If your business takes card payments, your acquirer will expect you to meet PCI DSS and show how you comply. This guide explains who it applies to, what it requires and what it costs.
PCI DSS applies to any business that stores, processes or transmits payment card data, or could affect its security. In the UK, your acquirer enforces it through your contract, not a regulator. How much work it takes depends mostly on how much card data you handle.
PCI DSS is the card industry’s security standard, written by the PCI Security Standards Council and enforced by card brands and acquirers. Any business that accepts card payments falls under it. The current version is 4.0.1, and how you prove compliance depends on how much card data you handle.
Does PCI DSS Apply to Your Business?
Yes, if you accept card payments. The PCI Security Standards Council says the standard applies to “all entities involved in payment card processing”, and lists merchants alongside processors, acquirers, issuers and service providers. Using a payment provider reduces how much of the standard you have to meet, but it does not take you out of scope.
Barclaycard says the same for its own merchants: compliance is “mandatory for all businesses who take card payments”. What varies is how much of the standard applies to you. This is the plain-English explanation Transputec gives clients: who it applies to, what it asks for and what it costs.
Why Does It Matter If It Is Not UK Law?
Because your acquirer can enforce it. The Council writes the standard, but whether you must comply and how you validate is decided by “organizations that manage compliance programs, such as a payment brand, acquirer, or other entity”. So it’s a contractual obligation, and your acquirer can charge you while you’re not compliant.
If a breach involves customers’ personal data, UK data protection law applies as well.
Card Payments? Get the Security Work Right
Transputec's PCI DSS-aligned penetration testing, vulnerability management and managed SOC reporting support the testing and monitoring side of the standard. Talk to the team about the work behind your next validation.
Get a Strategic ConsultationWhat Are the PCI DSS Requirements?
The standard has 12 principal requirements, grouped under six goals. Each one is broken down into detailed sub-requirements and testing procedures, and that’s where most of the work is. Here’s the full list of requirements, in the Council’s own wording:
| Goal | Principal requirement |
|---|---|
| Build and Maintain a Secure Network and Systems | 1. Install and Maintain Network Security Controls |
| 2. Apply Secure Configurations to All System Components | |
| Protect Account Data | 3. Protect Stored Account Data |
| 4. Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks | |
| Maintain a Vulnerability Management Program | 5. Protect All Systems and Networks from Malicious Software |
| 6. Develop and Maintain Secure Systems and Software | |
| Implement Strong Access Control Measures | 7. Restrict Access to System Components and Cardholder Data by Business Need to Know |
| 8. Identify Users and Authenticate Access to System Components | |
| 9. Restrict Physical Access to Cardholder Data | |
| Regularly Monitor and Test Networks | 10. Log and Monitor All Access to System Components and Cardholder Data |
| 11. Test Security of Systems and Networks | |
| Maintain an Information Security Policy | 12. Support Information Security with Organizational Policies and Programs |
Some will look familiar. Network security controls, secure configuration, malware protection and access control all match controls in the five Cyber Essentials controls, so work on one usually helps with the other.
Requirement 11 needs two kinds of specialist help. External vulnerability scans must be run by an Approved Scanning Vendor, a company approved for that role by the PCI Security Standards Council, so check any scanning provider against the Council’s official list. Penetration testing is separate. Transputec’s penetration testing is aligned to PCI DSS, and our vulnerability management reporting covers PCI DSS evidence alongside ISO 27001 and Cyber Essentials Plus.
Does PCI DSS Apply to Small Businesses?
Yes, fully, but smaller businesses can often use the lightest way to validate. Your acquirer tells you how to validate, and your level depends on volume. Visa says “a merchant’s total Visa transaction volume over a 12-month period determines your merchant level and the necessary requirements for validation”. For smaller merchants, that’s often a self-assessment questionnaire (SAQ).
The lightest, SAQ A, is for merchants whose account data functions are “completely outsourced to PCI DSS validated and compliant third parties” and who don’t store, process or transmit any account data electronically. For example, e-commerce or mail and telephone order businesses that use a hosted payment page.
The Council changed SAQ A on 30 January 2025. Requirements 6.4.3 and 11.6.1, which cover payment page security, and requirement 12.3.1 were removed from SAQ A. A new eligibility criterion was added: merchants must confirm their site is not susceptible to attacks from scripts that could affect their e-commerce systems.
Outsourcing payment handling greatly reduces your scope, but you’re still responsible for the website that sends customers to the payment page.
What Changed in PCI DSS 4.0?
Version 4.0 added 64 new requirements, and 51 of them were future-dated, becoming mandatory on 31 March 2025. Version 4.0.1, published on 11 June 2024, was a limited revision with “no additional or deleted requirements”, and v4.0 was retired on 31 December 2024. Assessments now use version 4.0.1.
