EPOS Tips

Drop to SAQ-A or SAQ-B-IP: PCI compliance for UK POS & hospitality

Last Updated: September 21, 2026

PCI DSS v4.x survival guide for UK shops and hospitality. Cut your PCI scope with P2PE and tokenisation, confirm the right SAQ with your acquirer, and...

17 min read

Yes, if your business accepts card payments in the UK, PCI DSS applies to you, full stop. Most small shops and cafés validate through an acquirer’s Self-Assessment Questionnaire rather than a full audit, and the fastest way to lighten that load is switching to PCI-validated terminals or a hosted payments setup. Start by asking your acquirer which SAQ applies to you, then work backwards from there. The PCI Security Standards Council and GOV.UK Pay are your two reference points throughout.


TL;DR:

  • Smaller retailers can significantly reduce PCI scope by implementing point-to-point encryption or tokenization, which minimizes the touchpoints of card data in their systems.
  • Choosing hardware and software that provides validated PCI devices and obtaining Attestation of Compliance documentation prevents common compliance pitfalls and unnecessary paperwork.
  • Staying updated with PCI DSS version changes, especially the requirement for multi-factor authentication and script integrity monitoring, is crucial for continuous compliance.
  • Properly mapping payment flows and system environments helps identify unnecessary data storage and segments the network, easing the scope and compliance process.
  • Using integrated EPOS solutions like Switch-and-Save’s bundles simplifies compliance efforts by providing hardware and software that are pre-validated and tailored to meet PCI requirements.

Switch-and-save
Simplify Your EPOS Payment Setup
Switch-and-Save combines EPOS hardware, AI-powered software and integrated payment processing for UK retail and hospitality businesses.

Explore EPOS solutions

What is PCI DSS and how does it work in the UK?

PCI DSS stands for the Payment Card Industry Data Security Standard, a set of technical and operational rules written by the PCI Security Standards Council, a body founded by the major card schemes. It is not UK law. It is a contractual requirement baked into the agreement you sign with your acquirer (the bank or payment provider that processes your card transactions).

That distinction matters more than most owners realise. Because PCI DSS sits in your merchant contract rather than in statute, your acquirer enforces it directly, and the consequences are commercial rather than criminal. Get it wrong and you can face:

  • Fines passed down from the card schemes through your acquirer, sometimes running to thousands of pounds a month until you fix the issue.
  • Suspension or termination of your ability to accept card payments.
  • Listing on MATCH, a shared database that flags terminated merchants to other acquirers, making it hard to get a new merchant account anywhere.

GOV.UK Pay, the government’s own payment platform, is certified as a level 1 PCI DSS service provider and publishes its compliance documentation openly. It is a useful benchmark for what a properly secured payment environment looks like, even if your business is a fraction of its size.

Does PCI DSS apply to my shop, café or restaurant?

It applies to every business that accepts, processes, transmits, or stores card data, regardless of turnover. What changes with size is your merchant level and which Self-Assessment Questionnaire (SAQ) you complete. Merchant levels run from 1 (over 6 million transactions a year) down to 4 (under 20,000), and almost every independent retailer, café, and restaurant in the UK sits at level 4, which usually means self-assessment rather than an external audit.

The SAQ you complete depends on how you take payment, not on your turnover:

  • SAQ-A: You use a fully hosted or outsourced payment page and never touch card data directly. Simplest option, lightest paperwork.
  • SAQ-B-IP: You use standalone, PCI-listed IP-connected terminals with no other electronic storage of card data.
  • SAQ-C / SAQ-C-VT: You use a virtual terminal or a POS application connected to the internet, with more controls to check.
  • SAQ-D: You store, process, or transmit cardholder data yourself, or your setup does not fit the simpler categories. This is the longest and most demanding questionnaire, covered in PCI SSC’s SAQ-D documentation.

If you are not sure which applies, ask your acquirer directly. They confirm the correct SAQ for your specific payment flow, and guessing wrong wastes far more time than one phone call.

How to reduce your PCI scope for in-person POS

Scope reduction is the single most effective lever a small retailer or restaurant has. The less of the cardholder data environment your systems touch, the shorter your SAQ and the fewer controls you need to prove.

