What Is a PCI DSS Certificate — and Who Actually Issues One?
Searching for a PCI DSS certificate? Here is the surprise: there is no official one. What actually proves compliance is your SAQ and Attestation of Compliance — here is how it works.
Type 'PCI DSS certificate' into a search engine and you will find companies happy to sell you one, consultants promising 'certification', and suppliers proudly attaching PDF certificates to emails. Here is the awkward truth the payments industry rarely spells out: there is no official PCI DSS certificate. The PCI Security Standards Council does not issue one, the card schemes do not recognise one, and no framed document makes you compliant. What exists instead is a validation process — and once you understand it, you will know exactly what to ask for, what to ignore, and what it should all cost.
Is there an official PCI DSS certificate?
No. The PCI Security Standards Council — the body that maintains the standard — is explicit that it does not certify merchants, and that certificates are not recognised documents in the validation process. Compliance is demonstrated through defined assessment documents, none of which is called a certificate. Anyone can print a certificate; that is precisely why the industry does not rely on them.
This catches people out because 'certification' is how most other business standards work — think Cyber Essentials or ISO 27001, where an official certificate genuinely exists. PCI DSS took a different route: you assess, you attest, and you file the evidence with the party that holds you to the standard, usually your acquirer. Our PCI compliance guide walks through that whole process end to end.
What actually proves PCI compliance?
Three documents do the real work, plus scan reports where they apply:
- Self-Assessment Questionnaire (SAQ) — the completed questionnaire matching how you take payments. There are several types (A, A-EP, B, B-IP, C, C-VT and D), ranging from a few dozen questions to well over 200.
- Attestation of Compliance (AoC) — the short, signed document summarising your assessment and its result. When a bank, platform or business partner asks for your 'PCI certificate', the AoC is almost always what they actually need.
- Report on Compliance (RoC) — the full report from an on-site audit by a Qualified Security Assessor. Only required for Level 1 merchants — broadly, those processing over six million transactions a year.
- ASV scan reports — quarterly external vulnerability scans from an Approved Scanning Vendor, where your SAQ type requires them.
Which of these applies to you depends on your merchant level. The overwhelming majority of UK small businesses are Level 4 and validate with an SAQ and AoC — no auditor required. Our guide to PCI merchant levels explains where the lines fall.
Who can issue what?
For most businesses, the honest answer is: you issue it yourself. At Levels 2 to 4, an officer of the business signs the SAQ and AoC — self-assessment is the officially sanctioned route, not a shortcut. A Qualified Security Assessor (QSA) is a professional certified by the PCI Security Standards Council to perform formal audits; QSAs produce the RoC that Level 1 merchants need, and some larger organisations use them (or trained Internal Security Assessors) for extra assurance. Approved Scanning Vendors are separately accredited to run the external vulnerability scans.
A managed compliance service sits alongside this structure rather than replacing it: it prepares the assessment, checks the answers against how you actually take payments, arranges the scans and files the paperwork — with the attestation still made on behalf of your business, as the standard requires.
So what are the 'PCI certificates' companies wave around?
Mostly one of three things. First, completion certificates generated by acquirer compliance portals when you file your SAQ — genuine records dressed up as certificates, harmless but informal. Second, certificates auto-produced by compliance platforms and managed services as a customer-friendly summary of a real assessment. Third, pure marketing badges. None of these has official standing; their value rests entirely on the SAQ and AoC underneath. So the reliable habit is this: whenever a supplier shows you a certificate, ask to see the AoC behind it. A company that has genuinely validated can produce one; a company waving only a certificate may simply have bought a PDF.
If you need to check credentials rather than certificates, go to the source: the card schemes publish lists of validated service providers, and the PCI Security Standards Council publishes registers of QSAs and ASVs. Neither will ever list a 'certificate holder' — which tells you everything about how much weight certificates carry.
What does your acquirer actually need to see?
Your acquirer needs a current, valid compliance record: the right SAQ completed, the AoC signed, and passing scan reports where your setup requires them — refreshed every year. Most acquirers collect this through a compliance portal or programme, and while they charge non-compliance fees (typically £5–£25 a month) when it is missing, none of them will ask you for a 'certificate'. If a third party — a marketplace, a platform or a corporate client — asks for proof of PCI compliance, the AoC is the document to send them.
Does PCI validation expire?
Yes — and this is where certificate thinking genuinely misleads. An AoC is dated, and your validation runs for twelve months from the assessment; scan reports, where required, are never more than three months old. There is no permanent certified status to reach: you re-assess and re-attest every year, so an impressive-looking document dated two or three years ago is evidence of nothing. If a supplier sends you a certificate, check the date as well as asking for the AoC behind it. And diarise your own renewal, because acquirers reinstate non-compliance fees the moment a validation lapses — not when they get around to reminding you.
How much does PCI 'certification' actually cost?
Searches for 'PCI certification cost' usually expect a big number, and at the top end it exists: a Level 1 QSA audit is a serious engagement that typically runs to five-figure sums. But that applies to the largest merchants only. For a normal UK business the real costs look very different: self-assessing is free apart from your time — anything from an afternoon to several days, with the main risk being completing the wrong SAQ and starting again — while our fully managed PCI compliance service handles the whole process, produces your AoC evidence and files it with your acquirer for £100 + VAT a year. Our breakdown of PCI compliance costs in the UK compares the routes in detail.
One worked comparison makes the point. A shop paying £15 a month in non-compliance fees while hunting for a 'certificate' spends £180 a year on precisely nothing. Filing a correct SAQ and AoC — £120 including VAT through a managed service, or an afternoon of careful DIY — makes that charge stop and produces the exact evidence anyone could legitimately ask for. The certificate hunt is not just fruitless; it is usually the expensive option.
Key takeaways
- There is no official PCI DSS certificate — validation is via an SAQ and AoC, or a QSA-audited RoC at Level 1.
- The Attestation of Compliance is the document banks, acquirers and partners actually need.
- Most UK businesses can legitimately self-assess; only the very largest need an auditor.
- Certificates from portals and platforms are only as good as the assessment behind them — always ask for the AoC.
- A managed service produces and files your AoC evidence for £100 + VAT a year.
Related Guides
Do You Need PCI Compliance with Stripe, PayPal or Square? Yes — Here's What
Stripe, PayPal and Square make PCI compliance much easier — but they do not make it disappear. Here is what these providers actually handle, and what is still your job.
Read ArticlePCI DSS Compliance Checklist for UK Businesses (2026)
A practical, step-by-step PCI DSS checklist for UK businesses: find your merchant level, pick the right SAQ, secure your kit, brief your staff and file your Attestation of Compliance.
Read ArticleHow to Get a PCI Compliance Quote in the UK (and What It Should Cost)
PCI compliance quotes in the UK range from free portals to four-figure consultancy for the same outcome. Here is what a quote should include, the red flags to avoid, and the questions that reveal the true annual cost.
Read Article