Written by Richard Sutherland Reviewed by Vatsal Bhandari Updated on 3 June 2026 On this page What Is PCI Compliance? What Is PCI DSS 4.0.1? Who Does PCI Compliance Apply To? What Are the 12 Standards of PCI Compliance? PCI Compliance Levels What Are the Consequences of Non-Compliance? Tips for Maintaining PCI Compliance Verdict Expand PCI compliance is a mandatory set of 12 security standards required for any UK business accepting payments by card reader, online or by phone. Before you can swipe, dip, or tap a customer’s card, you need to ensure your business has security measures in place to prevent card information from being stolen or misused.The process of adopting these security measures is known as Payment Card Industry (PCI) compliance and it’s absolutely essential for every business that accepts card payments. Failure to achieve PCI compliance can result in severe penalties from your merchant account provider and leave your business exposed to data theft.In this guide, we’ll explain what PCI compliance involves, including the costs, consequences and tips to ensure your business is fully compliant. PCI Compliance Guide: Key Takeaways PCI compliance involves meeting a set of 12 security standards to protect customers’ card data from theft. If your business accepts card payments in person, online or over the phone, PCI compliance is mandatory.Businesses fall into one of four PCI compliance levels, namely Level 1 to Level 4, depending on their card transaction volume. Each level has its own requirements for validating PCI compliance.PCI compliance costs vary from a few hundred pounds to £40,000 per year, depending on the size of your business and your validation requirements.Failure to comply with PCI requirements can result in steep penalties and leave your business vulnerable to costly data breaches. What Is PCI Compliance?PCI compliance refers to a set of 12 security standards that businesses must adopt in order to accept payments. They’re designed to protect customers’ card information against hacks and data breaches.PCI compliance standards, also known as Payment Card Industry Data Security Standard (PCI DSS), are written by the PCI Security Standards Council, an organisation created in 2006 by Visa, Mastercard, American Express, Discover and JCB. The standards are enforced by merchant account providers. What Is PCI DSS 4.0.1?PCI DSS version 4.0.1 is the current standard for securing payment card data, and any organisation that stores, processes, or transmits cardholder data should now align its controls with this version.On 31 March 2025, 51 requirements that were previously treated as best practice became mandatory for applicable companies, including:Expanded multi-factor authentication (MFA): MFA is now generally required for access to the Cardholder Data Environment (CDE), not just for remote access or privileged administrators.Stronger password rules: Where systems support it, the minimum password length is now 12 characters, with an eight-character minimum permitted only where longer passwords are not technically feasible.Automated web protection: Public-facing web applications, such as ecommerce checkout pages, generally must have automated firewall protections rather than relying solely on periodic manual reviews.Script monitoring and control: To reduce the risk of “digital skimming” attacks, ecommerce merchants must authorise and monitor scripts executing on payment pages, ensuring only trusted scripts can run.Essentially, the latest version of the standard tightened security requirements for businesses that handle card data. Who Does PCI Compliance Apply To?PCI compliance is required for all businesses that accept card payments in any form. Compliance applies if you:Take card payments in person using a card reader or point of sale systemTake card payments online using a payment gatewayTake card payments over the phone using a virtual terminalEven if your business only processes a few card transactions per month, you must still be PCI compliant. PCI compliance is also required regardless of whether you store customers’ card information. What Are the 12 Standards of PCI Compliance?PCI compliance is built on 12 core security requirements that cover how businesses protect cardholder data through strong network security, access control, encryption, monitoring and regular testing. Together, these standards ensure payment systems are secured against internal misuse and external cyber threats.To be PCI compliant, your card payment system must meet the following 12 requirements:Use firewalls: You must use a firewall on your corporate computer network. A firewall prevents unauthorised access to your network and serves as the first line of defence against the theft of customers’ card data.Use strong passwords: You must not use the default password for software or equipment used to process card payments, such as routers, modems and point-of-sale systems. In addition to changing the default passwords, you must maintain a list of all devices and software that rely on passwords for security.Protect stored card data: Your business should only store essential cardholder data needed to process recurring transactions. Furthermore, any card data you store must be protected using a combination of encryption and you must have a plan for the safe disposal of data that is no longer needed.Encrypt card data during transmission: When sending card data over public networks — such as sharing card information between devices — that data must be encrypted. Never send unencrypted card data by email, text or messaging app.Use malware controls: You must use antivirus software on any devices that store customers’ card information and run periodic malware scans.Maintain secure systems: You must have processes in place to identify and address software vulnerabilities. This could include installing updates, running antivirus scans and requiring new passwords every few months.Restrict access to cardholder data: Cardholder data should only be accessible to employees who need to view it for a specific purpose. You can assign varying levels of permissions to different users, and you must document who in your business has access to cardholder information.Create a unique ID for each employee: Employees with access to a computer that stores card information (including your point-of-sale system) must have a unique login ID. You can’t use a single user ID and password that multiple employees share.Restrict physical access to devices: Devices that store cardholder data should be kept in secure locations, such as in a locked room or drawer. Consider using security systems like CCTV. You should also keep a log of access to physical storage devices such as hard drives.Monitor access to cardholder data: You are required to use audit logs to track when cardholder information is accessed and by whom within your organisation.Perform regular vulnerability tests: Update your device and password inventory, perform vulnerability scans and test wireless access