If you take card payments, you have probably seen the letters “PCI DSS” on a statement or in an email from your payment provider — usually next to a request for money. It sounds like something only a bank or a big retailer needs to worry about. It isn’t. But here is the reassuring part: for most small businesses in the UK, PCI compliance is a short form you fill in once a year, not a mountain of technical work. This guide explains PCI DSS in plain English, tells you what you actually have to do, and shows you how to spot the sneaky non-compliance fee that some providers quietly add to your bill.
TL;DR
- PCI DSS is a set of card-industry security rules that protect your customers’ card details. It is not a UK law, but your card provider requires it.
- Nearly every business that takes card payments needs to be PCI compliant — even a one-person shop.
- For most small businesses, compliance means completing a Self-Assessment Questionnaire (SAQ) once a year. Often it takes under an hour.
- Modern card machines and hosted checkouts do most of the heavy lifting, because card data never really touches your systems.
- Watch for a “PCI non-compliance fee” — a monthly charge some providers add if you don’t complete your SAQ. It is avoidable.
What is PCI DSS, in plain English?
PCI DSS stands for Payment Card Industry Data Security Standard. Strip away the jargon and it is simply a rulebook. The card networks — Visa, Mastercard, Amex and the rest — got together and agreed a common set of security standards that any business handling card details should follow. The goal is straightforward: keep customers’ card numbers safe so they don’t get stolen and used by fraudsters.
It is worth being clear on one thing early, because it trips people up. PCI DSS is not a government law. No UK regulator will knock on your door about it. It is a contractual requirement — when you signed up to take card payments, you agreed to follow these rules as part of the deal. Your payment provider is the one that holds you to it.
Why does PCI compliance exist?
A stolen card number is money in a criminal’s pocket, and the damage spreads fast — the cardholder, their bank, and the business that leaked the data all pay a price. Before common standards existed, every shop and website handled card details in its own way, some of them alarmingly loose. PCI DSS set a baseline so a customer paying at a corner shop in Sunderland gets the same basic protection as someone shopping with a national chain.
For you as a small business owner, that baseline is quietly working in your favour. A data breach is expensive and reputation-wrecking. Following these rules is the cheapest insurance you will ever buy against being the business that lost a customer’s card details.
Do I need PCI compliance?
Short answer: almost certainly yes. If you accept card payments in any form — a card machine on the counter, a payment link, an online checkout, or a mobile reader at a market stall — PCI DSS applies to you. There is no minimum turnover that lets you off the hook. A sole trader taking a handful of card payments a week is covered by the same rulebook as everyone else.
The good news is that the size of your obligation scales with how you take payments and how much card data touches your business. This is where the different “levels” and questionnaires come in — and where most small businesses land in the easiest category.
What you actually have to DO
Here is the part that surprises people. For the vast majority of small businesses, staying compliant means completing a Self-Assessment Questionnaire — an SAQ — once a year. It is a set of yes/no questions about how you handle card payments and protect your systems. You fill it in yourself, usually through a portal your provider gives you, and you are done for another twelve months.
There are different versions of the SAQ depending on how you take payments. The one you get sent is matched to your setup, so you don’t need to work out which applies. A few common examples:
- SAQ A — for businesses that only take payments online and use a hosted checkout, where the card details go straight to the payment provider and never touch your website.
- SAQ B — for businesses using standalone card machines with no card data stored on a computer.
- SAQ A-EP or C — for more involved online setups where your systems play a bigger role in the payment.
The reason it is usually painless is that modern payment kit is built to keep card data away from you. When a customer taps a card on a proper terminal, the sensitive details are encrypted and sent straight to the bank. They never sit on your laptop or your till. That single design choice removes most of what would otherwise be a heavy technical burden. If you want a clear picture of how those terminals actually work, our plain-English explainer on PDQ machines is a good place to start.
Beyond the annual SAQ, the day-to-day habits that keep you compliant are mostly common sense: use strong, unique passwords, keep your devices and software updated, don’t write card numbers down on paper, and only use terminals from a reputable provider. None of it requires an IT department.
Quick tip: Never store a customer’s full card number, and never keep the three-digit security code (the CVV) after a payment — not on paper, not in a spreadsheet, not in an email. It is one of the fastest ways to fall out of compliance, and there is no situation where you need to.
The sneaky PCI non-compliance fee
Now for the bit that costs real money. Some payment providers charge a monthly “PCI non-compliance fee” — sometimes labelled as a PCI management or PCI service charge. Here is how it works: if you don’t complete your SAQ, the provider adds a fee to your bill, month after month, until you do. It can be anywhere from a few pounds to over £40 a month, and plenty of small business owners pay it for years without realising it is optional.
The frustrating thing is that the fee often appears not because you have done anything wrong, but because nobody told you an SAQ was waiting to be completed. The provider sends one email, it gets missed, and the charge starts ticking. It is worth checking your last few statements right now for any line mentioning PCI — if you spot one, completing your questionnaire will usually make it disappear.
A good provider makes the whole thing easy: a clear reminder when your SAQ is due, a simple portal to fill it in, and no penalty for a business that is genuinely trying to stay compliant. If your current provider is charging you a fee and giving you no help to avoid it, that tells you something about who is on your side.
How to stay compliant without the stress
Keeping on top of PCI compliance really comes down to a few simple habits:
- Complete your SAQ when it is due — put a yearly reminder in your calendar so it never lapses.
- Use encrypted terminals or a hosted online checkout so card data stays out of your systems.
- Keep your devices, apps and passwords secure and up to date.
- Never store full card numbers or security codes.
- Check your statements for any PCI non-compliance fee, and clear it by completing your questionnaire.
Do those things and PCI compliance stops being something to worry about. It becomes a five-minute admin task once a year. And once your payments are set up properly, the next thing worth understanding is the money side — when card takings actually land in your bank. We cover that in our guide to card settlement times and when you get paid.
Paying too much? Find out in minutes
If you are seeing a PCI fee on your bill — or you just want to know whether you are on a fair deal — it is worth a quick check. Use our free card payments comparison tool to see how your current rates and charges stack up, with no jargon and no pressure. A few minutes now could save you a fee you never needed to pay.
