Booster Club PCI Compliance Checklist: Protect Online Dues, Donations, and Ticket Payments

  • Home /
  • Blog Posts /
  • Booster Club PCI Compliance Checklist: Protect Online Dues, Donations, and Ticket Payments
Booster Club PCI Compliance Checklist: Protect Online Dues, Donations, and Ticket Payments

Plan your donor recognition experience

Get a walkthrough of touchscreen donor walls, donor trees, giving societies, and campaign progress displays.

Live Example: Rocket Alumni Solutions Touchscreen Display

Interact with a live example (16:9 scaled 1920x1080 display). All content is automatically responsive to all screen sizes and orientations.

A booster club PCI compliance checklist covers the steps required to satisfy the Payment Card Industry Data Security Standard (PCI DSS)—the set of security requirements that applies to any organization that accepts, processes, or transmits payment card data. For booster clubs collecting online dues, accepting digital donations, and selling event tickets through a web portal, PCI compliance is not optional. It is a condition of the merchant account that allows the club to accept card payments at all. This checklist walks through merchant classification, selecting the correct self-assessment questionnaire, securing online payment channels, and maintaining ongoing controls—organized so a treasurer with no prior PCI experience can work through each stage in sequence.

The good news for most booster clubs is that using a reputable, fully outsourced payment processor significantly simplifies the compliance obligation. The heavy technical burden of PCI DSS falls on the processor; the club’s primary responsibilities are choosing a compliant processor, completing an annual self-assessment, and maintaining a small set of operational practices that protect cardholder data from the moment a payment form appears to the moment funds settle.

This guide is for informational purposes only and does not constitute legal, accounting, or compliance advice. PCI DSS requirements are maintained by the PCI Security Standards Council and are subject to periodic revision. Consult a qualified security assessor, licensed CPA, or attorney for guidance specific to your organization’s payment channels, acquiring bank, and jurisdiction.

Athletics touchscreen kiosk in school trophy case displaying interactive hall of fame

Digital recognition infrastructure and online payment systems often share the same organizational accounts—PCI compliance protects the payment channels that fund everything from trophy cases to donor recognition displays

What PCI Compliance Means for Booster Clubs

PCI DSS is the global security standard maintained by the PCI Security Standards Council, established jointly by Visa, Mastercard, American Express, Discover, and JCB. The standard defines 12 requirements—organized into six control domains—that govern how organizations protect cardholder data during payment transactions. Any entity that accepts card payments must comply with the version of PCI DSS in effect at the time of their annual self-assessment.

For booster clubs, PCI compliance applies the moment the organization enables any mechanism for accepting card payments: an online dues portal, a fundraiser donation page, a ticket sales link, or a card reader at a concession stand. The compliance obligation follows the payment channel, not the size of the organization. A booster club processing $18,000 in annual online ticket sales carries the same basic PCI compliance requirements as any other merchant at its transaction volume.

What PCI compliance does not require is that every booster club build its own secure payment infrastructure. The standard explicitly anticipates that small organizations will outsource card processing to compliant third-party service providers—and it provides a streamlined compliance path for those that do.

School programs that invest in long-term recognition infrastructure rely on the same community trust that PCI compliance is designed to protect. When donors and families know that card payments are handled through a compliant process, the credibility of every financial transaction the program conducts is strengthened.

Booster Club PCI Compliance Checklist: Step-by-Step

Step 1: Determine Your Merchant Level

PCI DSS assigns merchants to one of four levels based on annual card transaction volume. The level determines the validation requirements—specifically, whether the organization must engage a Qualified Security Assessor (QSA) for an on-site audit or whether a self-assessment questionnaire (SAQ) is sufficient.

Merchant LevelVisa/Mastercard Transaction ThresholdValidation Requirement
Level 1Over 6 million transactions per yearAnnual on-site audit by a QSA; quarterly network scan
Level 21 million to 6 million transactions per yearAnnual SAQ; quarterly network scan
Level 320,000 to 1 million e-commerce transactions per yearAnnual SAQ; quarterly network scan
Level 4Fewer than 20,000 e-commerce transactions per year, or up to 1 million transactions across all channelsAnnual SAQ; quarterly network scan (at acquirer discretion)

Most booster clubs fall into Level 4—the category for smaller merchants that process card payments through third-party platforms without high-volume transaction counts. Level 4 allows compliance through self-assessment rather than an external audit, which keeps the compliance burden manageable for volunteer-led organizations.

