Compliance

PCI DSS Compliance Support for UK Merchants

The cheapest PCI DSS project is the one where card data never touches your systems. We reduce your scope first, then evidence what remains.

STANDARD
PCI DSS v4.0
ROUTE
Self-Assessment Questionnaire (SAQ)
SET BY
Your Acquiring Bank
CADENCE
Annual, with Quarterly Scanning Where Required
In short

Which PCI DSS Self-Assessment Questionnaire do we need?

It depends on how you take payments. Merchants who fully outsource card capture to a hosted payment page typically use SAQ A, the shortest. Card-present merchants with standalone terminals often use SAQ B or B-IP. Your acquiring bank confirms which applies — always check with them before starting.

Follow the card data

PCI DSS applies to the systems that store, process or transmit cardholder data, and to anything connected to them. So the first task is always to establish where card data actually goes — which is frequently more places than the business believes. Card details read out over the phone and typed into a browser put that workstation in scope. A call recording system capturing card numbers puts the recording platform in scope.

Once the flow is mapped, most merchants can restructure to remove scope entirely: a hosted payment page for the website, pause-and-resume or DTMF suppression for telephone orders, and standalone terminals on a segregated connection in store. That is nearly always cheaper than securing and evidencing a large environment.

  • Map every route by which card data enters the business
  • Identify anything storing card data, including call recordings and email
  • Move to hosted payment pages so the website never touches card data
  • Suppress card data in call recording rather than storing and redacting it
  • Segregate card terminals from the general office network

What PCI DSS v4.0 changed

Version 4.0 brought stricter expectations that particularly affect e-commerce merchants. Payment pages must have their scripts inventoried, justified and monitored for unauthorised change, which is a direct response to digital skimming attacks. Multi-factor authentication requirements were extended, and password expectations strengthened.

The standard also introduced a customised approach, allowing organisations to meet a control objective differently where they can document and validate it. In practice that flexibility is aimed at larger organisations; small merchants are almost always better served by reducing scope than by engineering an alternative.

  • Script inventory, justification and integrity monitoring on payment pages
  • Expanded multi-factor authentication requirements
  • Strengthened password and authentication expectations
  • Documented, assigned roles and responsibilities for each requirement
What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Frequently asked questions

PCI DSS Compliance — your questions answered

Who decides whether we are PCI DSS compliant?
Your acquiring bank sets your validation requirements and receives your evidence. They confirm which Self-Assessment Questionnaire applies and whether quarterly external scanning is required, so they should be your first call.
Can we avoid PCI DSS by using Stripe, PayPal or Worldpay?
You cannot avoid it, but you can reduce it dramatically. Fully outsourcing card capture to a hosted payment page typically qualifies you for SAQ A, the shortest questionnaire, because card data never reaches your systems.
Do we need quarterly vulnerability scans?
It depends on your SAQ type. Merchants with internet-facing systems in the card data environment generally require quarterly external scanning by an Approved Scanning Vendor. SAQ A merchants typically do not. We confirm this against your specific SAQ.
What happens if we take card details over the phone?
The workstation and often the phone system come into scope, and any call recording that captures card numbers brings the recording platform in too. Pause-and-resume or DTMF suppression removes most of that scope and is usually the right fix.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about pci dss compliance?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.