  1. Adopt point-to-point encryption (P2PE). A validated P2PE terminal encrypts card data the moment it is captured, so your till, network, and staff never see the raw card number. This is the technique PCI SSC’s small merchant guide recommends first, and for many independent businesses it is what drops them from SAQ-D into SAQ-B-IP or even SAQ-A.
  2. Use tokenisation for repeat or stored transactions. Instead of storing a card number for a regular customer or a tab, your processor swaps it for a token that is useless to anyone who steals it. Combined with a modern payment terminal, this removes most of the temptation to keep card details in a spreadsheet or notebook, which is one of the most common compliance failures inspectors find.
  3. Confirm vendor claims before you sign anything. Ask any terminal or POS supplier for their Attestation of Compliance (AOC), confirmation their devices appear on the PCI-listed validated P2PE and PTS device registers, and evidence of how tokenisation is implemented.

Pro Tip: Never take a supplier’s word for “PCI compliant” on a spec sheet. Ask for the AOC document by name. If they cannot produce one within a day, that tells you everything you need to know.

Key PCI DSS v4.x changes that affect POS owners

PCI DSS v4.0 replaced the older v3.2.1 standard, and v4.0.1 clarified several points before the mandatory controls became fully enforced in 2025, according to Gradeon’s breakdown of the transition. If your compliance evidence still reflects the old standard, it is out of date now.

Four changes matter most for POS-focused UK retailers and hospitality operators:

  • Multi-factor authentication (MFA) is now required for all access into the cardholder data environment, including admin consoles and local, non-console admin access, not just remote logins.
  • Payment page and script integrity monitoring applies where you take payments online or through a mixed in-store and web setup, requiring an inventory of scripts and checks against tampering.
  • External ASV scans (Approved Scanning Vendor scans of your internet-facing systems) remain mandatory on a quarterly basis, with authenticated internal scanning expected in more environments than before.
  • Targeted risk analysis lets businesses justify a non-prescriptive approach to certain controls, but auditors expect documented evidence behind any custom decision, not just a written excuse.

Many retailers spent 2025 catching up on these exact points, according to Servnet UK’s implementation guide, which flags scope review, script inventories, and MFA rollout as the highest-priority fixes for smaller operators.

Step-by-step: prepare, complete the correct SAQ, and avoid common failures

Getting through your first SAQ does not need to be painful if you work through it in order.

  1. Map every payment flow. List every device that touches a card, every member of staff with access, every third party (your EPOS provider, your acquirer, any booking platform), and anywhere card numbers might linger, including call recordings and voicemail. The BIRA guide for small retailers flags this mapping step as the one most businesses skip, and it is where the surprises live.
  2. Confirm your SAQ with your acquirer. Do not guess. A five-minute call saves you completing the wrong questionnaire twice.
  3. Assemble your evidence. Gather ASV scan reports, access logs, written security policies, and screenshots of MFA in place before you start answering questions.
  4. Fix the obvious failures first. Enable MFA everywhere it is missing, purge any card numbers stored in notes, spreadsheets, or recorded calls, and book your quarterly ASV scan if you have not already.
  5. Decide whether you need a QSA. Most SAQ-A and SAQ-B-IP merchants never need a Qualified Security Assessor. If you are looking at SAQ-D because your setup is complex, a QSA’s Report on Compliance (RoC) can be worth the cost to get it right first time.

Pro Tip: If your SAQ answers keep pointing towards SAQ-D, stop and ask whether a validated terminal or hosted checkout could simplify your setup enough to drop you into a shorter questionnaire. Redesigning the payment flow is usually cheaper than the paperwork.

Costs and timelines vary widely. A straightforward SAQ-A or SAQ-B-IP self-assessment costs nothing beyond your own time and typically takes a few hours to a couple of days once evidence is gathered. A QSA-led RoC for a complex SAQ-D environment can run into thousands of pounds and take several weeks, largely because of the on-site assessment and documentation review involved.

How Switch-and-save can help with PCI compliance for your POS

An EPOS setup built around validated hardware and integrated processing does much of the scope-reduction work before you even open your first SAQ. Switch-and-save’s Integrated Payments Bundle pairs EPOS software with card terminal hardware in one package, and the Hospitality EPOS Bundle does the same for restaurants, cafés, and takeaways with additional features suited to table service and multi-terminal sites.

Whichever provider you choose, ask these questions before signing anything:

  • Can you provide an AOC for your payment terminals?
  • Are your devices on the PCI-listed validated P2PE or PTS registers?
  • Do you have a relationship with a QIR (Qualified Integrator and Reseller) or QSA for more complex installations?
  • Will your team provide recent ASV scan reports on request?

Switch-and-save’s card machine options are built around this kind of validated hardware, and a short demo is usually enough to spot where your current setup is creating unnecessary compliance work.