Checklist items for this step:

  • Count your annual card transactions — Total all card transactions across every channel: online dues portals, donation pages, ticket sales, and any in-person card readers used at events. Use the prior fiscal year if current-year data is incomplete
  • Identify your acquiring bank — The bank that processes your card payments may have its own merchant level definitions and SAQ requirements. Confirm the level classification with your acquirer, as their requirements may be stricter than the card brand minimums
  • Record the result — Document your merchant level and the date of the classification in your financial procedures records. Recheck annually, because transaction volume growth can shift a club from Level 4 to Level 3

Step 2: Identify Which SAQ Type Applies

Not all merchants complete the same self-assessment questionnaire. PCI DSS provides multiple SAQ types, each designed for a specific payment environment. Selecting the wrong SAQ type—one that covers fewer controls than your actual payment environment requires—produces a non-compliant attestation even if the form itself is filled out correctly.

SAQ TypeWho It Applies ToApplicable to Most Booster Clubs?
SAQ ACard-not-present merchants that fully outsource all cardholder data functions to PCI-compliant third parties; no electronic storage, processing, or transmission of cardholder data on merchant systemsYes—if using a fully hosted payment page from a compliant processor
SAQ A-EPE-commerce merchants who outsource payment processing but whose website could affect the security of the payment transaction (e.g., custom checkout code that redirects to a processor)Possibly—if the club’s website hosts custom payment scripts before redirecting
SAQ B-IPMerchants using standalone IP-connected point-of-interaction terminals; no electronic cardholder data storagePossibly—if using a standalone terminal at an event without an integrated system
SAQ CMerchants with payment application systems connected to the internet; no electronic storage of cardholder dataLess common—applies to more complex payment environments
SAQ DAll other merchants not covered by A, A-EP, B, B-IP, or CRequires the full 12-requirement assessment; rarely applies to small booster clubs using outsourced processors

The most common booster club scenario is SAQ A. If the organization uses a fully hosted payment page from a processor such as Stripe, Square, or PayPal—where the donor or family member enters payment information directly into the processor’s interface and the booster club never sees or stores the card number—SAQ A is likely the correct form.

Checklist items for this step:

  • Identify every payment channel the club uses — List all platforms where card payments are accepted: online dues, donation forms, event ticket sales, concession stand readers, and any recurring payment programs
  • Confirm how each channel handles cardholder data — For each platform, determine whether the payment form is hosted entirely by the processor or whether any card fields appear on a page the club controls
  • Match each channel to the corresponding SAQ type — If different channels fall under different SAQ types, the organization must comply with the most comprehensive SAQ that applies across all channels
  • Confirm the SAQ selection with your acquiring bank — Your acquirer has final authority over which SAQ applies to your account. Some acquirers require a specific SAQ type regardless of the merchant’s payment environment

University donor recognition alumni portraits in campus background setting

Donor recognition programs are funded through the same payment channels that PCI compliance protects—when card data is handled securely, the integrity of every gift recorded on a recognition display is preserved from the moment of transaction

Step 3: Choose a PCI-Compliant Payment Processor

The single most effective PCI compliance decision a booster club can make is selecting a payment processor that maintains its own PCI DSS certification and provides a fully hosted payment interface. When the processor handles cardholder data entirely on its own certified systems, the club’s compliance scope shrinks to a narrow set of operational and website-level controls rather than the full 12-requirement framework.

Checklist items for this step:

  • Verify the processor’s PCI compliance status — Confirm that the processor appears on the Visa or Mastercard list of PCI-compliant service providers, or ask the processor directly for its current Attestation of Compliance (AOC) document
  • Confirm the payment page is fully hosted — Verify that card entry fields appear on the processor’s domain, not the club’s website or a page the club controls. If your site shows a card entry form before redirecting, your compliance scope expands beyond SAQ A
  • Review the processor’s data retention practices — Ask the processor what card data it stores and for how long. The organization should not receive full card numbers in any report, export, or notification the processor generates
  • Confirm HTTPS is enforced on every page that links to the payment form — Even if the payment page is hosted by the processor, any club-controlled page that contains a link to the payment form must be served over HTTPS to avoid PCI scope expansion
  • Review the processor agreement for breach notification obligations — The agreement should specify the processor’s obligation to notify the club of any security incident that may affect the organization’s cardholder data

Step 4: Secure Every Online Payment Channel

Choosing a compliant processor handles the card-processing layer. The club’s remaining technical responsibilities cover the pages, accounts, and practices that connect the processor to the club’s members, donors, and ticket buyers.

