We use essential cookies to make this site work. No tracking or advertising cookies are used. Cookie policy

Skip to main content
Back to Insights
Payments Explained

PCI Compliance for UK Small Businesses: The 10-Minute Guide That Could Save You Thousands

PCI compliance sounds like a headache reserved for banks and big retailers. It isn't. Every UK business that takes a card payment must comply, and the fines for getting it wrong are brutal.

3 October 2026
11 min read
Share:

PCI Compliance for UK Small Businesses: The 10-Minute Guide That Could Save You Thousands

Here is a number that should stop you mid-scroll: non-compliant businesses that suffer a card data breach can face fines of between £5,000 and £100,000 per month from their acquiring bank, before any regulatory action from the Financial Conduct Authority or the Information Commissioner's Office even enters the picture.

And yet, research consistently shows that small and medium-sized businesses are the least likely to be fully PCI compliant, and the most likely to be targeted by the kind of low-sophistication attacks that compliance is specifically designed to prevent.

This guide will not waste your time with legalese. In the next ten minutes, you will understand what PCI compliance actually is, what it requires from a business your size, what happens if you ignore it, and precisely what you need to do this week to get your house in order.


What PCI Compliance Actually Is (and Why It Exists)

PCI DSS stands for Payment Card Industry Data Security Standard. It is not a UK law or an FCA regulation in the traditional sense. It is a global technical and operational standard, created and maintained by the PCI Security Standards Council, which is a body founded in 2006 by Visa, Mastercard, American Express, Discover, and JCB.

Think of it like a building code for anyone who handles card payment data. The government sets fire safety regulations; the card schemes set data security standards. Both exist because the consequences of getting it wrong extend far beyond the individual business.

The standard applies to every organisation that stores, processes, or transmits cardholder data. That includes you if you take a single credit card payment in your shop, over the phone, or through your website. There is no turnover threshold. There is no "small business exemption". If you take cards, you are in scope.


The Four Merchant Levels: Where Does Your Business Sit?

The PCI DSS framework groups businesses into four merchant levels based on annual card transaction volume. Your level determines how rigorously you must demonstrate compliance.

Level 1: More than six million Visa or Mastercard transactions per year. These businesses must undergo an annual on-site audit by a Qualified Security Assessor. This is where the major supermarkets and national retailers sit.

Level 2: One million to six million transactions per year. Requires an annual Self-Assessment Questionnaire and quarterly network scans.

Level 3: Twenty thousand to one million e-commerce transactions per year. Similar requirements to Level 2, focused on online payment environments.

Level 4: Fewer than twenty thousand e-commerce transactions, or up to one million transactions across all other channels. This is where the vast majority of UK small businesses sit.

Level 4 sounds reassuring. It is not a free pass. Level 4 merchants must still complete an annual Self-Assessment Questionnaire (SAQ) and, depending on how they take payments, may require quarterly vulnerability scans of their systems. The difference is that you self-certify rather than bring in an external auditor, provided you are honest and thorough.


The Self-Assessment Questionnaire: Which One Do You Need?

This is where most small business owners get confused, because the PCI SSC publishes several different SAQ types depending on your payment environment. Choosing the wrong one is itself a compliance failure.

Here is a plain-English breakdown of the most relevant ones for UK SMEs:

SAQ A: For businesses that have fully outsourced all card processing. You do not store, process, or transmit any cardholder data on your own systems or premises. Examples include businesses using a hosted payment page from Stripe, PayPal, or a similar provider where the card entry happens entirely on their infrastructure. This is the simplest questionnaire, with approximately 22 requirements.

SAQ A-EP: For e-commerce businesses that outsource card processing but whose website indirectly affects the security of the payment. If your website loads scripts, redirects, or any elements that touch the payment flow, even tangentially, you may fall here rather than SAQ A. This is a common and costly misunderstanding.

SAQ B: For businesses that take payments only via standalone, dial-up card terminals that are not connected to any other systems or the internet. Many traditional retail shops with older terminals fall here.

