← Back to blog
Compliance
PCI DSS for small businesses: what you actually have to do
Almost every business that takes card payments has some level of PCI obligation. Most of the time, it's smaller than it sounds.
6 min readCompliance
PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements created by the card networks, covering any business that stores, processes or transmits card data. It applies whether you're a sole trader with a mobile card reader or a national retailer — what changes is the level of proof required, not whether it applies at all.
Why it applies to you even with a simple card reader
Even if you never see or store a card number — because your reader or gateway handles it directly — you're still in scope for PCI DSS, because your business is part of the payment chain. The good news is that most small businesses fall into the lowest compliance tier, with by far the lightest requirements.
The four merchant levels, roughly
| Level | Annual card transactions | What's typically required |
| 4 | Under ~6 million (most small/medium businesses) | Self-Assessment Questionnaire (SAQ) |
| 3 | 20,000–1 million ecommerce transactions | SAQ plus quarterly network scans |
| 2 | 1–6 million transactions | SAQ or external audit, plus scans |
| 1 | Over 6 million, or after a breach | Full annual external audit (QSA) |
The overwhelming majority of small and medium UK businesses sit in Level 4, meaning a self-assessment questionnaire rather than an external audit — and many card machine and gateway providers include this as part of their service, sometimes for a small monthly fee, sometimes bundled in for free.
What a Level 4 business actually needs to do
- Complete the relevant Self-Assessment Questionnaire annually (your provider will usually tell you which SAQ type applies, based on how you take payments)
- Never store full card numbers, PINs or security codes on your own systems, paper, or unsecured spreadsheets
- Keep the software on any till, terminal or website up to date, with default passwords changed
- Use a PCI-compliant provider for any online checkout, rather than building your own card form from scratch
- Run quarterly vulnerability scans if you store any cardholder data on your own network (most small businesses using a third-party reader or gateway don't)
The simplest way to shrink your PCI scope is to never touch card data directly. Using a hosted checkout, card reader, or payment link — rather than building a custom card form — pushes most of the compliance burden onto your provider.
What happens if you don't comply
Non-compliance itself doesn't typically trigger an automatic fine, but it does two things: it can invalidate certain protections if a breach happens, and providers can charge a non-compliance fee (often £15–£30 a month) until your SAQ is completed. If a data breach does occur while non-compliant, the costs — investigation, fines, and liability for fraudulent transactions — can be substantial.
Practical checklist for most small businesses
- Confirm with your provider which SAQ type applies to how you take payments
- Complete it annually — most providers send a reminder and a link to their own portal
- Never email, text or write down full card numbers, even "just to be helpful" to a customer
- Keep till software, apps and firmware updated rather than running old versions indefinitely
- If you run your own website checkout, use your gateway's hosted fields or checkout page rather than a custom-built card form
This is general information, not compliance or legal advice. PCI DSS requirements depend on exactly how your business takes and stores payments — confirm your specific obligations with your acquirer or a qualified adviser.
Most providers handle this differentlyCompare card machines and gateways, including what compliance support is included.
Open the compare tool