Free, quick comparison

PCI DSS compliance for small business

What PCI DSS actually requires of a small UK business, how the self-assessment works, and which payment providers keep your compliance scope simplest.

Compare now No obligation · Takes minutes

Trusted choice

Rated 4.9 out of 5

Secure checkout screen representing PCI DSS compliant payments
★ TrustpilotTrustScore 4.9 | reviews
Stripe logoProvider

Stripe (hosted checkout)

1.5% + 20p
per transaction
SAQ A
compliance level
Card data handling: Never touches your server
Setup: Self-serve
Simplest PCI scope
SumUp logoProvider

SumUp card machine

1.69%
per transaction
SAQ B
compliance level
Card data handling: Dedicated terminal only
Setup: Self-serve
Opayo logoProvider

Opayo by Elavon

From 1.0%
per transaction
SAQ A / A-EP
compliance level
Card data handling: Hosted or tokenised fields
Setup: Account managed
Worldpay logoProvider

Worldpay Simplicity

0.75%
per transaction
SAQ A / B
compliance level
Card data handling: Terminal or hosted page
Setup: Account managed

Deal tables sorted by headline rate (low to high)

Rates shown are indicative and depend on your turnover, average transaction value and business type. Final pricing is confirmed by the provider after your quote.

Padlock icon overlay on a card payment screen representing security

What is PCI DSS?

PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements every business that handles card data must meet, set by the major card schemes rather than UK law directly — though your merchant agreement contractually requires it.

Most small businesses meet it through a Self-Assessment Questionnaire (SAQ) rather than a full external audit, and the SAQ level required depends entirely on how your card data flows — a hosted checkout or a standalone card machine keeps the scope, and the paperwork, dramatically smaller than building your own payment form.

Why compare PCI DSS compliant providers providers?

Simpler compliance saves time

Choosing a hosted checkout or standalone terminal can drop your annual paperwork from a lengthy audit to a short self-assessment.

Lower breach risk

Keeping card data off your own servers entirely removes the biggest source of small business data breaches.

Required to keep processing

Your merchant agreement requires ongoing PCI compliance — losing it can mean losing the ability to accept cards at all.

What to look for in a PCI DSS compliant providers deal

Card data scope

The less your own systems touch raw card numbers, the shorter your compliance questionnaire — hosted and tokenised options minimise this by design.

Headline pricing

The percentage or flat fee taken from each payment. Compare on your real volumes, not the marketing rate.

Monthly and hidden fees

Check minimum monthly charges, PCI fees, gateway fees, refund charges and chargeback costs.

Settlement speed

How quickly funds reach your business account — next day makes a real difference to cashflow.

Security and compliance

PCI DSS scope, 3D Secure, tokenisation and fraud screening should be included, not bolted on.

Reporting and integrations

Links to your accounting software, EPOS or online store so takings reconcile automatically.

How does comparing PCI DSS compliant providers work?

Identify how card data reaches you — a physical terminal, a hosted checkout page, or fields built directly into your own website.

Your acquirer or gateway tells you which SAQ level applies based on that flow — hosted and terminal-based setups get the shortest questionnaire.

Complete the annual SAQ (a self-certification, not an external audit, for most small businesses) and keep evidence of basic security practices.

Re-certify annually — most providers send a reminder before your PCI compliance date and can point you to the right questionnaire.

Do I need PCI DSS compliant providers?

Any business taking card payments in any form needs to be PCI compliant — there's no size threshold that exempts you, though the requirements scale with how you handle card data.

Businesses using only a standalone card machine or a fully hosted checkout have the lightest requirement, typically a short annual questionnaire.

Businesses building their own custom checkout that touches raw card numbers face significantly more scope and should budget for that complexity upfront.

Business owner reviewing payment provider quotes

How do I choose the best PCI DSS compliant providers deal?

The biggest lever you control is architecture, not paperwork: a hosted checkout or tokenised fields keep you in the simplest SAQ-A category, while handling raw card numbers on your own server pushes you into a far heavier compliance level. Choose a provider that keeps card data off your systems entirely wherever the customer experience allows it.

How much could I save on PCI DSS compliant providers?

Moving from a self-built checkout that handles raw card data to a hosted or tokenised checkout can cut PCI compliance effort from a multi-week annual exercise to a short yearly questionnaire, freeing that time for the rest of the business.

FAQs

Our services are provided at no cost to you. We may receive a commission from the companies we refer you to, but this does not affect what you will pay for the product you choose.

Written by the Grow Your Business payments team · Updated 25 July 2026