How to Get a PCI Compliance Quote in the UK (and What It Should Cost)
PCI compliance quotes in the UK range from free portals to four-figure consultancy for the same outcome. Here is what a quote should include, the red flags to avoid, and the questions that reveal the true annual cost.
Search for a PCI compliance quote in the UK and you will meet prices from 'free' to several thousand pounds a year — often for exactly the same deliverable: a completed Self-Assessment Questionnaire filed with your acquirer. The spread is not because the work varies that much for a typical small business; it is because pricing in this market rewards confusion. This guide explains what a quote should include, what it should actually cost, the red flags that signal you are about to overpay, and how to switch if you already are. If you want the background on the standard itself first, start with our complete PCI DSS compliance guide.
What should a PCI compliance quote include?
A proper quote is for an outcome — you, validated as compliant with your acquirer — not for access to a portal. Before comparing prices, check each quote covers:
- Scoping: working out which SAQ actually applies to your business, rather than defaulting you onto the biggest one.
- Help completing the questionnaire — a person who answers questions, not just software that displays them.
- Vulnerability scans included in the price if, and only if, your SAQ type requires them.
- The signed Attestation of Compliance at the end.
- Filing the results with your acquirer, so your status actually changes and any fees stop.
- Renewal management, because validation lapses every twelve months.
- One total annual figure, with VAT stated, and the renewal price confirmed in writing.
If any of those are missing, vague, or 'available as an add-on', the headline price is not the real price.
How much should PCI compliance cost in the UK?
For a typical small UK merchant — a shop with a card machine, a café, a small online store — the realistic market looks like this. Doing it yourself through your acquirer's portal is nominally free, but budget your own time: understanding SAQs, gathering evidence and completing the form can easily absorb five hours, and five hours of an owner's time at even £25 an hour is £125 of effort — more if you pick the wrong SAQ and have to start again. Acquirer compliance programmes usually charge a few pounds a month whether or not you complete anything. Independent managed services commonly sit between £100 and £300 a year. Complex businesses that store card data or need the full SAQ D can genuinely face four figures, because the assessment work is real.
Fraud Defence First charges a flat £100 + VAT a year for its fully managed PCI compliance service — scoping, completion, attestation, filing and renewal, whichever SAQ applies. For a fuller breakdown of the market numbers, see how much PCI compliance costs in the UK.
What information should you have ready when you ask?
Quotes are only as accurate as the information behind them, and a provider who quotes a firm price without asking any of the following is guessing. Have to hand: how you take payments (card machine, online checkout, over the phone, or a mix); the names of your payment providers — the terminal supplier, gateway or e-commerce platform; who your acquirer is (the company that pays your card takings into the bank, named on your merchant statement); a rough idea of your card turnover; and whether you have validated compliance before. Five minutes with a recent merchant statement usually answers all of it.
That same statement is worth reading closely anyway. If it already shows a monthly PCI, compliance or non-compliance charge, you are effectively paying for a service you are not receiving — which strengthens your position when you ask any provider, including your current one, to justify their price.
What are the red flags in a PCI quote?
- Per-SAQ pricing that climbs. A teaser price 'for SAQ A' that doubles when you 'turn out' to need something bigger. Scoping should come first, not after you have signed.
- Scan bundles you do not need. Quarterly ASV scans are required for some setups (SAQ A-EP, B-IP, C and D among them) but not for standard SAQ A or SAQ B merchants. Paying for scans your SAQ does not ask for is pure margin.
- Long contracts. Twenty-four or thirty-six month terms with auto-renewal, for a task that repeats annually anyway.
- Setup or 'onboarding' fees stacked on top of the annual price.
- First-year discounts with the renewal price left unstated.
- 'From £X' pricing with no fixed total for your actual setup.
- A monthly 'management' or 'admin' fee charged alongside the service — which quietly turns £8 a month into £96 a year.
None of these is illegal, and some providers using them are otherwise competent. But each one exists to make the true annual cost harder to see, and the fix is always the same: insist on one all-in annual figure, in writing, before you commit.
Why do acquirer compliance programmes cost more than they look?
When you signed your card processing agreement, your acquirer almost certainly enrolled you in its own compliance programme. These are convenient — the portal is pre-linked to your merchant account — but they are typically built as two charges, not one. First, a monthly programme or management fee for access to the portal. Second, a separate monthly non-compliance fee, typically £5 to £25, that applies until you complete the validation yourself. And the programme rarely includes anyone actually doing the work with you: it is a portal and a helpline, not a service.
Put numbers on it: a £4.95 monthly programme fee plus a £14.95 monthly non-compliance fee is £19.90 a month — £238.80 a year — while a fully managed independent service that actually gets you validated costs £120 including VAT. If there is a PCI-related line on your statement you do not understand, our guide to the PCI compliance fee explained shows what each charge means and whether it should still be there.
What questions should you ask a provider before accepting a quote?
- What is the total annual cost including VAT — and is the renewal price the same?
- Which SAQ do you think applies to my business, and how did you decide?
- Are vulnerability scans included if my SAQ requires them?
- Who completes the questionnaire — your team with me, or me on my own?
- Do you file the results with my acquirer and confirm the non-compliance fee has stopped?
- What is the contract length and the notice period?
- What happens to the price if my payment setup — and therefore my SAQ type — changes mid-year?
A good provider answers all seven in one email without hedging. Evasion on any of them — especially the renewal price and the contract length — tells you what the second year will feel like.
How do you switch PCI compliance provider?
You are not obliged to use your acquirer's programme, or to stay with your current provider. Acquirers accept a valid SAQ and Attestation of Compliance regardless of who helped you produce it. Switching looks like this: check your current contract for notice terms; have the new provider scope and complete your SAQ; file it with your acquirer (a managed provider does this for you); confirm your portal status shows compliant and any non-compliance fee has stopped; and keep copies of the SAQ and AoC. The natural moment to move is your annual renewal — but if you are currently paying monthly non-compliance fees, every month you wait has a price on it.
The bottom line
A PCI compliance quote for a typical small UK business should be one fixed annual figure, roughly in the £100-to-£300 range, covering scoping, completion, attestation and filing — with scans included only when your SAQ demands them. Anything structured around monthly drips, per-SAQ surprises or multi-year lock-ins deserves a hard look at the total. Get two or three quotes, ask the seven questions above, and compare the all-in annual cost of actually being validated — not the headline. If you have more questions before getting in touch, our FAQ covers the ones we hear most often.
Related Guides
PCI DSS Compliance in Devon & Plymouth: Local Help for £100 + VAT
Fraud Defence First is a Plymouth-based PCI DSS compliance team helping shops, cafés, trades and online businesses across Devon get compliant fast — and stop paying acquirer non-compliance fees.
Read ArticlePCI Compliance for E-commerce & Online Stores (UK)
Selling online means card data is in play even if you never see it. Here's how PCI DSS applies to UK e-commerce, which SAQ you need, and how to keep it simple.
Read ArticlePCI Compliance for Small UK Businesses: A Practical Guide
PCI DSS applies to the smallest shops, cafés and sole traders too — but the path to compliance is short. Here is the minimum a small UK business actually needs to do.
Read Article