How to complete a PCI DSS self-assessment
Completing a PCI DSS self-assessment is a mandatory requirement to prove your business handles card payments safely and avoids costly non-compliance fees.
To complete your PCI DSS self-assessment, you must identify and fill out the specific Self-Assessment Questionnaire (SAQ) that applies to how your business handles card payments. This process confirms to your bank or payment processor that you are meeting the security standards required to protect your customers' sensitive financial data and prevents you from being charged non-compliance fees.
What is PCI DSS?
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. It isn't just a "good idea"; it is a contractual requirement for any UK business that takes card payments.
Step 1: Identify your Merchant Level
Most small businesses and startups fall into "Merchant Level 4." This level applies to any business processing fewer than 20,000 e-commerce transactions or up to 1 million total transactions per year. As a Level 4 merchant, you are eligible to "self-assess" rather than hiring an external auditor.
Step 2: Choose the correct SAQ
There are several versions of the Self-Assessment Questionnaire. Choosing the wrong one is a common mistake. Most UK small businesses will fall into one of these three categories:
| SAQ Type | Who it is for |
|---|---|
| SAQ A | E-commerce businesses that outsource all card processing to a third party (like Stripe, Shopify, or PayPal) and never see or touch the card data. |
| SAQ B | Brick-and-mortar shops using standalone dial-out terminals (PDQ machines) with no electronic card data storage. |
| SAQ B-IP | Shops using standalone terminals that are connected to the internet via a network cable, rather than a phone line. |
| SAQ C-VT | Businesses that manually enter card details into a "Virtual Terminal" (a web browser on a computer) one at a time. |
Step 3: Complete the Questionnaire
Once you have the correct form (usually provided via an online portal by your payment processor like Zettle, Worldpay, or Barclaycard), you will need to answer a series of "Yes" or "No" questions. These cover things like:
- Do you restrict physical access to your card terminals?
- Do you ensure you never store the 3-digit CVV security code?
- Do you use strong passwords on your business computers and Wi-Fi?
- Are your staff trained in basic security awareness?
Step 4: Sign the Attestation of Compliance (AoC)
The final part of the document is the Attestation of Compliance. This is a formal statement where you "attest" that you have completed the assessment accurately and are compliant with the standards. You will usually sign this digitally.
Tip: If you find you have to answer "No" to a question, don't panic. This simply highlights a security gap you need to fix. Fix the issue, then you can truthfully answer "Yes."
Step 5: Submit and Repeat Annually
Submit the completed SAQ through your payment provider's portal. They will keep this on file to prove your compliance to the card brands (Visa, Mastercard, etc.). Remember, PCI DSS compliance is not a one-time task; you must complete a new self-assessment every 12 months to remain compliant.
Best Practices
- Never store card data: The easiest way to pass your assessment is to never write down or electronically store card numbers or security codes.
- Use a reputable provider: Using modern payment gateways (like Stripe or Square) makes this process much easier, as they handle the "heavy lifting" of security for you.
- Watch out for emails: Your payment provider will usually email you when your assessment is due. Don't ignore these, as non-compliance can result in monthly fines of £20–£100 until the form is submitted.
Created by hatch. • Updated on May 14, 2026