The acquirer’s letter says your compliance validation is overdue. There is a new line on the monthly statement. And nobody is quite sure who filled in last year’s questionnaire, or whether it was even the right one.
PCI DSS applies to any business that stores, processes or transmits payment card data, or could affect its security. In the UK it is enforced through your contract with your acquirer rather than by a regulator, and the amount of work depends almost entirely on how much card data you actually touch.
PCI DSS is the card industry’s security standard, written by the PCI Security Standards Council and enforced by card brands and acquirers. Any business that accepts card payments falls under it. The current version is 4.0.1, and how you prove compliance depends on how much card data you handle.
Does PCI DSS Apply to Your Business?
Yes, if you accept card payments. The PCI Security Standards Council says the standard applies to “all entities involved in payment card processing”, and lists merchants alongside processors, acquirers, issuers and service providers. Using a payment provider reduces how much of the standard you have to meet, but it does not take you out of scope.
Barclaycard puts it more bluntly for its own merchants: compliance is “mandatory for all businesses who take card payments”. So the real question is not whether it applies but how much of it does. This is the plain-English version Transputec gives clients: who it applies to, what it asks for, and what it costs.
Why Does It Matter If It Is Not UK Law?
Because your acquirer can enforce it. The Council writes the standard, but whether you must comply and how you validate is decided by “organizations that manage compliance programs, such as a payment brand, acquirer, or other entity”. That makes it a contractual obligation with commercial consequences, starting with the charges an acquirer can apply while you are out of line.
And a breach that involves customers’ personal data brings UK data protection law in as well.
Card Payments? Get the Security Work Right
Transputec's PCI DSS-aligned penetration testing, vulnerability management and managed SOC reporting support the testing and monitoring side of the standard. Talk to the team about the work behind your next validation.
Get a Strategic ConsultationWhat Are the PCI DSS Requirements?
The standard has 12 principal requirements, grouped under six goals. Each one breaks down into detailed sub-requirements and testing procedures, which is where the real volume sits. The headline list, as the Council words it:
| Goal | Principal requirement |
|---|---|
| Build and Maintain a Secure Network and Systems | 1. Install and Maintain Network Security Controls |
| 2. Apply Secure Configurations to All System Components | |
| Protect Account Data | 3. Protect Stored Account Data |
| 4. Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks | |
| Maintain a Vulnerability Management Program | 5. Protect All Systems and Networks from Malicious Software |
| 6. Develop and Maintain Secure Systems and Software | |
| Implement Strong Access Control Measures | 7. Restrict Access to System Components and Cardholder Data by Business Need to Know |
| 8. Identify Users and Authenticate Access to System Components | |
| 9. Restrict Physical Access to Cardholder Data | |
| Regularly Monitor and Test Networks | 10. Log and Monitor All Access to System Components and Cardholder Data |
| 11. Test Security of Systems and Networks | |
| Maintain an Information Security Policy | 12. Support Information Security with Organizational Policies and Programs |
Several will look familiar. Network security controls, secure configuration, malware protection and access control all have direct counterparts in the five Cyber Essentials controls, so work done for one usually helps the other.
Requirement 11 needs specialist input from two directions. External vulnerability scans have to be run by an Approved Scanning Vendor, a company approved for that role by the PCI Security Standards Council, so check any scanning provider against the Council’s official list. Penetration testing is a different job, and that is where Transputec comes in: our penetration testing is aligned to PCI DSS, and our vulnerability management reporting covers PCI DSS evidence alongside ISO 27001 and Cyber Essentials Plus.
Does PCI DSS Apply to Small Businesses?
Yes, in full, but smaller businesses can often take the lightest route through it. Your acquirer tells you how to validate, and your level is set by volume: in Visa’s words, “a merchant’s total Visa transaction volume over a 12-month period determines your merchant level and the necessary requirements for validation”. For smaller merchants, that is often a self-assessment questionnaire, or SAQ.
The lightest, SAQ A, is for merchants whose account data functions are “completely outsourced to PCI DSS validated and compliant third parties” and who do not store, process or transmit any account data electronically. Think e-commerce or mail and telephone order businesses using a hosted payment page.
The Council changed SAQ A on 30 January 2025. Requirements 6.4.3 and 11.6.1, which cover payment page security, and requirement 12.3.1 were removed from SAQ A, and a new eligibility criterion was added: merchants must confirm their site is not susceptible to attacks from scripts that could affect their e-commerce systems.
That trade is worth understanding. Outsourcing payment handling shrinks your scope dramatically, but it does not remove your responsibility for the website that sends customers to the payment page.
What Changed in PCI DSS 4.0?
Version 4.0 added 64 new requirements, and 51 of them were future-dated, becoming mandatory on 31 March 2025. Version 4.0.1, published on 11 June 2024, was a limited revision with “no additional or deleted requirements”, and v4.0 was retired on 31 December 2024. So 4.0.1 is the version assessments run against now.
