Compliance

Do cannabis payments need PCI compliance?

Short answer

Yes, whenever your environment stores, processes or transmits cardholder data — including debit-based acceptance — PCI DSS applies, and your provider will usually require annual validation appropriate to your scope. Solutions that keep card data out of your systems reduce scope but do not eliminate obligations.

Written by
Cannabis Pay Hub editorial team
Reviewed
Reviewed by a Cannabis Pay Hub payments specialist
Published
Updated

The fuller explanation

Scope is the practical issue. A dispensary using a provider-supplied, point-to-point encrypted PIN pad has far less to validate than one running payment software on general-purpose store computers or storing customer payment details for delivery orders.

Ask your provider which self-assessment questionnaire applies to your setup and what evidence they require. Then align your network segmentation, device inventory, access controls and vendor management to that scope, and keep the documentation with your compliance file.

Important caveats

  • ACH and pay-by-bank have different data-protection obligations than card data, but bank data still needs protection.
  • Delivery workflows that capture payment details on personal devices expand scope quickly.
  • PCI validation is not a substitute for state cannabis security requirements.

Other ways people ask this

These phrasings share the same answer, so they live on this page rather than on duplicate URLs.

  • PCI DSS for dispensaries
  • Is PCI required for cannabis POS?
  • Cannabis payment security standards

Sources

  1. PCI DSS v4.x document library

    PCI Security Standards Council · checked

Was this helpful?

Read next

  1. 1Cannabis Payments Regulatory Resource DirectoryThe primary sources that govern cannabis payments in the United States are federal financial-crime guidance, banking regulators, card and debit network rules, and state cannabis regulators. This directory links each one with its publisher and the date we last checked it.
  2. 2AML requirements for dispensariesAt minimum: maintain active licensing, verifiable ownership records, written KYC/AML and cash-handling procedures, accurate transaction and seed-to-sale records, tax remittance documentation, PCI obligations where card data is in scope, and prompt notification to your bank and processor when the business changes materially.
  3. 3Card-Network Rules Cannabis Operators Are Judged AgainstEven where cards are available, as they often are for CBD and hemp sellers, the account is judged against network rules on accurate merchant coding, truthful…

Talk it through with a specialist

Bring your license type, POS, monthly volume and current provider. We will tell you what is workable and what is not.

Talk to a Cannabis Payment Specialist