UK data protection law and PCI DSS: where GDPR fits in

PCI DSS and UK GDPR are two different obligations that overlap constantly at the point of sale, and conflating them is a common mistake. PCI DSS is a payment industry contract standard focused specifically on cardholder data. UK GDPR is statute, enforced by the Information Commissioner’s Office, and it covers any personal data your business holds, which includes customer names, addresses, loyalty scheme details, and yes, payment information too.

PCI DSS and UK GDPR comparison

A card number is personal data under UK GDPR whenever it can be linked to an identifiable person, which in a retail or hospitality setting is nearly always. That means a data breach involving stored card numbers can trigger two separate sets of consequences: acquirer penalties under your PCI contract, and a potential ICO investigation with its own fines under UK GDPR, which can reach far higher figures than typical PCI fines for serious breaches.

The practical overlap shows up most in three places. First, data minimisation, a core UK GDPR principle, aligns neatly with PCI’s advice to avoid storing card data you do not need. Second, breach notification timelines differ: UK GDPR gives you 72 hours to notify the ICO of a qualifying breach, while your acquirer’s PCI-related reporting obligations run on a separate, contractually defined clock. Third, staff training and access logging, both expected under PCI DSS, also help demonstrate UK GDPR accountability if the ICO ever asks how you protect customer data.

Treat the two frameworks as complementary rather than duplicated effort. A business that has properly scoped its cardholder data environment under PCI DSS has usually already done half the work UK GDPR expects for payment-related personal data.

Fitting PCI compliance into your existing POS hardware and software

Retrofitting compliance onto an EPOS system you already own is usually more realistic than most owners assume, provided you know which parts of your setup actually touch card data. The starting point is always a compatibility check between your existing till hardware, your card terminal, and whatever software links them together, because a mismatch here is often where card data ends up sitting somewhere it should not.

If your current EPOS software stores transaction records locally, ask your provider exactly what fields are captured and whether full card numbers ever appear in logs, receipts, or exports. Many older systems were not built with PCI DSS v4.x’s stricter access controls in mind, and a software update or configuration change can close gaps without replacing the hardware entirely. A POS hardware compatibility guide is a useful starting reference when you are trying to work out whether your current terminal and till software can be reconfigured or whether replacement is the more sensible route.

Integration also matters for multi-terminal and multi-site businesses. If you run several tills across one shop or multiple locations, every additional terminal and every additional piece of connected software widens your cardholder data environment unless it is properly segmented. Network segmentation, keeping your payment systems on a separate network from your general Wi-Fi and back-office systems, is one of the simplest ways to shrink that environment without ripping out equipment you have already paid for.

Staff training deserves a mention here too. Hospitality businesses in particular run into trouble when front-of-house staff are never told which systems are in scope, leading to card numbers ending up in booking notes or shared spreadsheets. Practical guidance on fixing common hospitality operational issues covers this kind of training gap well, and it is worth reading alongside your PCI preparation rather than treating the two as separate projects.

How new UK payment technology is changing PCI compliance for POS

Contactless and Tap to Pay technology has changed faster in the UK than almost any other retail payment feature, and each shift brings a fresh compliance question. Tap to Pay on mobile, where a standard smartphone becomes the card reader with no separate terminal required, is now available through several UK providers, and it changes the compliance picture because the phone itself becomes part of the cardholder data environment rather than a dedicated, PCI-listed device sitting alongside it.

The safest approach with Tap to Pay on mobile is to confirm the software development kit behind it is itself PCI validated, specifically under the Contactless Payments on COTS (CPoC) or Software-based PIN Entry on COTS (SPoC) standards published by PCI SSC. A provider that cannot point you to which standard their mobile acceptance solution meets has not done the validation work themselves, and that gap becomes your problem the moment something goes wrong.

Open banking payments and account-to-account transfers are also creeping into UK retail and hospitality checkouts, particularly for high-value transactions where card scheme fees bite hardest. These payment rails sit outside traditional card network rules, so they are not governed by PCI DSS in the same way, but they still fall under UK GDPR and the Financial Conduct Authority’s payment services regulations, so do not assume moving away from cards removes your compliance workload; it just changes which rulebook applies.

Digital wallets, loyalty apps, and QR code ordering systems common in UK cafés and quick-service restaurants add further points where customer and payment data pass through your systems. Each new integration is a new question to ask: does this touch card data, and if so, has the provider validated it against a recognised PCI standard? Asking that question before adopting any new payment technology keeps your scope from creeping back up after you have worked to reduce it.

