Zahl
Find a provider About Blog Terms
← Back to blog
Compliance

PCI DSS for small businesses: what you actually have to do

Almost every business that takes card payments has some level of PCI obligation. Most of the time, it's smaller than it sounds.

PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements created by the card networks, covering any business that stores, processes or transmits card data. It applies whether you're a sole trader with a mobile card reader or a national retailer — what changes is the level of proof required, not whether it applies at all.

Why it applies to you even with a simple card reader

Even if you never see or store a card number — because your reader or gateway handles it directly — you're still in scope for PCI DSS, because your business is part of the payment chain. The good news is that most small businesses fall into the lowest compliance tier, with by far the lightest requirements.

The four merchant levels, roughly

LevelAnnual card transactionsWhat's typically required
4Under ~6 million (most small/medium businesses)Self-Assessment Questionnaire (SAQ)
320,000–1 million ecommerce transactionsSAQ plus quarterly network scans
21–6 million transactionsSAQ or external audit, plus scans
1Over 6 million, or after a breachFull annual external audit (QSA)

The overwhelming majority of small and medium UK businesses sit in Level 4, meaning a self-assessment questionnaire rather than an external audit — and many card machine and gateway providers include this as part of their service, sometimes for a small monthly fee, sometimes bundled in for free.

What a Level 4 business actually needs to do

The simplest way to shrink your PCI scope is to never touch card data directly. Using a hosted checkout, card reader, or payment link — rather than building a custom card form — pushes most of the compliance burden onto your provider.

What happens if you don't comply

Non-compliance itself doesn't typically trigger an automatic fine, but it does two things: it can invalidate certain protections if a breach happens, and providers can charge a non-compliance fee (often £15–£30 a month) until your SAQ is completed. If a data breach does occur while non-compliant, the costs — investigation, fines, and liability for fraudulent transactions — can be substantial.

Practical checklist for most small businesses

  1. Confirm with your provider which SAQ type applies to how you take payments
  2. Complete it annually — most providers send a reminder and a link to their own portal
  3. Never email, text or write down full card numbers, even "just to be helpful" to a customer
  4. Keep till software, apps and firmware updated rather than running old versions indefinitely
  5. If you run your own website checkout, use your gateway's hosted fields or checkout page rather than a custom-built card form
This is general information, not compliance or legal advice. PCI DSS requirements depend on exactly how your business takes and stores payments — confirm your specific obligations with your acquirer or a qualified adviser.
Most providers handle this differentlyCompare card machines and gateways, including what compliance support is included.
Open the compare tool