PCI DSS Payment Card Compliance Check
Check whether your website or checkout meets PCI DSS v4.0 requirements for handling debit and credit card payments, now fully mandatory.
Why this matters
The Payment Card Industry Data Security Standard (PCI DSS) is a contractual requirement imposed by Visa, Mastercard, Amex and the other card schemes on every business — of any size — that stores, processes or transmits cardholder data, enforced through your merchant acquirer or payment gateway rather than by a government regulator. Version 4.0 replaced the older 3.2.1 standard, and its full set of requirements — including the previously “future-dated” controls covering things like targeted risk analyses, authenticated internal vulnerability scanning, and stronger multi-factor authentication for all access into the cardholder data environment — became mandatory from 31 March 2025. Many small businesses assume that because they use a hosted checkout page (Stripe, SumUp, WorldPay, PayPal) they have nothing to do, but even fully outsourced payment pages still carry a Self-Assessment Questionnaire (SAQ) obligation, and script-based attacks on checkout pages (Magecart-style card skimming) mean the newer standard specifically requires businesses to monitor and authorise the JavaScript running on their payment pages.
Non-compliance doesn’t usually show up as a fine from a regulator — it shows up as your acquiring bank or payment provider levying monthly non-compliance fees, raising your transaction processing rates, or in the worst case suspending your ability to take card payments at all, and if a card data breach happens while you’re non-compliant you can be liable for the full cost of fraud losses, card reissuance and forensic investigation. The ICO can also take separate UK GDPR enforcement action where a card data breach involves personal data, layering data protection risk on top of the card scheme’s own contractual penalties. Any UK business taking card payments online, by phone, or in person — from a solo trader with a card reader to a retailer running its own checkout — needs to know which SAQ type applies to them and whether their current setup actually meets it.
What you'll need
- How your business takes card payments (in-person terminal, hosted checkout, own checkout page, phone/mail order)
- The name of your payment gateway or processor (e.g. Stripe, SumUp, WorldPay, PayPal, Square)
- Whether you ever see, store or type in full card numbers yourself
- Whether you've completed a PCI Self-Assessment Questionnaire (SAQ) before
What you'll get
A personalised compliance report covering: a score out of 100, an executive summary, a list of findings ranked by severity, and a prioritised action plan with timeframes.
Use this free tool to check whether your website or checkout meets PCI DSS v4.0 requirements — now fully mandatory since 31 March 2025 — covering your payment setup, checkout page scripts, and Self-Assessment Questionnaire status. Get a clear action plan in minutes.
General guidance only — not legal advice. Consult a qualified UK solicitor for specific issues.