PCI DSS Compliance for Real Estate Companies: A Practical Guide for SMBs

Real estate companies that accept credit or debit card payments for rent, deposits, or fees must comply with PCI DSS. Most small to mid-sized brokerages and property managers fall under SAQ A or SAQ B, requiring network security controls, cardholder data protection, and annual validation. Non-compliance fines range from $5,000 to $100,000 per month.

Does a real estate company need to be PCI DSS compliant if it uses a third-party payment portal?

Yes, but your compliance scope is significantly reduced. Using a fully outsourced, PCI-compliant payment gateway means you likely qualify for SAQ A, the simplest validation path. You still need to complete an annual SAQ, maintain a written security policy, and confirm your gateway's Attestation of Compliance (AOC) is current. You do not need to implement most of the 12 PCI DSS requirements yourself.

What is the difference between SAQ A, SAQ B, and SAQ D for real estate companies?

SAQ A applies when all card transactions are handled by a third-party, PCI-compliant payment processor and no cardholder data touches your own systems. SAQ B applies when you use standalone, dial-out payment terminals that do not store card data electronically. SAQ D applies when you directly process, store, or transmit card data - this carries the most requirements and highest audit burden. Most real estate SMBs that use AppFolio, Buildium, or a similar platform qualify for SAQ A.

What are the fines for PCI DSS non-compliance in real estate?

PCI DSS fines are levied by acquiring banks (the banks that process your card transactions), not directly by the PCI Security Standards Council. Monthly fines for non-compliance range from $5,000 to $100,000 depending on merchant level and the duration of non-compliance. Following a confirmed data breach, acquiring banks may also impose per-transaction fines, require a costly forensic investigation (PFI), and suspend your ability to accept card payments.

How long does it take a real estate SMB to achieve PCI DSS compliance?

For a real estate company qualifying for SAQ A with no major remediation gaps, the process typically takes two to six weeks: one to two weeks to complete the SAQ questionnaire, one to two weeks for an ASV scan and remediation of any flagged issues, and one to two weeks for documentation review. Companies with more complex environments, physical payment terminals, or legacy software may need three to six months if significant remediation is required.

Does PCI DSS apply to rent payments collected by check or ACH?

No. PCI DSS applies specifically to payment card data - credit and debit cards issued under Visa, Mastercard, American Express, Discover, and JCB networks. ACH transfers, paper checks, and wire transfers are governed by different frameworks (such as NACHA rules for ACH). If your property management company collects rent exclusively via ACH and does not accept credit or debit cards, PCI DSS does not apply.

Are property management software platforms like AppFolio or Buildium PCI DSS compliant?

AppFolio and Buildium both maintain PCI DSS compliance for their built-in payment processing modules and publish Attestations of Compliance (AOCs). Using their payment features typically places your company in SAQ A scope. You should request a current AOC from your software vendor annually to confirm their compliance status has not lapsed. Do not assume compliance - verify it in writing.

What is the first step a real estate company should take toward PCI DSS compliance?

The first step is determining your merchant level and SAQ type based on your current payment processing environment. Map all the ways your company accepts card payments - online portals, in-office terminals, phone orders - and identify which third-party vendors handle each channel. Then complete a gap assessment against the relevant SAQ requirements. The Value Aligners marketplace at https://www.valuealigners.com/marketplace offers a free assessment to help you identify gaps and match you with appropriate vendors.