Loading...
This PCI Compliance Checklist for UK Merchants provides a comprehensive yet simplified guide to help businesses understand and implement the requirements of the Payment Card Industry Data Security Standard (PCI DSS). Designed for both new and established merchants, it covers everything from determining your merchant level and selecting the appropriate Self-Assessment Questionnaire (SAQ), to securing cardholder data, maintaining system security, and ensuring compliance with UK-specific regulations such as GDPR and, where applicable, Financial Conduct Authority (FCA) rules. The checklist is structured into clear categories with actionable steps, making it an essential tool for businesses seeking to protect payment data, meet regulatory obligations, and avoid costly security breaches or fines.
If you are a new business, estimate how many card transactions you expect to process in a year.
Discuss your estimated volume to confirm your PCI merchant level.
Do you use physical terminals, virtual terminals, or an e-commerce website?
Classify your PCI level
Answer all questions honestly. Keep evidence and documentation.
Use firewalls to separate trusted and untrusted networks.
Replace default logins on all devices and software.
Use WPA2 or better. Rename SSID and set a strong passphrase.
Don't store CVV, PIN, or full magnetic stripe data after payment.
If storing card data is necessary, use strong encryption like AES.
Use TLS/SSL (e.g., HTTPS) when transmitting cardholder data.
Only authorised personnel should access card data.
No shared logins — use named accounts for traceability.
Required for remote or admin access to systems.
Install and regularly update across all devices.
Keep systems, apps, and plugins updated as soon as patches are available.
Write a plan for responding to data breaches. Test it regularly.
Keep detailed logs of access to cardholder data.
Use an Approved Scanning Vendor (ASV).
Simulate attacks to identify weaknesses.
Outline data security responsibilities. Review annually.
Teach staff about PCI DSS, data safety, and how to spot threats.
Handle customer data under UK GDPR rules, including lawful processing and breach reporting.
Ensure hosting providers, payment gateways, and software vendors are compliant.
Keep documentation showing each provider’s compliance.
Submit annually to your acquiring bank.
Level 1 merchants must use a Qualified Security Assessor to submit a Report on Compliance (ROC).
Secure personal data and report any serious data breaches to the Information Commissioner's Office (ICO) within 72 hours.
Financial services must comply with FCA expectations on operational resilience and third-party risk.