Checklist items for this step:

  • Enforce HTTPS on all club-controlled web pages — Every page on the club’s website—including the landing page, the dues information page, and any page that displays a link to the payment form—must use HTTPS. HTTP-only pages expand the club’s PCI scope even if the actual card entry page is hosted externally
  • Enable two-factor authentication on all payment platform accounts — The club’s administrative access to the payment processor portal should require a second authentication factor beyond a password. This prevents unauthorized access to transaction histories, payout settings, and refund capabilities
  • Never collect or store card numbers outside the processor — No officer or volunteer should accept a card number by email, text message, phone, or handwritten form and then enter it into a system. If a member cannot complete an online transaction, the correct process is to direct them to the payment page—not to accept card details through an unofficial channel
  • Remove any stored card numbers from existing files — Search email archives, spreadsheets, and shared drives for any file that contains card numbers. If discovered, delete securely and document the remediation. Stored card numbers represent a compliance violation regardless of whether a breach has occurred
  • Establish a process for returned or disputed transactions — Chargebacks and refund requests should flow through the processor’s official dispute channel, not through informal contact with the treasurer

Athletic programs that develop comprehensive digital recognition systems often use the same organizational accounts that process online payments—maintaining strong access controls on those accounts protects both the payment data and the recognition content simultaneously.

Step 5: Complete the Annual Self-Assessment Questionnaire

The SAQ is the organization’s formal attestation that its payment environment meets PCI DSS requirements. Completing the SAQ is a year-end compliance obligation, not a one-time setup task. Requirements evolve with each revision of the PCI DSS standard, and the organization’s payment environment may change as new channels are added.

Checklist items for this step:

  • Obtain the current SAQ form from the PCI Security Standards Council — The current versions of all SAQ forms are available at pcisecuritystandards.org. Do not use a form from a prior year; the requirements may have changed
  • Complete the SAQ with accurate responses reflecting current practices — Each question should be answered based on the organization’s actual current practices, not intended practices. If a control is not yet implemented, the SAQ must reflect that
  • Sign and retain the completed SAQ and Attestation of Compliance — Keep a copy of the signed SAQ and AOC in the organization’s financial records. Your acquiring bank may request these documents
  • Submit the SAQ to your acquiring bank if required — Some acquirers require active submission of the completed SAQ; others require only that the merchant maintain a copy. Confirm your acquirer’s requirement
  • Set a reminder for the next annual assessment — Calendar the next SAQ completion date at the time of submission so the deadline does not fall during an officer transition

Interactive touchscreen honor wall kiosk with RU logo in school hallway

Recognition kiosks and online payment portals share the same organizational governance—PCI compliance for the payment side protects the financial integrity behind every athlete and donor recognized on the display

Step 6: Train Officers and Volunteers Who Handle Payments

PCI DSS requirement 12 explicitly addresses organizational security policies and the training of personnel who have access to cardholder data. For booster clubs, the relevant personnel are the officers who manage payment platforms, the volunteers who operate card readers at events, and any committee member who handles online registration or ticket sales.

Checklist items for this step:

  • Conduct annual payment security orientation for all officers — Cover the following in the orientation: what card data the club is not allowed to collect or store, how to handle a member who tries to provide card details informally, and who to contact if a potential security incident is observed
  • Brief event volunteers before any event where card readers are used — Volunteers operating mobile card readers should know that they must never write down card numbers, must return equipment to the designated officer at the end of the event, and must report any reader that behaves unexpectedly
  • Document the training — Maintain a sign-in sheet or email confirmation that records who received training and when. This documentation supports the SAQ attestation
  • Update training when the payment environment changes — If the club adds a new payment platform, changes processors, or begins accepting payments through a new channel, schedule a briefing before the new channel goes live

Step 7: Maintain Year-Round Compliance Controls

PCI compliance is a continuous obligation, not an annual project. The controls established at setup must remain active and accurate throughout the year.

Checklist items for this step:

  • Review payment processor access credentials at each officer transition — When the treasurer changes, update the authorized administrator on the payment platform immediately. Remove the outgoing officer’s access on the transition date; do not allow shared credentials to persist between administrations
  • Confirm HTTPS is enforced after any website update — If the club’s website is updated, redesigned, or migrated to a new platform, re-verify that HTTPS is enforced across all pages before the new version goes live
  • Monitor transaction activity for unauthorized charges — Review the payment platform’s transaction report at least monthly. Unfamiliar transactions—especially small-dollar test charges that precede larger fraud attempts—should be investigated immediately
  • Confirm the processor’s PCI compliance annually — Processor certifications are renewed annually. Verify that your processor’s compliance status is current before completing your own SAQ attestation

PCI Compliance Quick-Reference Table

Use this table at each quarterly board meeting to confirm that the organization’s payment security controls remain active.