Two requirements show where the standard is heading. Requirement 12.5.2 calls for an annual scope confirmation exercise, and 11.3.2 calls for external vulnerability scans by an Approved Scanning Vendor at least once every three months. Both work against the same habit: treating compliance as a once-a-year form rather than something that stays true all year.
How Much Does PCI DSS Compliance Cost in the UK?
There is no single price, because most of the cost is the work of reducing and securing your scope, and that depends on your setup. What is published is what acquirers charge. Barclaycard, for example, lists its Proactive Security Service at £15 plus VAT per month per outlet, and charges £4.80 per month per level at which you attest compliance if you use its Data Security Manager or a third-party provider instead. It also warns that merchants who miss the deadline “could incur non-compliance charges”, without publishing the amount.
Search for PCI DSS compliance cost UK figures and you will find plenty of ranges with nothing behind them. The honest breakdown is three buckets: your acquirer’s fees, any external testing that applies to you, and the internal time or managed support needed to keep controls and evidence current, which is the gap compliance as a service is designed to fill. The biggest lever on all three is reducing how much card data you touch in the first place.
What Happens If Card Data Is Breached?
Two things at once. Your acquirer’s contract governs the payment card side, and if customers’ personal data is involved, UK GDPR applies too. The ICO’s guidance is that if a risk is likely, “you must notify us, as soon as possible, and where feasible within 72 hours”.
Card payment security requirements do not stop at the standard, in other words. The evidence you keep for your acquirer, meaning logs, access records and scan results, is the same evidence you will need to understand a breach quickly enough to report it. Transputec’s managed SOC services produce monthly compliance reporting that covers PCI DSS alongside ICO incident notification.
Your PCI DSS Checklist
- Ask your acquirer which merchant level you are and how they want you to validate.
- Map every place card data enters, moves through or is stored in your business, including phone lines and email.
- Cut that scope wherever you can, for example with a hosted payment page so card numbers never touch your systems.
- If you rely on SAQ A, confirm your website is not susceptible to script attacks that could affect your e-commerce systems.
- Check you are validating against version 4.0.1, not a retired version.
- Where external scans apply to you, book them with an Approved Scanning Vendor at least once every three months.
- Confirm your scope at least once a year rather than assuming last year’s still holds.
- Keep logs, access records and scan results in a state you could hand over without a scramble.
- Decide who reports a breach, and test that you could notify the ICO within 72 hours if customers’ personal data is involved.
Conclusion
The standard is not a UK law, but for any business taking card payments it behaves like one, because your acquirer enforces it and can charge you while you are out of line. The good news for many smaller businesses is that the effort scales with the card data you touch, and outsourcing payment handling can shrink it to a fraction of the full standard.
For PCI DSS compliance, UK businesses answer to their acquirer, not to Transputec: we do not validate compliance or sit between you and them. What we do is the security work the questionnaire is asking about: aligned penetration testing, vulnerability management and monitoring that produce evidence you can stand behind, delivered through our cyber security services. If you want to see how that fits a wider programme, our guide to what compliance as a service is sets out the model.
If your acquirer’s letter is sitting unanswered, talk to us about the security work behind your answer.
FAQs
Does PCI DSS Apply to Small Businesses?
Yes. It applies to any business that stores, processes or transmits cardholder data or could affect its security, regardless of size. What changes with size is how you validate: your acquirer sets that by merchant level, and smaller merchants that fully outsource card handling may qualify for SAQ A, the lightest self-assessment questionnaire.
What Are the PCI DSS Requirements?
There are 12 principal requirements under six goals: a secure network and systems, protecting account data, vulnerability management, access control, monitoring and testing, and information security policy. Transputec’s aligned penetration testing sits under requirement 11, Test Security of Systems and Networks.
How Much Does PCI DSS Compliance Cost in the UK?
It depends mostly on your scope. Acquirer fees are published: Barclaycard lists £15 plus VAT per month per outlet for its Proactive Security Service, or £4.80 per month per level if you attest another way, and warns of non-compliance charges for missed deadlines. External testing and keeping evidence current make up the rest.
Is PCI DSS a Legal Requirement in the UK?
No, it is an industry standard rather than legislation. Payment brands and acquirers decide whether and how you must comply, and enforce it through your merchant contract. A breach involving customers’ personal data also brings in UK GDPR, and the ICO expects notification within 72 hours where feasible if a risk is likely.
What Is the Current Version of PCI DSS?
Version 4.0.1, published on 11 June 2024 as a limited revision with no added or deleted requirements. Version 4.0 was retired on 31 December 2024, and the 51 future-dated requirements introduced in v4.0 became mandatory on 31 March 2025.
This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.



