Having staff accept credit card payments over the phone can be a convenient option for businesses and organizations, but it also brings with it specific security obligations under the Payment Card Industry Data Security Standard (PCI DSS). For organizations that manually enter customer credit card data into a virtual terminal (VT), compliance isn’t just about using a PCI-compliant virtual terminal or PCI compliant card entry application; it begins well before the card information is keyed in. Let’s explore what the PCI DSS requires for handling these transactions, particularly under the Self-Assessment Questionnaire (SAQ) C-VT, and discuss some alternatives that can reduce your PCI compliance burden.