SAQ B-IP: For businesses using standalone payment terminals that connect over IP (internet protocol) but do not store electronic cardholder data. Most modern card terminals in UK shops fall into this category.

SAQ C: For businesses whose payment application systems are connected to the internet. Useful for businesses running point-of-sale software on a networked system.

SAQ D: The most comprehensive questionnaire, covering all other merchants not covered by A through C. If in doubt, speak to your payment provider about which SAQ applies to your setup.

The single most important thing you can do right now is call your acquiring bank or payment provider and ask them two questions: "Which SAQ type do I need to complete?" and "Are you providing me with a compliant payment environment?"


The 12 Core Requirements: What You Are Actually Being Asked to Do

The PCI DSS standard (currently version 4.0.1, published in 2024) is built around 12 core requirements. For a small business, these translate into practical, real-world actions.

1. Install and maintain network security controls. In practice: ensure your router has a firewall enabled and is properly configured. Do not use factory-default passwords on any networking equipment.

2. Apply secure configurations to all system components. Change default usernames and passwords on every device and piece of software that touches your payment environment.

3. Protect stored account data. The safest approach for most small businesses is to not store card data at all. If you do not store it, you cannot lose it. Use tokenisation where your payment provider offers it.

4. Protect cardholder data with strong cryptography during transmission. Ensure your website uses HTTPS (look for the padlock). Ensure your payment terminal uses end-to-end encryption.

5. Protect all systems and networks from malicious software. Install reputable antivirus software on any computer connected to your payment systems. Keep it updated.

6. Develop and maintain secure systems and software. Apply security patches and software updates promptly. An unpatched system is an open door.

7. Restrict access to system components and cardholder data by business need to know. Not everyone in your business needs access to your payment systems. Limit access accordingly.

8. Identify users and authenticate access to system components. Every person who accesses your systems should have their own unique login. Shared passwords are a compliance failure and a security risk.

9. Restrict physical access to cardholder data. Ensure your card terminal is in a location where customers can use it without someone being able to observe their PIN. Be aware of card skimming devices.

10. Log and monitor all access to system components and cardholder data. For most small businesses, this is handled by your payment provider. Confirm this is the case.

11. Test security of systems and networks regularly. Depending on your SAQ type, this may include quarterly vulnerability scans from an Approved Scanning Vendor.

12. Support information security with organisational policies and programmes. Document your security practices. This sounds bureaucratic but a simple one-page policy noting how you handle card data, who has access, and what your incident response looks like is sufficient for most Level 4 merchants.


What Happens If You Are Not Compliant?

Let us be direct about the consequence chain, because it is more serious than most small business owners realise.

If your business suffers a data breach and you are found to be non-compliant, your acquiring bank can impose monthly fines ranging from £5,000 to £100,000. They can also pass through fines levied by the card schemes themselves, Visa and Mastercard, which can reach into the tens of thousands per incident. Your merchant account can be terminated, which means you lose the ability to accept card payments entirely.

Beyond the card scheme penalties, if cardholder data is compromised, you are also likely in breach of the UK GDPR, since payment card data constitutes personal data under the regulation. The ICO can fine you up to £17.5 million or 4% of global annual turnover, whichever is higher, for serious breaches. For a small business, even a fraction of that is existential.

Then there is the reputational damage. A 2023 study by Mastercard found that small businesses that suffer a publicised data breach lose an average of 40% of their customers within three months. Most do not recover.

Compliance is not bureaucracy for its own sake. It is the price of operating in the card payments ecosystem, and it is cheap compared to the alternative.


The Honest Good News for Most UK Small Businesses

If you are taking payments through a reputable, modern payment provider and not storing card data yourself, you are likely much closer to compliance than you think.

Providers that offer fully hosted payment pages, integrated terminal solutions with end-to-end encryption, and tokenisation handle the heavy lifting of PCI DSS on your behalf. Your responsibility narrows considerably. You still need to complete the appropriate SAQ, maintain basic security hygiene on your own systems, and document your approach. But you are not building a fortress from scratch.

