Skip to main content
Compliance Requirements

'My Provider Handles PCI for Me' — What Your Acquirer Actually Does (and Doesn't)

Your payment provider secures its systems — but PCI validation, your premises and your staff stay your responsibility. Here is where the line really sits, and how to stop paying for the misunderstanding.

Fraud Defence First
14 July 2026
6 min read

Ask a room full of small-business owners about PCI DSS and someone will say it within a minute: 'my card machine provider handles all that for me.' It may be the most expensive misunderstanding in card payments — not because providers are dishonest, but because 'handling PCI' means something much narrower than most owners assume. This article sets out exactly what your payment provider and acquirer do for you, what remains yours, why you are charged a fee and still expected to fill in forms, and how to close the gap for good.

Where does 'my provider handles it' come from?

Usually from a perfectly true sentence heard in a sales conversation. When a provider says its terminal or payment gateway is 'fully PCI compliant', it is telling the truth — about itself. Payment companies are assessed as service providers, typically at the most demanding level, with independent audits far stricter than anything asked of a small merchant. But that certifies their systems, not your business. Your obligation to validate compliance sits in your merchant agreement, in your name, and no supplier's certificate transfers it.

What does your payment provider actually handle?

A good provider genuinely takes on the heaviest parts of card security:

  • Secure processing infrastructure — the gateways, networks and data centres your transactions travel through.
  • PCI-approved hardware — terminals that encrypt card data at the moment of capture, so readable numbers never sit on your premises.
  • Hosted payment pages — online checkouts that keep card details off your website entirely.
  • Their own PCI DSS validation as a service provider — maintained continuously and audited independently.

This work matters, and it is why the right payment setup makes your own compliance dramatically easier: a standalone encrypted terminal or a fully hosted checkout can reduce your annual validation to one of the shortest questionnaires. What it cannot do is make the obligation disappear.

The same is true online. 'Our gateway is fully PCI compliant' is a statement about the gateway, not about your shop. Even with a fully hosted checkout — the lightest possible setup, where card details go straight from your customer's browser to the provider — you are still expected to complete the short SAQ A each year, confirm you are not storing card data anywhere else, and keep the parts of your site that hand over to the checkout secure. A small job, certainly. But it is your job, not theirs.

So what stays your responsibility?

  • Annual validation — completing the correct Self-Assessment Questionnaire (SAQ) and filing it with your acquirer, every year.
  • Your environment — the premises, tills, computers and Wi-Fi that surround the payment process.
  • Your people — what staff actually do with card numbers on the phone and at the counter.
  • Your habits — no card numbers in notebooks, emails, spreadsheets or customer-notes fields, however convenient.
  • Your suppliers — knowing which third parties touch card data on your behalf and confirming they are compliant.

PCI DSS treats this as shared responsibility: the provider secures the pipe, and you secure everything around the mouth of it — then you sign your name to that fact annually. The questionnaire exists precisely because encrypted terminals cannot stop a member of staff writing a card number on a notepad. If the terminology here is unfamiliar, our explainer what is PCI DSS compliance? covers the basics in plain English.

Why does my acquirer charge a PCI fee and still expect me to self-assess?

It feels back-to-front: a monthly 'PCI programme' or 'compliance management' charge on your statement, and yet the questionnaire is still yours to complete. The explanation is that the fee pays for the programme around your compliance — the online portal, the reminder emails, the scan tooling — not for anyone doing the assessment for you. And if you do not validate, most acquirers add a separate non-compliance fee, typically £5 to £25 a month, on top of the programme charge. We break down both lines on your statement in the PCI compliance fee explained.

Here is how the misunderstanding compounds, in pounds. A gift shop signs up for a card terminal and assumes compliance is included. Its acquirer charges £4.95 a month for the compliance programme and, once the validation deadline quietly passes, adds a £19.95 monthly non-compliance fee. Over two years that is £597.60 — paid by an owner who believed the paperwork was being done for them. Validating properly from day one would have cost the programme fee and one afternoon; a fully managed service would have cost £100 + VAT a year and no afternoons at all.

How do acquirer 'compliance programme' portals work?

Most acquirers run a branded compliance portal, often operated by a specialist security firm on their behalf. You receive a login by email or letter, answer profiling questions about how you take payments, get routed to the SAQ the profile suggests, complete it, and — if your setup requires it — schedule quarterly vulnerability scans. Deadlines are enforced by the non-compliance fee rather than by anyone helpfully chasing you.

The portals work, but they fail in predictable ways: the invitation email lands in spam or goes to someone who left the business; the profiling questions are answered wrongly, routing you into a far longer questionnaire than your setup requires; or a scan fails and the technical report explaining why goes unread. Each failure ends the same way — 'non-compliant' on the acquirer's records and a fee on your statement, sometimes for years.

One more wrinkle worth knowing: compliance does not follow you between providers. If you switch acquirer to save on transaction fees, your validated status does not transfer — the new acquirer runs its own programme, issues its own portal login and sets its own deadline. Businesses often discover this months after switching, when the first non-compliance fee appears on an otherwise cheaper statement. Whenever you change provider, put 'revalidate PCI' on the same checklist as swapping the card machine and updating the till.

What should you ask your provider?

Five questions will establish exactly where the line sits on your account:

  • Which SAQ does my setup qualify for, and why?
  • Am I required to run quarterly vulnerability scans?
  • What does your PCI programme fee actually pay for — and does anyone complete the assessment with me?
  • Am I currently recorded as compliant, and when is my next validation due?
  • Is there a non-compliance fee on my account right now?

The last two questions are the ones that find money. A surprising number of businesses discover they have been paying a monthly penalty for years — not because compliance was hard, but because nobody knew the question needed asking.

How does a managed service close the gap?

A managed compliance service does precisely the part your provider leaves with you: mapping how card data flows through your business, choosing the correct SAQ, completing it with you, managing any scans, and filing the result with your acquirer so the portal shows green. Fraud Defence First's fully managed service does all of this for a flat £100 + VAT a year — usually less than five months of a typical non-compliance fee — and keeps you validated year after year. For the full picture of how the standard and the process fit together, see the complete PCI DSS compliance guide.

The bottom line

'My provider handles PCI for me' is true of the plumbing and false of the paperwork. Your provider secures the infrastructure; you validate, every year, that your side of the arrangement — your premises, your people, your habits — holds up. The businesses that get caught out are not the careless ones; they are the ones who never knew where the line was. Now you do, and closing the gap costs less than the fee for leaving it open.

Need Expert PCI Compliance Help?

Our PCI compliance specialists are here to guide your business through the certification process. Get personalised advice and ensure your business stays compliant.

14/07/2026
6 min

Why Your Card Machine Provider Charges a PCI Fee — and How to Stop It

That PCI charge on your card machine statement is usually two different fees in disguise — and the larger one can normally be removed. Here is why providers charge it and how to stop paying.

Read Article
14/07/2026
6 min

SAQ A vs SAQ A-EP: What's the Difference and Which Do You Need?

SAQ A and SAQ A-EP sound alike but are worlds apart: around 30 questions against roughly 190, decided entirely by how your checkout is built. Here is how to tell which one your website needs — and how to move to the simpler one.

Read Article
14/07/2026
7 min

How to Complete SAQ A: Step-by-Step for UK Businesses (2026)

SAQ A is the shortest route to PCI compliance — around 30 questions for businesses whose card handling is fully outsourced. Here is who qualifies under v4.0.1, what the form contains, the evidence to gather, and how to file it without the common mistakes.

Read Article