Take the payment on a card reader
The card is present, so the reader captures it and your software never sees the card number.
Your answers so far
- Where does the payment happen?
- In person, with the card at the counter. Change
Choose one
What to build
Talk to your account team about which readers this instance supports before you build anything. The reader decides your scope, so choosing it is the first decision rather than a detail at the end. Your own integration then works the same way the online ones do: your server calls the API and reads the result.
What this means for PCI
typically eligible for SAQ B-IP, or SAQ P2PE when the reader is part of a validated point-to-point encryption solution. Which one applies depends on the reader rather than on your software.
This is guidance rather than a compliance determination. Which questionnaire you are eligible for depends on your full environment, so confirm it with your QSA or your acquirer before you rely on it.
Worth knowing
- A reader that encrypts to a validated solution is the shortest annual questionnaire available for a card-present merchant.
- If you also take payments online, that half is scoped separately. Walk this guide again for it.