Blog / The data you hold
The data you hold
Card Data: The Safest Way to Store It Is to Never Touch It
PCI scope reduction in plain terms: why a small business should never store card numbers, what tokenization does, and what changed in SAQ A in 2025.
The drawer behind reception
The front-office manager of a 48-room boutique hotel in Dubai runs a tidy desk. Guests sign a registration card at check-in, and in the box marked "incidentals" the receptionist writes the full card number, the expiry and the three digits from the back. The cards go in a drawer behind reception. The drawer has a lock. The key lives in the drawer above it.
She has done it this way for eleven years, because the old system needed it and because guests sometimes leave without settling the minibar. Nobody has ever complained.
The new general manager, who came from a hotel group, asks to see the drawer on his first Wednesday. He counts 1,900 registration cards going back to 2019, every one of them with a working card number and a security code. Night porters, housekeeping supervisors and a temp from the summer have all had the key. The bank's annual PCI questionnaire, which the accountant fills in, has said "we do not store cardholder data" for as long as anyone can remember.
He does not shout. He asks the accountant a quieter question: if one photo of that drawer ends up on a forum, how does the hotel prove which guests to call?
What the heck does this mean
Cardholder data is the full card number, and anything stored with it: name, expiry, the security code. The security code is never allowed to be stored after authorization, on paper or on a screen.
The cardholder data environment, CDE, is every system, drawer, person and process that touches that data. PCI DSS, the card industry's security standard, applies to all of it.
PCI scope is the size of your CDE. Scope reduction means shrinking it, ideally to nothing you own. The fewer places a card number can exist, the fewer things you have to secure, prove and pay for.
Tokenization is how a hotel keeps a card on file without keeping the card. The processor stores the number and hands you a token, a stand-in that lets you charge the minibar but is useless to a thief.
SAQ A is the short self-assessment questionnaire for merchants who outsource card handling completely. SAQ D is the long one for merchants who store numbers themselves. The drawer puts this hotel in SAQ D, whatever the accountant ticked.
The principle is the same one I have given boards for twenty years: you cannot lose what you never held.
The numbers that matter
Fifty-one future-dated PCI DSS v4.x requirements became mandatory on 31 March 2025 (PCI SSC, 2025). The questionnaire your accountant filled in three years ago describes a standard that no longer exists.
In January 2025 the SAQ A revision removed requirements 6.4.3, 11.6.1 and 12.3.1 in favor of an eligibility criterion (PCI SSC, 2025). The short form got shorter for merchants who truly outsource, and stricter about who qualifies.
Thirty-four percent of firms report at least one account takeover incident per month (Barracuda 2026 Email Threats Report). The login to your booking engine or payment portal is the modern version of the key in the drawer above.
What to do this week
- Find every card number you hold. Registration cards, the folder of faxed authorization forms, the "notes" field in the booking system, the spreadsheet in accounting, voicemail. Count them. Then shred the paper and purge the fields, keeping a signed log of what was destroyed and when. (CIS 3 Data Protection)
- Move incidentals to a tokenized card on file with your payment processor. Every modern property or point-of-sale system supports this; ask your provider for the setting, not for a quote. (CIS 16 Application Software Security)
- Rewrite the registration card. Remove the card-number box entirely. If a guest wants to guarantee incidentals, the receptionist takes the card at the terminal and the token does the rest. (CIS 3 Data Protection)
- Lock down the payment terminals and the booking-engine admin: unique logins per person, MFA on, default passwords changed, the summer temp's account deleted. (CIS 4 Secure Configuration of Enterprise Assets and Software)
- Re-read the questionnaire and answer it truthfully. If any card number still exists on your premises or your servers, you are not SAQ A. Fix that before you sign, because the signature is the part the bank holds you to. (CIS 3 Data Protection)
- Ask your web developer one question in writing: which scripts run on the payment page, and who approved each one. Unapproved scripts on checkout pages are where card numbers walk out of online shops. (CIS 16 Application Software Security)
Where AccuSights fits
Our assessment finds every place a card number exists in your business, on paper or in a field, and shows you the shortest path to holding none of them, so the questionnaire you sign is true. The Cyber Hygiene Test takes three minutes. A 15-minute call with an engineer will tell you which SAQ you are actually in and what it would take to get to the short one.
We map the assessment to PCI DSS and, where a payments licence applies, the CBUAE framework, and our read-only compliance agent shows where card data sits and which settings have drifted, so you prioritize the right things and keep an eye on them. We have no access and do not remediate; you or your IT partner fix, and we show you where.
Questions people ask
Do I need PCI compliance if I use Square or Stripe? Yes, but far less of it. A hosted payment processor takes on most of the technical requirements, and your job shrinks to the short questionnaire, a few settings and one rule: never let a card number touch your own systems. The moment you store a number in a spreadsheet, a drawer or a notes field, you have pulled all of it back onto your desk.
What is SAQ A vs SAQ D? SAQ A is the short self-assessment questionnaire for merchants who fully outsource card handling to a validated processor and never store card data. SAQ D is the long one, covering most of the standard, for merchants who store, process or transmit card numbers themselves. The difference is roughly a couple of dozen questions against several hundred. Which one you fill in is decided by what you touch, not by your size.
Can I write card numbers on a form? You can, and you should not. A paper form with a full card number is cardholder data, which means the drawer, the filing cabinet and the person with the key are all inside your PCI scope. The sensible replacement is a tokenized card on file with your processor, which gives you an authorization for incidentals without a number anyone can copy.
The drawer is empty now, and the questionnaire finally says something true. That is the whole trick: hold less, prove less, lose less.
Questions people ask
Do I need PCI compliance if I use Square or Stripe?
Yes, but far less of it. A hosted payment processor takes on most of the technical requirements, and your job shrinks to the short questionnaire, a few settings and one rule: never let a card number touch your own systems. The moment you store a number in a spreadsheet, a drawer or a notes field, you have pulled all of it back onto your desk.
What is SAQ A vs SAQ D?
SAQ A is the short self-assessment questionnaire for merchants who fully outsource card handling to a validated processor and never store card data. SAQ D is the long one, covering most of the standard, for merchants who store, process or transmit card numbers themselves. The difference is roughly a couple of dozen questions against several hundred. Which one you fill in is decided by what you touch, not by your size.
Can I write card numbers on a form?
You can, and you should not. A paper form with a full card number is cardholder data, which means the drawer, the filing cabinet and the person with the key are all inside your PCI scope. The sensible replacement is a tokenized card on file with your processor, which gives you an authorization for incidentals without a number anyone can copy.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
PII You Did Not Know You Were Holding: Employee Files, Web Forms and the CRM Export
PII hides in employee files, web forms and CRM exports. What counts as personally identifiable information, which laws reach a small business, what to delete.
The data you holdSource Code and Secrets: The API Key in the Repo Is the Whole Company
Source code security for a small software team: why the API key in the repo is the whole business, the first hour after a leak, and how to stop the next one.
The data you holdClient Financial Data: What a Law Firm, CPA or Wealth Advisor Is Really Holding
Client financial data security for law firms, CPAs and advisors: what you are holding, the 30-day breach clocks that now apply, and the folder to lock first.
