Cannabis Point of Sale: The Rules a Till Sits Inside
A cannabis point-of-sale system is one part of a retail operation, not the operation’s compliance perimeter. The rules around the till include payment-account security standards, federal tax reporting and recordkeeping, financial-institution due diligence and suspicious-activity reporting, and state and local licensing requirements.
A cannabis point-of-sale system is one part of a retail operation, not the operation’s compliance perimeter. The rules around the till include payment-account security standards, federal tax reporting and recordkeeping, financial-institution due diligence and suspicious-activity reporting, and state and local licensing requirements. This article describes the position as of August 20, 2026; it can change after that date. 1234
This article is general information, not individualized legal, medical, business, or compliance advice. Whether any of it applies to a particular person, product or business depends on the facts and on applicable state law; consult a qualified professional.
The card-security standards body
The PCI Security Standards Council is a global forum that develops, enhances, stores, disseminates and supports implementation of security standards for payment account data. Its standards and resources address people, processes and technologies across the payment ecosystem, including entities that store, process or transmit payment account data and entities that accept or process payment transactions. 1
PCI SSC develops and maintains standards; it does not monitor implementation or enforce compliance. Whether a business must comply with, or validate compliance to, an applicable PCI standard is left to the organizations managing the relevant compliance program, such as a payment brand, acquirer or other entity. 1
That distinction matters at the till. A software feature is not legal compliance, and a payment provider’s policy is not federal law. A system may record or transmit payment information, but the evidence does not establish that buying a system confers PCI compliance, payment acceptance or access to any particular payment relationship. 1
Tax obligations attach to the sale
Cannabis businesses must report taxable income, including income received in cash. Businesses trafficking marijuana in contravention of federal or state law are subject to the limitations of Internal Revenue Code Section 280E. The till’s payment method does not change the underlying reporting obligation. 2
Cash also creates specific reporting duties. A person in a trade or business that receives more than $10,000 in cash in one transaction or related transactions must file Form 8300 within 15 days after receiving payment. Financial institutions and other persons subject to FinCEN regulations separately report qualifying currency transactions involving marijuana-related businesses under the same rules and thresholds that apply in other contexts; for example, banks and money services businesses report receipt or withdrawal of more than $10,000 in cash per day. 23
Small-business taxpayers often need quarterly estimated tax payments. Good records help track transactions and deductible expenses and substantiate items reported on tax returns; the evidence describes a recordkeeping system that summarizes all business transactions and generally records them daily. 2
A POS record can be part of a business’s records, but inventory recordkeeping is not regulatory approval. The evidence does not establish that any software feature satisfies every tax obligation, resolves Section 280E treatment or determines what a business may deduct. Tax decisions should be handled with a qualified tax professional. 2
What a financial institution is expected to do
FinCEN guidance explains how financial institutions may provide services to marijuana-related businesses consistently with their Bank Secrecy Act obligations. It does not require every institution to open an account. The decision to open, close or refuse an account or relationship is made by each financial institution based on institution-specific factors, including business objectives, product or service risk and the institution’s capacity to manage that risk. 3
Customer due diligence is central to that decision. The guidance describes verifying state licensure and registration, reviewing the license application and related documents, seeking available information from state licensing and enforcement authorities, understanding expected business activity and customer types, monitoring public information and suspicious activity, and periodically refreshing information in proportion to risk. 3
A financial institution that provides services to a marijuana-related business must file suspicious-activity reports under the applicable rules. That obligation is unaffected by a state law legalizing marijuana-related activity. The guidance distinguishes a “Marijuana Limited” SAR when the institution reasonably believes the business does not implicate specified enforcement priorities or violate state law, and a “Marijuana Priority” SAR when its due diligence indicates that it does. 3
A financial institution may also terminate a relationship when it considers termination necessary to maintain an effective anti-money-laundering compliance program, with a SAR noting the basis for termination. A payment provider’s policy, account decision or acceptance decision is therefore not a guarantee of banking access or payment acceptance, and platform availability is not universal eligibility. 3
Licensing is a separate gate
California illustrates the state-specific structure. California allows medicinal and adult use, but its cannabis industry is strictly regulated. The state’s cannabis statute establishes a framework for licensing, oversight and enforcement, while the Department of Cannabis Control creates regulations covering license applications, business operations, packaging, testing, Track and Trace and enforcement actions. 4
California’s rules are not a universal rule for every state. In California, cities and counties may also impose ordinances governing the time, place and manner of operation. Those ordinances apply only in the jurisdiction that created them and cannot conflict with state statutes or regulations. 4
The state licensing requirement is about who may operate a cannabis business, not which POS system was purchased. Buying a system does not confer a cannabis license, regulatory approval or permission to sell. A financial institution’s due diligence may itself include verifying that the business is duly licensed and registered, which reinforces that licensing exists outside the till. 34
What the till cannot establish
- A software feature is not legal compliance. The evidence identifies separate PCI, tax, banking and state regulatory requirements; it does not establish that a feature fulfills all of them. 124
- Automation is not human or legal review. The banking guidance calls for customer due diligence, ongoing monitoring and periodic information refreshes; those obligations remain processes for the financial institution and do not become legal review merely because software performs a task. 3
- A payment provider’s policy is not federal law. PCI SSC develops standards, while payment brands, acquirers and other compliance-program managers determine applicable compliance or validation requirements. 1
- Platform availability is not universal eligibility. Each financial institution decides whether to provide a relationship based on its own objectives, risk assessment and capacity to manage risk. 3
- Inventory recordkeeping is not regulatory approval. The California materials identify Track and Trace, licensing, operating rules and enforcement as distinct regulatory subjects. 4
- AI assistance is not autonomous compliance. The evidence establishes neither an AI capability nor a basis for treating automated assistance as a substitute for the applicable human, institutional or legal determinations. 134
The practical boundary is straightforward: a till may sit inside processes for recording sales and handling payment data, but it does not itself decide whether a business is licensed, how federal tax rules apply, whether a financial institution will accept the relationship, what suspicious-activity reporting is required, or whether a payment compliance program requires validation. Those decisions should be reviewed with qualified legal, tax and compliance professionals. 1234