The key questions to ask your payment provider are:

  • Are your terminals PCI-approved devices?
  • Do you offer end-to-end encryption and tokenisation?
  • Which SAQ type applies to my payment setup with you?
  • Do you provide quarterly vulnerability scans as part of my service?
  • Is PCI compliance support included, or is there an additional fee?

That last question matters. Some acquirers charge a monthly "PCI non-compliance fee" if you have not submitted your SAQ, often between £15 and £30 per month. This is not a compliance service. It is a penalty. And many businesses pay it for years without realising it could be eliminated simply by completing a questionnaire.


Your Action Plan: This Week

Day 1. Contact your payment provider or acquiring bank. Ask which SAQ type applies to your business. Ask whether you are currently being charged a PCI non-compliance fee.

Day 2. Change the default passwords on your Wi-Fi router, payment terminal, and any point-of-sale software. If you do not know how, call your broadband provider or terminal supplier. This is not optional.

Day 3. Ensure your business Wi-Fi network is separate from any network used to process payments. Guest Wi-Fi and payment terminals should never share a network.

Day 4. Complete your SAQ. The PCI SSC website (pcisecuritystandards.org) provides the official documents. Your payment provider may also offer a guided completion tool.

Day 5. Write one page documenting who in your business has access to payment systems, how that access is controlled, and what your procedure is if a card terminal is lost, stolen, or tampered with.

Five days. That is genuinely all it takes for most Level 4 merchants to get from "I've never thought about this" to "I am compliant and documented".


What This Means for Your Business

PCI compliance is not a one-time tick-box exercise. It is an ongoing posture. Renew your SAQ annually. Keep your software patched. Review who has access to your systems whenever a staff member leaves. And when you change your payment setup, whether switching providers, adding an online shop, or integrating a new till system, reassess which SAQ applies.

The businesses that get hurt by PCI non-compliance are almost never targeted by sophisticated hackers. They are caught out by basic, avoidable failures: default passwords, unpatched software, shared logins, card data stored in spreadsheets. The standard exists precisely to close those gaps.

You can protect your customers, your revenue, and your reputation. It starts with ten minutes today.

Sources

  1. PCI Security Standards Council: Official PCI DSS v4.0.1 documentation and SAQ types. https://www.pcisecuritystandards.org
  2. UK Finance: Payment Markets Summary 2024, covering UK card transaction volumes and merchant data. https://www.ukfinance.org.uk
  3. Information Commissioner's Office: UK GDPR fines framework and personal data definition including payment card data. https://ico.org.uk
  4. Financial Conduct Authority: FCA guidance on payment security obligations for UK merchants. https://www.fca.org.uk
  5. Mastercard: Small Business Cybersecurity Research 2023, referencing customer attrition following publicised data breaches. https://www.mastercard.com/news/insights
  6. Verizon Data Breach Investigations Report 2024: Small business breach targeting patterns and vulnerability analysis. https://www.verizon.com/business/resources/reports/dbir
  7. Payment Systems Regulator: PSR oversight of acquiring bank fee structures and merchant protections. https://www.psr.org.uk

Disclaimer

The views and information shared in this post are for educational and informational purposes only and do not constitute financial, legal, or professional advice. While every effort is made to ensure accuracy, Klipy UK Limited accepts no liability for decisions made based on this content. Payment processing rates, regulations, and product features referenced are subject to change. Klipy UK is an authorised seller of Teya payment solutions. Where third-party sources are cited, links are provided for reference; Klipy UK does not endorse or guarantee the accuracy of external content. For personalised guidance on your business payment needs, please contact us directly at editor@klipy.uk.

Found this helpful? Share with your network:

This content is published by Klipy UK, a Teya-authorised reseller of payment solutions. The views expressed are for informational purposes only and do not constitute financial advice. All content is the intellectual property of Klipy UK. Reproduction without permission is prohibited.

Ready to Compare Your Rates?

See exactly how much you could save. Upload your statement or enter your monthly turnover-instant results, no obligation.

Try Calculator