with, and in Minnesota a single transaction. None of the three is in the summary everybody repeats, and the third is the one that reached us.

The questionnaire, by the way, we answered honestly and it was fine. What changed was not our security. It was that I stopped treating a document I had never read as somebody else's paperwork.

A

Written by

Anya Petrova

Frequently asked questions

Is this a real founder's diary?

It is a composite. These diaries are built from patterns across several small software companies, with the numbers, names and timeline changed, so no single story here is any one real company. The legal material is not composite: every statute quoted is quoted verbatim from the linked legislature page and was read in September 2026.

Is PCI compliance a legal requirement?

Usually it reaches you through your merchant agreement rather than through legislation, which is why almost every summary calls it purely contractual. That is not universally true. Nevada Revised Statutes 603A.215 requires a business accepting payment cards to comply with the current version of PCI DSS, and Nevada treats a violation of that chapter as a deceptive trade practice.

Which states have written PCI DSS into law?

I verified three in September 2026. Nevada makes compliance with the current version of PCI DSS a statutory duty. Washington makes certified PCI compliance, or encryption, a statutory defence against a bank's reissuance claim. Minnesota does not name PCI DSS at all but bans retention of card security codes, PIN verification codes and full magnetic stripe track data, and attaches a reimbursement duty to a breach. I did not survey the other forty seven states.

Does being PCI compliant protect me if there is a breach?

It depends entirely on which statute applies. In Washington it is an express safe harbour, and the statute even says a compliance assessment is nonrevocable for that purpose. In Nevada compliance plus the absence of gross negligence or intentional misconduct removes liability for damages. In Minnesota the word compliant does not appear in the statute at all, so certification is not a defence there.

Can my payment provider's mistake make me the one in violation?

In Minnesota, yes. Section 325E.64 says a person or entity is in violation if its service provider retains the prohibited data after authorisation, and it defines a service provider as an entity that handles access device data on behalf of another. Washington runs the opposite way and makes a vendor liable instead of the business to the extent the damage was proximately caused by the vendor's negligence.

Am I too small for any of this to apply?

Not reliably. Washington's definition of business is an entity processing more than six million card transactions a year, which is about 16,438 a day, so a small merchant is outside it. But Washington's other category, processor, covers anyone handling card data on behalf of another person and carries no threshold at all, and Minnesota's statute has no size threshold anywhere in its operative text.

Founder narrative

The month a payout feature made me a money transmitter at 65K MRR

A composite founder diary. At 65K MRR a banking partner asked whether client funds ever touched our balance. Nine days in the statutes turned up a federal felony that says your knowledge is irrelevant, an exemption written for somebody else, and a civil penalty of 10,556 dollars a day that the statute itself prints as 5,000.

10 min read85
Founder narrative

The month DORA compliance arrived in someone else's contract, at 75K MRR

A composite founder diary. A payments customer sent an eleven page DORA addendum with a one percent of turnover penalty clause. Four days of reading the regulation showed that no EU regulator could fine us at all, that the size relief is reserved for regulated firms, and that the real cost was free incident support written into the contract.

10 min read98
Founder narrative

The month my bank was allowed not to read the name, at 82K MRR

A composite founder diary at 82K MRR. When a payment order names one person and numbers another, the receiving bank may pay on the number and need not check the name. The escape the statute gives a non bank originator is deleted by a signature, and the right to chase the stranger follows the loss.

10 min read34