Two requirements show the direction of the standard. Requirement 12.5.2 calls for an annual scope confirmation exercise, and 11.3.2 calls for external vulnerability scans by an Approved Scanning Vendor at least once every three months. Both are meant to keep you compliant all year, not just when you fill in the form.
How Much Does PCI DSS Compliance Cost in the UK?
There’s no single price. Most of the cost is the work of reducing and securing your scope, which depends on your setup. Acquirer fees are published, though: Barclaycard, for example, lists its Proactive Security Service at £15 plus VAT per month per outlet.
It charges £4.80 per month per level at which you attest compliance if you use its Data Security Manager or a third-party provider instead. It also says merchants who miss the deadline “could incur non-compliance charges”, but doesn’t publish the amount.
If you search for PCI DSS compliance cost UK figures, you’ll find plenty of estimates without sources. The real costs fall into three areas: your acquirer’s fees, any external testing that applies to you, and the internal time or managed support needed to keep controls and evidence up to date. That last area is what compliance as a service is designed to cover. The best way to reduce all three is to handle less card data in the first place.
What Happens If Card Data Is Breached?
Two sets of rules apply. Your acquirer’s contract covers the payment card side, and if customers’ personal data is involved, UK GDPR applies too. The ICO says that if a risk is likely, “you must notify us, as soon as possible, and where feasible within 72 hours”.
So card payment security requirements go beyond the standard. The logs, access records and scan results you keep for your acquirer are the same evidence you’ll need to understand a breach quickly enough to report it. Transputec’s managed SOC services produce monthly compliance reporting that covers PCI DSS alongside ICO incident notification.
Your PCI DSS Checklist
- Ask your acquirer which merchant level you are and how they want you to validate.
- List every place card data enters, moves through or is stored in your business, including phone lines and email.
- Reduce that scope where you can, for example with a hosted payment page so card numbers never reach your systems.
- If you rely on SAQ A, confirm your website is not susceptible to script attacks that could affect your e-commerce systems.
- Check you are validating against version 4.0.1, not a retired version.
- Where external scans apply to you, book them with an Approved Scanning Vendor at least once every three months.
- Confirm your scope at least once a year instead of assuming last year’s is still right.
- Keep logs, access records and scan results organised so you can hand them over quickly.
- Decide who reports a breach, and test that you could notify the ICO within 72 hours if customers’ personal data is involved.
Conclusion
The standard isn’t UK law, but if your business takes card payments you still have to follow it, because your acquirer enforces it and can charge you if you don’t. For many smaller businesses, the effort depends on how much card data they handle, and outsourcing payment handling can reduce it to a small part of the full standard.
For PCI DSS compliance, UK businesses answer to their acquirer, not to Transputec. We don’t validate compliance or act between you and your acquirer. We do the security work the questionnaire asks about: aligned penetration testing, vulnerability management and monitoring that produce reliable evidence, delivered through our cyber security services. To see how that fits a wider programme, read our guide to what compliance as a service is.
If your acquirer has asked you to confirm compliance, talk to us about the security work behind your answer.
FAQs
Does PCI DSS Apply to Small Businesses?
Yes. It applies to any business that stores, processes or transmits cardholder data or could affect its security, regardless of size. What changes with size is how you validate: your acquirer sets that by merchant level, and smaller merchants that fully outsource card handling may qualify for SAQ A, the lightest self-assessment questionnaire.
What Are the PCI DSS Requirements?
There are 12 principal requirements under six goals: a secure network and systems, protecting account data, vulnerability management, access control, monitoring and testing, and information security policy. Transputec’s aligned penetration testing sits under requirement 11, Test Security of Systems and Networks.
How Much Does PCI DSS Compliance Cost in the UK?
It depends mostly on your scope. Acquirer fees are published: Barclaycard lists £15 plus VAT per month per outlet for its Proactive Security Service, or £4.80 per month per level if you attest another way, and warns of non-compliance charges for missed deadlines. External testing and keeping evidence current make up the rest.
Is PCI DSS a Legal Requirement in the UK?
No, it’s an industry standard, not legislation. Payment brands and acquirers decide whether and how you must comply, and enforce it through your merchant contract. A breach involving customers’ personal data also brings in UK GDPR, and the ICO expects notification within 72 hours where feasible if a risk is likely.
What Is the Current Version of PCI DSS?
Version 4.0.1, published on 11 June 2024 as a limited revision with no added or deleted requirements. Version 4.0 was retired on 31 December 2024, and the 51 future-dated requirements introduced in v4.0 became mandatory on 31 March 2025.
This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.



