PCI DSS Compliance for UK Small Businesses: 2026 Guide

Updated August 2026. PCI DSS is the security standard for organisations that store, process or transmit payment-card account data. The current standard is PCI DSS v4.0.1. The major future-dated requirements associated with the v4 transition became effective on 31 March 2025, so older guidance describing them as optional future requirements is now out of date.
For a small UK business, PCI compliance is usually much easier when you use validated card terminals and provider-hosted online checkout rather than handling card details yourself. The goal should be to reduce the amount of payment-card data that ever touches your own systems.
Quick answer
- Current standard: PCI DSS v4.0.1.
- Who it applies to: organisations that store, process or transmit payment account data, with validation requirements set by the relevant card brands, acquirer or payment provider.
- Small retailer using a validated terminal: usually has a much smaller compliance scope than a business storing card details.
- Ecommerce: hosted checkout reduces scope but does not remove the need to secure the merchant website.
- SAQ A: the January 2025 version changed ecommerce eligibility and reporting around payment-page script security.
What does PCI DSS stand for?
PCI DSS means Payment Card Industry Data Security Standard. It is maintained by the PCI Security Standards Council and is designed to protect payment account data throughout the payment process.
PCI DSS is not a UK government licence. The Council publishes the standard and supporting validation tools, while compliance and validation requirements are typically enforced through card brands, acquiring banks and payment providers.
For the source standard, see the PCI Security Standards Council document library.
PCI DSS v4.0.1 is the current version
PCI DSS v4.0.1 was published as a limited revision to v4.0. It did not reset the timetable for the new v4 requirements. The future-dated requirements became effective on 31 March 2025.
If your old compliance guide still says those controls are “best practice until March 2025”, it needs updating.
Does PCI DSS apply to a small business?
Yes, size does not automatically create an exemption. A sole trader taking card payments can still fall within PCI DSS requirements.
The practical workload, however, can be dramatically different. A business using a validated standalone terminal and never storing card details has a much smaller payment-data environment than an ecommerce company running a custom card-processing stack.
If you are still selecting how to take payments, our accepting card payments guide explains the main models.
The 12 PCI DSS requirements
PCI DSS v4.x organises its requirements around six broad goals and 12 high-level requirements. In plain English, they cover:
- installing and maintaining network security controls;
- applying secure configurations to system components;
- protecting stored account data;
- protecting cardholder data with strong cryptography during transmission over open public networks;
- protecting systems and networks from malicious software;
- developing and maintaining secure systems and software;
- restricting access to system components and cardholder data by business need to know;
- identifying users and authenticating access;
- restricting physical access to cardholder data;
- logging and monitoring access;
- testing security systems and processes regularly;
- maintaining information-security policies and programmes.
A small merchant should not attempt to translate all of this into technical controls alone without first identifying which requirements actually apply to its payment environment.
What is a Self-Assessment Questionnaire?
Many smaller merchants validate compliance using a Self-Assessment Questionnaire, usually referred to as an SAQ. There are different SAQs because a shop using a standalone terminal does not have the same risk profile as an ecommerce merchant or a business using an integrated payment application.
Your acquirer or payment provider should tell you which validation route applies. Do not choose the shortest SAQ simply because it looks easier.
SAQ A changed for ecommerce merchants
SAQ A is intended for merchants whose account-data functions are fully outsourced to PCI DSS-compliant third parties and who do not electronically store, process or transmit account data on their own systems or premises.
In January 2025, PCI SSC updated SAQ A. Requirements 6.4.3, 11.6.1 and the related targeted risk analysis were removed from the SAQ A reporting form itself, but a new eligibility criterion requires ecommerce merchants to confirm that their site is not susceptible to script attacks that could affect the ecommerce system.
The underlying PCI DSS requirements were not deleted from the standard. This distinction matters.
Why website scripts matter
Modern ecommerce sites load scripts for analytics, marketing, reviews, chat, tag managers and other tools. Malicious or compromised scripts can alter a payment page or steal information.
Using a hosted checkout is therefore not an excuse to ignore the rest of the website. Keep WordPress, plugins, themes, ecommerce software and third-party scripts under control.
For payment architecture, see our online payment gateway guide and ecommerce merchant accounts guide.
Do you need to store card details?
Most small businesses should avoid doing so. Use tokenisation or the payment provider’s stored-payment features instead of keeping raw card numbers in your own database.
Never store card security codes after authorisation. The safest payment data is often the data your business never receives.
