Skip to main content
Getting Started

PCI DSS Compliance Checklist for UK Businesses (2026)

A practical, step-by-step PCI DSS checklist for UK businesses: find your merchant level, pick the right SAQ, secure your kit, brief your staff and file your Attestation of Compliance.

Fraud Defence First
14 July 2026
6 min read

Becoming PCI DSS compliant sounds like a technical mountain, but for most UK businesses it is a sequence of small, manageable steps — most of which you only need to think about once a year. This checklist walks through those steps in order, from working out your merchant level to filing your Attestation of Compliance, and reflects PCI DSS v4.0.1, the version of the standard currently in force. If PCI DSS is brand new to you, start with our plain-English explainer on what PCI DSS compliance is, then come back and work through the list.

Step 1: Do you know your merchant level?

The card schemes group merchants into four levels based on annual transaction volumes, and your level determines how you are allowed to validate compliance:

  • Level 1 — over six million card transactions a year: a full on-site audit by a Qualified Security Assessor, producing a Report on Compliance.
  • Level 2 — one to six million transactions: an annual Self-Assessment Questionnaire, sometimes with extra sign-off depending on the card scheme.
  • Level 3 — 20,000 to one million e-commerce transactions: an annual SAQ.
  • Level 4 — everyone else: an annual SAQ. This is where nearly every small UK business sits.

If you run a typical shop, café, trades business or small online store, you are almost certainly Level 4 and can self-assess. Our guide to PCI merchant levels explains where the boundaries fall and what each level must produce.

Step 2: Have you mapped how card data moves through your business?

Before you can answer a single questionnaire question, you need an honest picture of every route a card number can take into — and through — your business. Work through this list and write the answers down:

  • Do you take face-to-face payments on a countertop or portable card machine?
  • Do you sell online — and if so, does your checkout redirect to a provider's page, or are card fields embedded in your own site?
  • Do you take payments over the phone, typing the number into a terminal or virtual terminal?
  • Does anyone ever write card numbers down — on order forms, notepads or booking sheets?
  • Are card numbers ever emailed to you, stored in spreadsheets, or kept 'on file' anywhere?

The golden rule is to shrink your footprint. Every place card data touches your business adds questions to your assessment and risk to your year. If you do not genuinely need to store or handle card numbers, stop doing it — your compliance instantly becomes simpler and cheaper.

Step 3: Have you chosen the right SAQ?

There are several Self-Assessment Questionnaires — SAQ A, A-EP, B, B-IP, C, C-VT and D — and the right one follows directly from your answers in step 2. Getting this wrong is the most expensive mistake in the whole process: SAQ A is a short questionnaire of roughly 30 questions, while SAQ D runs to well over 200. Our SAQ A vs SAQ D comparison shows just how different the workloads are. As a rough guide:

  • SAQ A — fully outsourced card handling, such as a hosted payment page or full redirect.
  • SAQ A-EP — e-commerce where your own website's code affects how card data is captured.
  • SAQ B — standalone dial-out terminals; SAQ B-IP for standalone terminals connecting over the internet.
  • SAQ C-VT — virtual terminals used one transaction at a time; SAQ C for connected payment systems.
  • SAQ D — anyone who stores cardholder data electronically or does not fit a simpler profile.

Step 4: Is your equipment locked down?

Most of the practical security work for a small business comes down to a short list of habits:

  • Change every default password — on card terminals, routers, tills and any EPOS software. 'admin/admin' is still the classic way in.
  • Keep terminal firmware and till software updated; if your terminal is rented, confirm your provider pushes updates automatically.
  • Check card machines regularly for tampering — unexpected attachments, broken seals, swapped devices — and record serial numbers so a swap stands out.
  • Keep payment equipment off public Wi-Fi, and separate it from the network your customers use.
  • Restrict who can reach terminal admin menus and settings to the people who genuinely need to.

Step 5: Do your staff know the dos and don'ts?

