PCI-DSS

PCI DSS compliance support for UK merchants and service providers. Scoping, SAQ guidance, remediation and annual revalidation against v4.0.1.

Service Details

PCI DSS compliance means your card payments are handled securely enough to keep your acquiring bank, your customers and the card brands satisfied, and we get you there with clear scoping, practical remediation and evidence ready for assessment. You find out exactly which systems are in scope, which assessment you need, and what to fix first.

The Payment Card Industry Data Security Standard (PCI DSS) protects cardholder data wherever it is stored, processed or transmitted. The current version is v4.0.1, and every requirement in it is now mandatory. This page sits within our governance services, alongside the other frameworks and regulations we help you meet.

INFO

If you take card payments or handle them for others, PCI DSS is a condition of your contract with your acquiring bank, not an optional standard.


Who PCI DSS applies to

PCI DSS applies to any business that stores, processes or transmits card data, or whose systems can affect how that data is protected. The less card data touches your systems, the smaller your scope and the lighter your assessment.

PCI DSS applies if you store, process or transmit

Cardholder Data

  • Primary account numbers (PAN)
  • Cardholder names
  • Expiry dates and service codes

Sensitive Authentication Data

  • PINs and PIN blocks
  • Card validation codes (CAV2, CVC2, CVV2, CID)
  • Full magnetic stripe or chip data

Sensitive authentication data must never be stored after a payment is authorised, even if it is encrypted. Finding where it has crept into logs, call recordings or spreadsheets is often the first quick win.

Does your business need PCI DSS?

You need PCI DSS if you are a:

Merchant

You sell goods or services and accept card payments, online, by phone or in person.

Service Provider

You store, process or transmit cardholder data for another organisation, for example through hosting, a payment gateway or managed services.

Or Both

You accept card payments and provide services that handle card data for other organisations.

A smiling bearded man holding a camera in a modern office with colleagues in the foreground

What PCI DSS requires

PCI DSS v4.0.1 has 12 requirements grouped under six goals. In plain English, you need to:

  1. Build and maintain a secure network — Control traffic into and out of the card environment, and replace default settings and passwords with secure configurations (requirements 1 and 2).
  2. Protect account data — Keep stored card data to a minimum and protect it, and encrypt card data sent over public networks (requirements 3 and 4).
  3. Manage vulnerabilities — Protect systems from malware and build and patch software securely, including scripts on payment pages (requirements 5 and 6).
  4. Control access — Limit access to people who need it, give everyone a unique login with multi-factor authentication, and restrict physical access (requirements 7, 8 and 9).
  5. Monitor and test — Log and review access to card data, and test regularly through vulnerability scans and penetration tests (requirements 10 and 11).
  6. Keep a security policy — Run an information security programme with policies, risk analyses, staff training and supplier oversight (requirement 12).

Version 4.0 also lets you meet some requirements through a customised approach, where you design your own control and prove it achieves the stated objective. It suits mature organisations with strong evidence; most businesses are better served by the defined approach.


How we help you comply

Scoping and Gap Analysis

We map where card data flows, confirm which SAQ or ROC applies, and measure your controls against all 12 requirements.

Remediation Roadmap

You get a prioritised plan, from network segmentation and outsourced payment pages that shrink scope to the policies that sustain compliance.

Hands-on Remediation

Our engineers deliver the fixes across encryption, access control, logging and testing, rather than leaving you with a report.

Evidence and Revalidation

We keep evidence current and support annual revalidation and quarterly scanning, so each cycle takes less effort than the last.


Why PCI DSS protects the business

PCI DSS is about more than securing payment systems. It protects your ability to trade, your relationship with your bank and the trust of your customers.

Avoid Fines

Non-compliance can bring fines passed on by your acquirer and higher transaction fees until you fix the gaps

Keep Taking Cards

A serious breach can cost you your card processing facilities, and the revenue that depends on them

Protect Customer Trust

Card theft is the breach customers remember. Compliance keeps their data, and their loyalty, intact


PCI DSS controls overlap heavily with other standards, so evidence you build once can count several times. ISO 27001, the CIS Controls and Cyber Essentials share much of the same ground, and card data is also personal data under UK GDPR. Payment and fintech firms may also face DORA, NIS2 and FCA obligations; our framework guide compares them, and our end-to-end compliance programme brings them together.

Requirement 11 calls for regular penetration testing, and our risk management work covers the targeted risk analyses v4.0 introduced. Identity and access handles multi-factor authentication and least-privilege access, a security posture review gives you a wider baseline, and compliance support keeps your evidence ready for assessment.

We support PCI DSS programmes for retail, financial services, insurance and not-for-profit organisations that take donations by card.


Frequently asked questions

Shrink your PCI DSS scope

Tell us how you take card payments and who handles the data. You get a clear view of your scope, the assessment you need and the gaps to close first.