Control AreaWhat to VerifyWho VerifiesFrequency
Processor compliance statusProcessor appears on current compliant service provider listTreasurerAnnually
HTTPS enforcementAll club web pages served over HTTPSTreasurer or webmasterQuarterly
Payment platform admin accessOnly current authorized officers hold admin credentialsTreasurerAt each officer transition
Two-factor authenticationMFA active on payment platform admin accountsTreasurerQuarterly
No stored card numbersNo card numbers present in email, spreadsheets, or shared filesTreasurerAnnually or after any personnel change
Annual SAQ completionSAQ completed, signed, and filedTreasurerAnnually
Event volunteer briefingPre-event training completed before each card reader eventEvent coordinatorBefore each event
Transaction monitoringMonthly transaction report reviewed for anomaliesTreasurerMonthly
Processor agreement reviewData retention and breach notification terms remain currentTreasurer and presidentAnnually

Connecting PCI Compliance to Donor and Sponsor Trust

Booster clubs operate on community trust—and community trust depends on the confidence that financial transactions are handled with the same care that the organization extends to its recognition programs and public commitments. When a family pays online dues, a donor submits a digital gift, or a supporter purchases an event ticket, they are extending that trust to the organization’s payment infrastructure.

A PCI compliance failure is not an abstract regulatory event. It is, at its most direct, a breach of that trust. If cardholder data is exposed through a non-compliant payment process, the affected individuals—families, donors, and sponsors—bear the consequences of unauthorized charges, account monitoring, and the administrative burden of card replacement. The organization’s response to that exposure, and the questions that follow about why compliance controls were not in place, creates a stewardship gap that formal recognition programs cannot close.

PCI compliance does not require advanced technical expertise. For most booster clubs, it requires selecting a compliant processor, completing an annual SAQ, and maintaining a small set of operational practices that prevent cardholder data from circulating in the organization’s informal systems. Those requirements impose a modest, predictable workload—far less than the reputational and legal cost of a breach that proper controls would have prevented.

Programs that build athletic recognition displays and hall of fame installations demonstrate the same long-term stewardship mindset that PCI compliance requires: consistent discipline applied year after year, not as a compliance exercise but as a demonstration of organizational integrity to the community that funds the program.

Student recognition programs and academic achievement displays are funded by the same community members whose payment data PCI compliance is designed to protect—maintaining secure payment channels and maintaining high-quality recognition programs reflect the same core commitment to the people who invest in the school.

RU wall of honor screen showing campus aerial view with name plaques

Donor name plaques and recognition displays represent the visible result of payment transactions that PCI compliance controls protect from the first card entry to the final recognition installation

PCI Compliance and Online Ticketing Platforms

Many booster clubs accept event ticket payments through a third-party ticketing platform rather than through a general-purpose payment processor. The same PCI compliance logic applies: if the platform maintains its own PCI DSS certification and processes cardholder data entirely on its own certified systems, the club’s compliance scope for that channel is limited to operational practices—not the technical requirements that the platform provider has already satisfied.

Before using any ticketing platform for card-accepting events, verify:

  • The platform maintains current PCI DSS compliance — Ask the platform for its current Attestation of Compliance or confirm its status through your acquirer
  • Card entry occurs entirely on the platform’s interface — The ticket buyer enters payment information on a platform-controlled page, not a club-managed page
  • The platform does not transmit full card numbers to the club — Any transaction reports or export files the club receives should contain only masked or tokenized card references, never full card numbers
  • The platform’s breach notification terms are documented — Review the service agreement for the platform’s obligation to notify the club of security incidents and the timeline for that notification
  • The platform is included in the annual SAQ scope — If the ticketing platform is used alongside another payment processor, confirm with your acquirer how the two channels interact for SAQ purposes

School event planning and field day programs generate ticket and registration revenue that flows through the same payment compliance framework—consistent PCI controls across all event revenue channels protects both the school and the families who register.

