What PCI DSS actually requires of a small UK business, how the self-assessment works, and which payment providers keep your compliance scope simplest.
Trusted choice
Rated 4.9 out of 5
Deal tables sorted by headline rate (low to high)
Rates shown are indicative and depend on your turnover, average transaction value and business type. Final pricing is confirmed by the provider after your quote.
PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements every business that handles card data must meet, set by the major card schemes rather than UK law directly — though your merchant agreement contractually requires it.
Most small businesses meet it through a Self-Assessment Questionnaire (SAQ) rather than a full external audit, and the SAQ level required depends entirely on how your card data flows — a hosted checkout or a standalone card machine keeps the scope, and the paperwork, dramatically smaller than building your own payment form.
Choosing a hosted checkout or standalone terminal can drop your annual paperwork from a lengthy audit to a short self-assessment.
Keeping card data off your own servers entirely removes the biggest source of small business data breaches.
Your merchant agreement requires ongoing PCI compliance — losing it can mean losing the ability to accept cards at all.
The less your own systems touch raw card numbers, the shorter your compliance questionnaire — hosted and tokenised options minimise this by design.
The percentage or flat fee taken from each payment. Compare on your real volumes, not the marketing rate.
Check minimum monthly charges, PCI fees, gateway fees, refund charges and chargeback costs.
How quickly funds reach your business account — next day makes a real difference to cashflow.
PCI DSS scope, 3D Secure, tokenisation and fraud screening should be included, not bolted on.
Links to your accounting software, EPOS or online store so takings reconcile automatically.
Identify how card data reaches you — a physical terminal, a hosted checkout page, or fields built directly into your own website.
Your acquirer or gateway tells you which SAQ level applies based on that flow — hosted and terminal-based setups get the shortest questionnaire.
Complete the annual SAQ (a self-certification, not an external audit, for most small businesses) and keep evidence of basic security practices.
Re-certify annually — most providers send a reminder before your PCI compliance date and can point you to the right questionnaire.
Any business taking card payments in any form needs to be PCI compliant — there's no size threshold that exempts you, though the requirements scale with how you handle card data.
Businesses using only a standalone card machine or a fully hosted checkout have the lightest requirement, typically a short annual questionnaire.
Businesses building their own custom checkout that touches raw card numbers face significantly more scope and should budget for that complexity upfront.
The biggest lever you control is architecture, not paperwork: a hosted checkout or tokenised fields keep you in the simplest SAQ-A category, while handling raw card numbers on your own server pushes you into a far heavier compliance level. Choose a provider that keeps card data off your systems entirely wherever the customer experience allows it.
Moving from a self-built checkout that handles raw card data to a hosted or tokenised checkout can cut PCI compliance effort from a multi-week annual exercise to a short yearly questionnaire, freeing that time for the rest of the business.
These guides might help.
Interchange, scheme and acquirer fees explained — and which ones you can negotiate away…
What UK providers check, how long onboarding takes and when a specialist beats your bank…
The compliance basics every business handling payments has to meet…
Not a direct UK law, but it's a mandatory condition of your merchant agreement with card schemes and acquirers — non-compliance risks fines or losing the ability to take card payments.
A Self-Assessment Questionnaire — the standard way most small businesses demonstrate PCI compliance annually, without a full external audit.
It significantly simplifies your scope, but you still need to complete the applicable SAQ each year and follow basic security practices like not storing card numbers yourself.
Your acquirer can apply non-compliance fees, and in the event of a breach, non-compliance significantly increases your liability for the resulting costs.
Our services are provided at no cost to you. We may receive a commission from the companies we refer you to, but this does not affect what you will pay for the product you choose.
Written by the Grow Your Business payments team · Updated 25 July 2026