Technology only covers half the standard. Day-to-day habits are the other half, and a five-minute briefing prevents most of the common failures:

  • Never write full card numbers down — not on notepads, delivery slips or booking forms.
  • Never ask a customer to email, text or WhatsApp their card details — and if one does it unprompted, delete the message and take payment another way.
  • Never store card numbers 'for later' unless you have a proper, compliant way to do it.
  • Only trained staff should process refunds or use terminal admin functions.
  • Everyone should know who to tell — immediately — if a terminal goes missing or looks tampered with.

Step 6: Do you need a vulnerability scan?

Some setups require quarterly external vulnerability scans by an Approved Scanning Vendor (ASV) — broadly, those where your systems face the internet as part of taking payments, such as e-commerce with card fields your site is involved in, or terminals communicating over IP in certain configurations. Fully outsourced checkouts and simple standalone terminals usually do not need them. Your SAQ type tells you the answer: if it includes the scan requirement, the scans must pass, four times a year, and the reports form part of your evidence.

Step 7: Have you filed your Attestation of Compliance?

Completing the questionnaire is not the finish line. You must sign the Attestation of Compliance (AoC) and file it with your acquirer or their compliance portal — this is the step that actually flips your status to 'compliant'. It is also the step people forget, and forgetting is expensive: non-compliance fees of £5–£25 a month keep being charged until the paperwork lands. A business that finished its SAQ in March but never filed it could quietly pay £180 or more over the following year for a form sitting in a drawer.

Step 8: Have you diarised your renewal?

PCI compliance is annual, and scans (where required) are quarterly. Set a reminder at least a month before your validation expires. Providers rarely chase you helpfully — the first sign of a lapsed validation is often the non-compliance fee reappearing on your statement. A recurring calendar entry costs nothing and stops you paying the penalty twice for the same oversight.

The full checklist at a glance

  • Confirm your merchant level (almost certainly Level 4).
  • Map every route card data takes through your business — and shrink it.
  • Choose the SAQ that matches your setup.
  • Secure your kit: default passwords changed, software updated, terminals checked.
  • Brief your staff on the dos and don'ts.
  • Run quarterly ASV scans if your SAQ requires them.
  • Sign and file your Attestation of Compliance with your acquirer.
  • Diarise your renewal a month before it falls due.

What if you would rather not do any of this yourself?

Everything above is doable in-house, and our complete PCI compliance guide expands on every step if you want to go deeper. But there is a fair question of time: a first-time SAQ, done carefully, can swallow an afternoon or more — considerably more if you pick the wrong questionnaire and have to start again. Our fully managed PCI compliance service handles the whole checklist for £100 + VAT a year: we identify the right SAQ, complete it with you in a short phone call, manage any scans, file the AoC and diarise your renewal so next year happens without you noticing. Compare that £120 all-in with £60–£300 a year in non-compliance charges for doing nothing, and the maths tends to make itself.

Need Expert PCI Compliance Help?

Our PCI compliance specialists are here to guide your business through the certification process. Get personalised advice and ensure your business stays compliant.

14/07/2026
6 min

How to Get a PCI Compliance Quote in the UK (and What It Should Cost)

PCI compliance quotes in the UK range from free portals to four-figure consultancy for the same outcome. Here is what a quote should include, the red flags to avoid, and the questions that reveal the true annual cost.

Read Article
14/07/2026
6 min

PCI DSS Compliance in Devon & Plymouth: Local Help for £100 + VAT

Fraud Defence First is a Plymouth-based PCI DSS compliance team helping shops, cafés, trades and online businesses across Devon get compliant fast — and stop paying acquirer non-compliance fees.

Read Article
27/06/2026
6 min

PCI Compliance for E-commerce & Online Stores (UK)

Selling online means card data is in play even if you never see it. Here's how PCI DSS applies to UK e-commerce, which SAQ you need, and how to keep it simple.

Read Article