School hall of fame lobby wall with blue and yellow shields and TV display screen

Hall of fame lobbies represent sustained community investment—PCI compliance for the dues, donation, and ticket payment channels that fund these spaces is part of the same stewardship ethic that makes long-term recognition programs credible to the families and donors who support them

Frequently Asked Questions

Does a booster club that only accepts checks need to comply with PCI DSS?

No. PCI DSS applies only to organizations that accept payment cards—credit, debit, or prepaid cards carrying a card brand logo (Visa, Mastercard, American Express, Discover). Organizations that accept only checks, cash, or ACH bank transfers have no PCI DSS obligation. However, many booster clubs that process online dues or donations also accept card payments through the same platform, making PCI compliance relevant for at least a portion of their payment activity.

What is the consequence of PCI non-compliance for a small booster club?

The consequences of non-compliance range from increased transaction fees and monthly fines assessed by the acquiring bank (which passes penalties from card brands) to suspension of the organization’s ability to accept card payments. In the event of a data breach during a period of non-compliance, the card brands can impose additional fines and hold the organization responsible for the cost of card reissuance for affected cardholders. For a Level 4 merchant, fines during a non-compliance period typically range from a few thousand to tens of thousands of dollars depending on the duration and the acquiring bank’s contractual terms—far exceeding the annual cost of maintaining compliance.

Does using PayPal, Stripe, or Square automatically make the booster club PCI compliant?

No—but it significantly simplifies compliance. These processors maintain their own PCI DSS certifications and handle cardholder data on their own secure systems. When the booster club uses their fully hosted payment interfaces (not custom-embedded card fields), the club’s PCI scope is limited to SAQ A requirements. The club still has obligations: completing the SAQ annually, maintaining HTTPS across all club-controlled pages, and preventing cardholder data from circulating in informal channels. Choosing a compliant processor handles the processor’s obligations; the club remains responsible for its own.

Can the treasurer complete the SAQ without a security consultant?

Yes, for SAQ A. SAQ A is the simplest self-assessment form, designed for merchants who have fully outsourced card processing to a compliant provider. It covers a focused set of questions about website security, third-party provider compliance, and operational practices—all of which the treasurer can verify without technical security expertise. More complex SAQ types (A-EP, C, D) may benefit from consultation with a Qualified Security Assessor if the questions extend into technical network and application security areas that volunteer officers are not positioned to evaluate.

How does the club handle a member who insists on providing card details by phone or email?

Redirect the member to the online payment form. Accepting card details through an informal channel—by phone, text, email, or written note—creates card data outside the processor’s secure environment and expands the club’s PCI scope to include whatever system the information passes through. If the online payment form creates an access barrier for a specific member (technology access, disability accommodations), consult the payment processor about official telephone or assisted payment options that remain within the compliant environment.

What happens if the booster club switches payment processors mid-year?

PCI compliance follows the payment environment at the time of the annual SAQ. If the club switches processors, the SAQ completed at year-end should reflect the current processor. The club should also verify that no cardholder data from the prior processor relationship remains in any system the club controls. Former processor administrative credentials should be deactivated, and the prior processor’s data retention and deletion practices should be confirmed through the service agreement or by direct inquiry.

It depends on how those pages process card data. If a social media fundraising feature routes payment data through the platform’s own compliant infrastructure and the booster club receives only donation confirmation notifications without card data, the platform’s compliance covers the payment layer. If the club uses a custom peer-to-peer fundraising setup where card fields appear on a page the club controls, that page falls within the club’s PCI scope. Confirm the data flow with the platform before enabling any social fundraising feature that accepts card payments.

Award and recognition programs that build lasting visibility for student and athletic achievements depend on financial systems that can sustain multi-year commitments—PCI compliance is one of the foundational controls that keeps those financial systems credible and operational.

School honor programs and academic achievement recognition are funded by the same community members whose payment security PCI compliance protects—treating payment security as integral to the recognition program, not separate from it, reflects the organizational discipline that sustains donor and family confidence over time.


When your booster club is ready to build the recognition infrastructure that reflects the financial stewardship your PCI compliance program protects—digital donor walls with accurate giving histories, lobby displays with verified sponsor placements, and athletic records boards designed for long-term governance—explore how Rocket Alumni Solutions supports school programs with recognition systems built for institutional accountability.

Live Example: Rocket Alumni Solutions Touchscreen Display

Interact with a live example (16:9 scaled 1920x1080 display). All content is automatically responsive to all screen sizes and orientations.

1,000+ Installations - 50 States

Browse through our most recent halls of fame installations across various educational institutions