points at least once per quarter.Document your security policies: You must have written documentation of your company’s security practices and policies for PCI compliance. PCI Levels, Costs and RequirementsPCI compliance levels are determined by your annual card transaction volume, with higher levels requiring more rigorous validation, security controls and external oversight. In general, smaller businesses can rely on self-assessments, while larger organisations must undergo formal audits and regular third-party security testing.LevelTransaction volume (Visa/Mastercard)Who it applies toKey requirementsAnnual cost (estimated)Level 1Over 6 millionLarge enterprises or breached merchantsAnnual external audit (ROC by QSA), quarterly ASV scans, Attestation of Compliance (AOC)£40,000+Level 21–6 millionEstablished mid-sized businessesAnnual SAQ, quarterly ASV scans, AOC submission£4,000–£30,000Level 320,000–1 million ecommerceGrowing online businessesAnnual SAQ, quarterly ASV scans£750–£3,500Level 4Under 20,000 ecommerce or up to 1 million totalSmall businesses and low-volume merchantsSAQ, occasional scans (depending on acquirer), AOC (often required by provider)£150–£375PCI compliance requirements scale with transaction volume and overall security risk, so larger businesses face stricter validation standards.Lower levels typically rely on self-assessment questionnaires (SAQs) and basic vulnerability scanning to confirm compliance, often managed through a merchant account provider.Mid to high-level merchants are required to complete more formal validation processes, including quarterly scans and documented compliance reporting.The highest level (Level 1) requires independent external audits (ROC by a Qualified Security Assessor), alongside ongoing security testing and certification.Small businesses in Level 4 may be able to lean on their merchant account provider to achieve PCI compliance at no additional cost — for example, Square and PayPal POS both offer free PCI compliance assistance with your merchant account. What Are the Consequences of Non-Compliance?Non-compliance with PCI standards can lead to fines of up to £100,000 per month, higher transaction fees or account termination, liability for fraud losses, costly forensic audits, legal action, and lasting reputational damage.Consequences of non-compliance can include:Hefty fines from payment processors and card networks: These can range from £5,000 to £100,000 per month, depending on the severity of the violation and how long it goes unresolved.Increased fees or the loss of your merchant account: Merchant account providers may raise your transaction fees to offset risk. They could also potentially terminate your account entirely, essentially halting your operations overnight.Liability for fraud losses and chargebacks: If a breach occurs, you may be held financially responsible for fraudulent transactions, customer refunds and chargeback fees.Mandatory forensic audits after a breach: After a suspected breach, you’ll likely be required to pay for a PCI forensic investigation. These audits are expensive, highly detailed and can disrupt day-to-day operations.Legal penalties and potential lawsuits: Data breaches often lead to regulatory scrutiny and legal action, including potential fines from authorities and lawsuits from affected customers or partners.Serious reputational damage leading to lost customer trust: Customers expect their payment data to be secure. A breach can damage your brand credibility and reduce customer retention.PCI non-compliance: A real-world exampleIn 2018, British Airways suffered a data breach that exposed the payment details of around 400,000 customers. The airline was later fined £20 million by the Information Commissioner’s Office for failing to adequately protect customer data and also faced major reputational damage and costs. Tips for Maintaining PCI ComplianceMaintaining PCI compliance is easiest when you combine support from your merchant account provider, strong internal cybersecurity practices, secure integrated payment systems and minimal storage of cardholder data.Here are a few specific actions you can take to make PCI compliance easier:Get PCI compliance through your merchant account: Choose a merchant account provider that offers help with PCI compliance. Even if there’s a monthly fee, it’s well worth ensuring your business is compliant and safe from costly penalties.Implement strong digital hygiene: It’s important to be diligent about your business’ cybersecurity. For example, always use strong passwords and require employees to change them frequently. Ensure software is up to date with the latest security patches. Educate employees about phishing and install monitoring software to detect unusual activity on your network.Use an end-to-end point-of-sale system: Using a point-of-sale system and card readers from a single hardware provider can make it easier to integrate equipment in a way that’s PCI-compliant. For example, hardware from a single provider is usually designed to keep data encrypted during transfer. If you mix and match different pieces of hardware and software to process payments, it’s a good idea to hire a PCI consultant to ensure your configuration is secure.Limit what data you store: Only store card data that’s essential for your business to operate smoothly. This can reduce the number of devices you need to manage for PCI compliance and your potential liability in the event of a data breach. Verdict: What is PCI Compliance? PCI compliance is mandatory for all businesses that process debit and credit cards. To maintain compliance, your business must meet 12 security standards designed to protect customers’ card data against data breaches.Businesses must verify compliance through quarterly network scans and annual evaluations, with requirements varying based on annual transaction volume. While PCI compliance carries some costs, it’s much cheaper than the penalties for non-compliance or dealing with a data breach.For more information on accepting credit and debit cards at your business, check out our complete guide to taking card payments. Written by: Richard Sutherland Richard has more than 20 years of experience in business operations, computer science and full-stack development roles. A graduate in Computer Science and former IT support manager at Samsung, Richard has taught coding courses and developed software for both private businesses and state organisations. A prolific author in B2B and B2C tech, Richard’s work has been published on sites such as TechRadar Pro, ITProPortal and Tom’s Guide. Reviewed by: Vatsal Bhandari Finance Expert Vatsal Bhandari is a Certified Anti-Money Laundering Specialist (CAMS) and a finance, legal, and research consultant with over five years of cross-border experience. He has a Masters of Business Administration from Imperial College Business School in London and an LLM (Master of Laws) in Banking & Finance Law from the University of Edinburghhttps://www.linkedin.com/in/vatsalbhandari/