Install and maintain network security controls
Segment the cardholder data environment (CDE) from in-store guest Wi-Fi and back-office networks.
A practitioner's guide to PCI DSS v4.0 for multi-location operators — written from 27 years inside QSR operations. The 12 requirements, merchant levels, multi-store pitfalls and an audit-readiness checklist you can hand to your area managers.
In one minute
Section 01
Card brands classify merchants by annual transaction volume across all channels. Your acquiring bank confirms your level in writing — but most multi-location QSR and Retail operators sit at Level 1 or Level 2.
| Level | Annual transactions | Validation |
|---|---|---|
| Level 1 | > 6M card transactions / year | Annual Report on Compliance (ROC) by a QSA + quarterly ASV scan |
| Level 2 | 1M – 6M / year | Annual Self-Assessment Questionnaire (SAQ) + quarterly ASV scan |
| Level 3 | 20K – 1M e-commerce / year | Annual SAQ + quarterly ASV scan |
| Level 4 | < 20K e-commerce or < 1M total / year | Annual SAQ + ASV scan (acquirer-dependent) |
Section 02
The standard is built around six control objectives and twelve numbered requirements. Here is what each one actually means when your environment is hundreds of stores, dozens of vendors and a payment lane that cannot go down at peak hours.
Segment the cardholder data environment (CDE) from in-store guest Wi-Fi and back-office networks.
Replace vendor defaults on POS terminals, kitchen displays, KDS routers and back-office PCs.
Never store full PAN on store servers. Tokenise at the terminal and let the processor hold the vault.
TLS 1.2+ end to end — from POS to payment gateway, with certificate pinning where possible.
Endpoint protection on every POS, BOH PC and digital-menu controller; signatures updated automatically.
Patch POS, OS and middleware on a monthly cadence; track CVEs against your payment-adjacent stack.
Role-based access for managers, shift leads and crew; no shared logins on the POS.
MFA for every remote access path into store networks — vendors, head office and managed services.
Tamper-evident seals on PIN pads, locked comms cabinets, CCTV over POS lanes.
Centralise POS, firewall and AD logs; alert on after-hours admin activity per store.
Quarterly ASV scans, annual penetration tests, plus continuous monitoring of the CDE.
Written policies your area managers can actually run — incident response, vendor management, staff training.
Section 03
Audit findings repeat themselves across QSR and Retail. Address these six patterns and you remove the majority of common PCI DSS gaps before a QSA ever walks in.
A single un-patched lane can compromise the chain. Treat firmware, OS and payment-app versions as a fleet-wide inventory, not a per-store problem.
Guest Wi-Fi, drive-thru tablets, digital menu boards and the POS often share one VLAN. Segment the CDE so a compromised tablet can't reach a PIN pad.
Shared logins are the fastest way to fail Requirement 8. Issue per-user credentials, enforce shift-end logout, and rotate manager codes monthly.
POS vendors, KDS suppliers, loyalty platforms and managed-Wi-Fi providers all dial in. Each path needs MFA, time-boxed sessions and centralised logging.
Corporate stores and franchisees rarely run identical stacks. Publish a minimum security baseline and audit franchisee attestations annually.
Refund logs, end-of-day reports and customer service spreadsheets can leak PAN. Scan, redact, and route reconciliation data through tokenised channels.
Section 04
Run this list 60 days before your assessment date — it covers ~80% of the evidence a QSA will ask for.
How Arka helps
ArkaSec — our cyber security as a service offering — wraps the operational controls behind PCI DSS into a managed programme: continuous monitoring across stores, vendor remote access governance, quarterly ASV scans, and audit evidence collection ready for your QSA. We are SOC 2 Type 2 compliant and run the same playbook across multi-brand QSR and Retail estates.
Keep reading
Products
Continuous monitoring, vendor access governance and audit support.
Industries
How we approach operational technology for multi-location chains.
About
Why Arka is built by an operator, for operators.