PCI DSS Compliance Support for UK Merchants
The cheapest PCI DSS project is the one where card data never touches your systems. We reduce your scope first, then evidence what remains.
Which PCI DSS Self-Assessment Questionnaire do we need?
It depends on how you take payments. Merchants who fully outsource card capture to a hosted payment page typically use SAQ A, the shortest. Card-present merchants with standalone terminals often use SAQ B or B-IP. Your acquiring bank confirms which applies — always check with them before starting.
Follow the card data
PCI DSS applies to the systems that store, process or transmit cardholder data, and to anything connected to them. So the first task is always to establish where card data actually goes — which is frequently more places than the business believes. Card details read out over the phone and typed into a browser put that workstation in scope. A call recording system capturing card numbers puts the recording platform in scope.
Once the flow is mapped, most merchants can restructure to remove scope entirely: a hosted payment page for the website, pause-and-resume or DTMF suppression for telephone orders, and standalone terminals on a segregated connection in store. That is nearly always cheaper than securing and evidencing a large environment.
- Map every route by which card data enters the business
- Identify anything storing card data, including call recordings and email
- Move to hosted payment pages so the website never touches card data
- Suppress card data in call recording rather than storing and redacting it
- Segregate card terminals from the general office network
What PCI DSS v4.0 changed
Version 4.0 brought stricter expectations that particularly affect e-commerce merchants. Payment pages must have their scripts inventoried, justified and monitored for unauthorised change, which is a direct response to digital skimming attacks. Multi-factor authentication requirements were extended, and password expectations strengthened.
The standard also introduced a customised approach, allowing organisations to meet a control objective differently where they can document and validate it. In practice that flexibility is aimed at larger organisations; small merchants are almost always better served by reducing scope than by engineering an alternative.
- Script inventory, justification and integrity monitoring on payment pages
- Expanded multi-factor authentication requirements
- Strengthened password and authentication expectations
- Documented, assigned roles and responsibilities for each requirement
Included in every engagement
Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.
PCI DSS Compliance — your questions answered
Who decides whether we are PCI DSS compliant?
Can we avoid PCI DSS by using Stripe, PayPal or Worldpay?
Do we need quarterly vulnerability scans?
What happens if we take card details over the phone?
Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.
You might also need
Ready to talk about pci dss compliance?
Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.