We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / The data you hold

The data you hold

Card Data: The Safest Way to Store It Is to Never Touch It

PCI scope reduction in plain terms: why a small business should never store card numbers, what tokenization does, and what changed in SAQ A in 2025.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The drawer behind reception

The front-office manager of a 48-room boutique hotel in Dubai runs a tidy desk. Guests sign a registration card at check-in, and in the box marked "incidentals" the receptionist writes the full card number, the expiry and the three digits from the back. The cards go in a drawer behind reception. The drawer has a lock. The key lives in the drawer above it.

She has done it this way for eleven years, because the old system needed it and because guests sometimes leave without settling the minibar. Nobody has ever complained.

The new general manager, who came from a hotel group, asks to see the drawer on his first Wednesday. He counts 1,900 registration cards going back to 2019, every one of them with a working card number and a security code. Night porters, housekeeping supervisors and a temp from the summer have all had the key. The bank's annual PCI questionnaire, which the accountant fills in, has said "we do not store cardholder data" for as long as anyone can remember.

He does not shout. He asks the accountant a quieter question: if one photo of that drawer ends up on a forum, how does the hotel prove which guests to call?

What the heck does this mean

Cardholder data is the full card number, and anything stored with it: name, expiry, the security code. The security code is never allowed to be stored after authorization, on paper or on a screen.

The cardholder data environment, CDE, is every system, drawer, person and process that touches that data. PCI DSS, the card industry's security standard, applies to all of it.

PCI scope is the size of your CDE. Scope reduction means shrinking it, ideally to nothing you own. The fewer places a card number can exist, the fewer things you have to secure, prove and pay for.

Tokenization is how a hotel keeps a card on file without keeping the card. The processor stores the number and hands you a token, a stand-in that lets you charge the minibar but is useless to a thief.

SAQ A is the short self-assessment questionnaire for merchants who outsource card handling completely. SAQ D is the long one for merchants who store numbers themselves. The drawer puts this hotel in SAQ D, whatever the accountant ticked.

The principle is the same one I have given boards for twenty years: you cannot lose what you never held.

The numbers that matter

Fifty-one future-dated PCI DSS v4.x requirements became mandatory on 31 March 2025 (PCI SSC, 2025). The questionnaire your accountant filled in three years ago describes a standard that no longer exists.

In January 2025 the SAQ A revision removed requirements 6.4.3, 11.6.1 and 12.3.1 in favor of an eligibility criterion (PCI SSC, 2025). The short form got shorter for merchants who truly outsource, and stricter about who qualifies.

Thirty-four percent of firms report at least one account takeover incident per month (Barracuda 2026 Email Threats Report). The login to your booking engine or payment portal is the modern version of the key in the drawer above.

What to do this week

  1. Find every card number you hold. Registration cards, the folder of faxed authorization forms, the "notes" field in the booking system, the spreadsheet in accounting, voicemail. Count them. Then shred the paper and purge the fields, keeping a signed log of what was destroyed and when. (CIS 3 Data Protection)
  2. Move incidentals to a tokenized card on file with your payment processor. Every modern property or point-of-sale system supports this; ask your provider for the setting, not for a quote. (CIS 16 Application Software Security)
  3. Rewrite the registration card. Remove the card-number box entirely. If a guest wants to guarantee incidentals, the receptionist takes the card at the terminal and the token does the rest. (CIS 3 Data Protection)
  4. Lock down the payment terminals and the booking-engine admin: unique logins per person, MFA on, default passwords changed, the summer temp's account deleted. (CIS 4 Secure Configuration of Enterprise Assets and Software)
  5. Re-read the questionnaire and answer it truthfully. If any card number still exists on your premises or your servers, you are not SAQ A. Fix that before you sign, because the signature is the part the bank holds you to. (CIS 3 Data Protection)
  6. Ask your web developer one question in writing: which scripts run on the payment page, and who approved each one. Unapproved scripts on checkout pages are where card numbers walk out of online shops. (CIS 16 Application Software Security)

Where AccuSights fits

Our assessment finds every place a card number exists in your business, on paper or in a field, and shows you the shortest path to holding none of them, so the questionnaire you sign is true. The Cyber Hygiene Test takes three minutes. A 15-minute call with an engineer will tell you which SAQ you are actually in and what it would take to get to the short one.

We map the assessment to PCI DSS and, where a payments licence applies, the CBUAE framework, and our read-only compliance agent shows where card data sits and which settings have drifted, so you prioritize the right things and keep an eye on them. We have no access and do not remediate; you or your IT partner fix, and we show you where.

Questions people ask

Do I need PCI compliance if I use Square or Stripe? Yes, but far less of it. A hosted payment processor takes on most of the technical requirements, and your job shrinks to the short questionnaire, a few settings and one rule: never let a card number touch your own systems. The moment you store a number in a spreadsheet, a drawer or a notes field, you have pulled all of it back onto your desk.

What is SAQ A vs SAQ D? SAQ A is the short self-assessment questionnaire for merchants who fully outsource card handling to a validated processor and never store card data. SAQ D is the long one, covering most of the standard, for merchants who store, process or transmit card numbers themselves. The difference is roughly a couple of dozen questions against several hundred. Which one you fill in is decided by what you touch, not by your size.

Can I write card numbers on a form? You can, and you should not. A paper form with a full card number is cardholder data, which means the drawer, the filing cabinet and the person with the key are all inside your PCI scope. The sensible replacement is a tokenized card on file with your processor, which gives you an authorization for incidentals without a number anyone can copy.

The drawer is empty now, and the questionnaire finally says something true. That is the whole trick: hold less, prove less, lose less.

Questions people ask

Do I need PCI compliance if I use Square or Stripe?

Yes, but far less of it. A hosted payment processor takes on most of the technical requirements, and your job shrinks to the short questionnaire, a few settings and one rule: never let a card number touch your own systems. The moment you store a number in a spreadsheet, a drawer or a notes field, you have pulled all of it back onto your desk.

What is SAQ A vs SAQ D?

SAQ A is the short self-assessment questionnaire for merchants who fully outsource card handling to a validated processor and never store card data. SAQ D is the long one, covering most of the standard, for merchants who store, process or transmit card numbers themselves. The difference is roughly a couple of dozen questions against several hundred. Which one you fill in is decided by what you touch, not by your size.

Can I write card numbers on a form?

You can, and you should not. A paper form with a full card number is cardholder data, which means the drawer, the filing cabinet and the person with the key are all inside your PCI scope. The sensible replacement is a tokenized card on file with your processor, which gives you an authorization for incidentals without a number anyone can copy.

Controls this post maps to

CIS 3 Data ProtectionCIS 16 Application Software SecurityCIS 4 Secure Configuration of Enterprise Assets and Software

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.