PCI DSS itself carries no statutory penalty because it is not law, but the practical consequences of failing it can be just as severe as a legal one, and sometimes worse for a small business’s survival. Your acquirer’s contract is the enforcement mechanism, and a breach or a failed assessment typically triggers a sequence of escalating responses rather than a single penalty.

Fines from the card schemes, passed through your acquirer, can range from a few hundred pounds a month for a minor, quickly fixed issue to substantial ongoing charges for a serious breach involving stolen card data. These fines usually continue until you demonstrate remediation, which means the cost compounds the longer an issue goes unaddressed. Beyond fines, acquirers can suspend your ability to take card payments altogether while an investigation runs, which for a café or shop with no cash-only fallback can mean days or weeks of lost trading.

The most serious commercial consequence is MATCH listing, a shared database maintained by the card schemes that flags merchants terminated for compliance or fraud reasons. Once listed, securing a new merchant account with any other UK acquirer becomes extremely difficult, effectively locking a business out of card acceptance for years.

Where a breach also exposes customer personal data, UK GDPR adds a separate legal layer entirely. The Information Commissioner’s Office can investigate independently of any PCI-related acquirer action, and its fining powers are set in statute rather than contract, meaning they apply regardless of what your payment provider decides to do. A single incident involving stolen card data can therefore trigger acquirer fines, a possible MATCH listing, and an ICO investigation simultaneously, which is precisely why scope reduction and continuous monitoring cost so much less than dealing with the aftermath of a breach.

Compliance is not a document you file once. Fix multi-factor authentication and stop storing card numbers in notes or recordings first. These two changes cost little and close the gaps auditors find most often. Everything else follows from there.

— Amir

Get help reducing your PCI scope with a proper EPOS setup

Switch-and-save is the practical alternative to piecing together compliance yourself across mismatched hardware and software. The Integrated Payments Bundle and the Hospitality EPOS Bundle both pair EPOS software with card terminal hardware in one package, which means the scope-reduction work this article covers, validated terminals, encrypted card capture, no loose spreadsheets of customer numbers, is largely handled before you even sit down to complete your SAQ.

Switch-and-save

The Hospitality EPOS Bundle includes AI-powered cloud software at £20 a month, while the Integrated Payments Bundle runs its EPOS software subscription at £30 a month. Both come with UK-based support, so when you need to answer a supplier question for your SAQ, such as an AOC or confirmation your terminal is PCI-listed, you are asking someone who already knows the answer rather than chasing a call centre abroad. Request a free demo and ask for a quick compliance checklist tailored to your shop or restaurant. It is the fastest way to see exactly where your current setup is creating extra paperwork you do not need.

Where to check the official rules yourself

For SAQ downloads and device lists, go to PCI SSC. For public-sector payment security benchmarks, see GOV.UK Pay. Check your acquirer’s own dashboard for your specific SAQ submission path.

Sources

FAQ

No, PCI DSS is not UK statute, it is a contractual requirement set by the card schemes and enforced through your acquirer agreement. That said, a card data breach can still trigger UK GDPR obligations and potential Information Commissioner’s Office action, which are legal requirements.

Can I do PCI compliance myself?

Yes, most small UK retailers and hospitality businesses complete a Self-Assessment Questionnaire themselves without hiring a Qualified Security Assessor. You only typically need a QSA if your setup is complex enough to require SAQ-D and a full Report on Compliance.

Is PCI compliance legally required?

It is required by your merchant contract with your acquirer, not by an Act of Parliament, so failing to comply risks fines, suspension, or MATCH listing rather than criminal prosecution. Where cardholder data is also personal data under UK GDPR, separate legal obligations apply on top of your PCI contract.

How much should PCI compliance cost?

A straightforward SAQ-A or SAQ-B-IP self-assessment costs nothing beyond your own time, typically a few hours of work once your evidence is gathered. A QSA-led assessment for a complex SAQ-D environment can cost thousands of pounds and take several weeks; current pricing for Switch-and-save’s EPOS bundles, which include validated terminals that help reduce this burden, is available on the Switch-and-save website.

Sales Team A

Author

Epos Guru

Reviewed by Epos Guru. Our content covers EPOS systems, business finance, utilities, and SME technology trends for UK businesses.

Ready to Switch & Save?

Get a free EPOS demo and see how we can cut your costs and grow your business.

Get Your Free EPOS Demo
Back to All Articles