Card machines and PCI DSS
A business using a validated card terminal generally has a simpler compliance path because the terminal and provider handle the sensitive card interaction.
This is another reason to buy supported hardware through a recognised card-machine provider rather than buying an unknown used terminal and trying to configure it yourself.
See our PDQ terminal guide for hardware considerations.
Mobile card readers
Phone-paired readers from mainstream providers are designed to keep sensitive card data inside the provider’s secure payment process rather than exposing it to the merchant’s phone app.
The business still needs to secure the account, device and staff access. Use strong authentication and remove access promptly when an employee leaves.
See our mobile card reader guide.
Virtual Terminal and telephone payments
A Virtual Terminal is a secure provider interface used to key card details for telephone payments. It is much safer than writing details down or storing them in an ordinary spreadsheet.
Staff should enter the information directly into the approved system and avoid creating separate copies of card data.
Our credit card processing guide explains card-present and card-not-present processing in more detail.
Passwords and authentication
PCI DSS v4.x strengthened identity and authentication expectations. Businesses should use unique accounts, strong passwords and multi-factor authentication where required rather than sharing one administrator login among staff.
Even if the payment terminal itself is secure, a compromised merchant dashboard can expose transaction information or allow fraudulent account changes.
Keep systems patched
Apply security updates to POS software, computers, ecommerce platforms, plugins and network devices. Unsupported software is a poor foundation for a compliant payment environment.
If you run WordPress ecommerce, remove plugins you no longer use and do not leave abandoned themes or old integrations installed simply because they are disabled.
Network security
A café or shop should avoid putting payment systems on an unmanaged network shared freely with customers. Segment guest Wi-Fi from business systems where appropriate and secure routers using non-default credentials and current firmware.
Ask your EPOS supplier how its equipment connects before installation. Our EPOS systems guide covers wider till infrastructure.
Logging and monitoring
Businesses need enough logging to identify suspicious access and investigate incidents. For a micro-business using a hosted provider, much of this may be handled by the payment platform. For a larger or custom environment, the merchant may have much more responsibility.
Vulnerability scanning
Some merchant environments require external vulnerability scanning by an Approved Scanning Vendor. Whether you need this depends on the systems exposed to the internet and your validation route.
Do not buy scanning services simply because a salesperson says every merchant needs them. Confirm the requirement with your acquirer or compliance-enforcing entity.
What happens if you are not compliant?
PCI SSC does not itself levy merchant fines. Consequences normally arise through the card brands, acquirer or payment-provider relationship and can include extra fees, remediation requirements, account restrictions or increased liability following a breach.
The commercial risk of a payment-data breach can be far larger than any compliance administration fee.
High-risk merchants
Businesses in higher-risk sectors can face more scrutiny around fraud, chargebacks and payment security. PCI DSS is only one part of that wider acquiring assessment.
See our high-risk merchant account guide.
Simple PCI DSS checklist for a small merchant
- Use a reputable payment provider and supported terminal.
- Do not store card security codes.
- Keep raw card data out of your own systems wherever possible.
- Use unique accounts and strong authentication.
- Install security updates promptly.
- Keep payment devices physically secure.
- Separate customer Wi-Fi from business systems where appropriate.
- Train staff not to write down or message card details.
- Complete the SAQ or other validation requested by your provider.
- Review the payment setup whenever the website, POS or provider changes.
Changing payment provider can change your PCI scope
Moving from a hosted checkout to a custom payment integration can increase the systems in scope. Moving the other direction can reduce them.
Do not treat PCI compliance as a once-a-year form divorced from how the business actually takes payments.
Related Quotehunt guides
- How to accept card payments
- Online payment gateways
- Ecommerce merchant accounts
- Payment processing companies
- Card machine providers
- Mobile card readers
- High-risk merchant accounts
- Merchant accounts
Our verdict
For most UK small businesses, PCI DSS becomes much easier when the payment provider handles the sensitive card data. Use supported terminals, hosted checkout and provider-managed tokenisation rather than trying to store or process card details yourself.
The key 2026 update is that PCI DSS v4.0.1 is current and the major future-dated requirements have already taken effect. Ecommerce merchants should also understand the updated SAQ A eligibility requirement around script attacks.
If you are unsure which SAQ or validation process applies, ask the acquirer or payment provider that enforces compliance for your merchant account rather than guessing.
Need a card-payment setup that keeps your PCI scope manageable?



