Concerns about merchant data security standards prompted development of the Payment Card Industry Data Security Standard (PCI DSS). However, a significant gap in compliance between small and midsize businesses (SMBs) and relatively larger firms creates an unresolved challenge that must be addressed to effect end-to-end data security.