# PCI DSS compliance.

> PCI DSS compliance support for UK businesses that take card payments. Scope reduction, self-assessment questionnaires, PCI scanning and practical fixes.

Canonical: https://cybersecuritylondon.com/pci-dss


If you take card payments, PCI DSS applies to you. We help you understand your scope, reduce it where possible and meet the requirements without unnecessary cost.

Covers: Scope reduction, SAQ support, PCI scanning, Remediation.

## Overview

PCI DSS is the security standard set by the card brands. Your bank or payment provider will expect you to show compliance, usually through a self-assessment questionnaire (SAQ).

The quickest win is often reducing scope, so fewer systems touch card data. We help you choose the right SAQ, close the gaps and keep the evidence your acquirer asks for.

### A good fit if

- Your payment provider has asked for PCI compliance
- You are unsure which SAQ applies to you
- You are being charged non-compliance fees
- You are changing how you take payments

## What's included

- **Scope review**: Where card data flows and which systems are in scope.
- **Scope reduction**: Advice on payment setups that reduce your PCI burden.
- **SAQ support**: Choosing and completing the right self-assessment questionnaire.
- **PCI scanning**: External vulnerability scanning where your SAQ requires it.
- **Remediation**: Practical help closing the gaps.
- **Evidence pack**: Documentation ready for your acquirer.

## How it works

1. **Scope**: Map card data flows and systems.
2. **Reduce**: Simplify scope where possible.
3. **Remediate**: Close the gaps against the requirements.
4. **Validate**: Complete the SAQ and supporting evidence.

## Support options

- **PCI readiness review**: A clear view of your scope and gaps.
- **SAQ completion support**: Guidance through the right questionnaire for your setup.
- **PCI DSS scanning**: Quarterly external scans where required.
- **PCI DSS v4.0 transition**: Help adapting to the latest version of the standard.

## What affects the cost

- **Payment setup**: How you take payments affects scope and effort.
- **SAQ type**: Some questionnaires are short; others cover hundreds of requirements.
- **Scanning**: Whether quarterly external scans are needed.
- **Remediation**: How much needs fixing to meet the standard.

We quote a fixed price after reviewing how you take payments.

## Frequently asked questions

### Does PCI DSS apply to my business?

If you accept, process, store or transmit card payments, yes. The amount of work depends on how you take payments.

### Which SAQ do I need?

It depends on your payment setup, for example whether you use a hosted payment page, card terminals or process cards on your own systems. We help you confirm the right one.

### What is PCI DSS scanning?

Quarterly external vulnerability scans required for some merchants, carried out by an approved scanning vendor. We arrange and manage these where needed.

### Can we reduce our PCI scope?

Often, yes. Using hosted payment pages or point-to-point encrypted terminals can take many of your systems out of scope.

## Related services

- [Vulnerability Management](https://cybersecuritylondon.com/vulnerability-management)
- [Security Audits](https://cybersecuritylondon.com/security-audits)
- [ISO 27001](https://cybersecuritylondon.com/iso-27001)

## Contact

Email letstalk@networklondon.co.uk or use the enquiry form at https://cybersecuritylondon.com/#contact. Cyber Security London, The Leather Market, London Bridge, London.
