WordPress design
Custom WordPress builds on a 5-year hosting agreement
Trades & home services — emergency call-out, service grid, local trust signals
View WordPress designNano & Micro entry
Apps+OS from £5.33/mo — WordPress eligible
Small — 3 months free
Most popular starter — trial on new accounts
Scale plans
X-Large through 16X-Large for growth clients
Professional mailboxes
Webmail on your domain — monthly and annual plans
Uptime monitoring
External checks and alerts before customers notice
WordPress design
Custom WordPress builds on a 5-year hosting agreement
Trades & home services — emergency call-out, service grid, local trust signals
View WordPress designCustom development
Bespoke sites, apps, and integrations
Ecommerce retail — product discovery, merchandising, and checkout-ready layout
View Custom development
You set up a shop, added a payment button, and the orders started coming in. Somewhere in the small print of your payment provider was a phrase about being PCI compliant, and you nodded along without quite knowing what it meant. That gap is extremely common, and it is worth closing.
The good news is that for most small UK retailers, meeting these rules is far simpler than the acronym implies. The trick is understanding which parts actually apply to you.
The Payment Card Industry Data Security Standard, mercifully shortened to PCI DSS, applies to any business that accepts, processes or stores card payments. It does not matter whether you turn over a few hundred pounds a month or a few hundred thousand. Take a card and you are in scope.
It is not a law in the way UK data protection is, but it is a contractual requirement set by the card schemes and enforced through your payment provider. Ignore it and you risk higher fees, and a far worse position if a breach ever exposes customer card details. The official standard is maintained by the PCI Security Standards Council, an industry body rather than a government one.
Strip away the formal language and the standard asks you to do sensible things. Protect card data while it moves and while it rests, keep the systems that touch it patched and access controlled, and be able to show what you have done.
For a typical small shop, compliance is demonstrated through a self assessment questionnaire rather than a full external audit. The council publishes different questionnaire versions for different setups, and the version you complete depends entirely on how you handle the card details in the first place.
That last point is the one that decides how much work you face. The less card data ever touches your own systems, the shorter and simpler your questionnaire becomes.
Here is the single most useful decision you can make. Do not handle raw card numbers yourself. Use a hosted payment page or an embedded field from an established gateway, so the customer's card details go straight to the payment provider and never land on your server.
When the sensitive data bypasses you entirely, most of the standard's heaviest requirements fall away. You still have responsibilities, but they shrink to keeping your site secure and your integration tidy rather than guarding a vault of card numbers. It is the difference between storing valuables in your own back room and letting a specialist hold them in their safe.
This approach also protects you from the most common ways shops get caught out. A poorly maintained site that captures card fields can be skimmed by injected scripts, the kind of attack the OWASP Top Ten has tracked for years. Keep the card data off your servers and that whole risk largely disappears.
Your hosting setup quietly does a lot of the compliance work for you, or quietly undermines it. A current platform with supported software versions, a properly configured firewall and encryption in transit covers several requirements before you have lifted a finger.
Encryption in transit is non negotiable, which means a valid certificate on every page, not just the checkout. If you are unsure what type you need, our SSL certificate guide and options explain the choices in plain terms. A site served entirely over a secure connection both satisfies the standard and reassures the customer staring at the address bar.
Beyond that, look for a host that patches the underlying systems, isolates accounts from one another, and can evidence its own security posture. We keep the relevant documentation and controls described on our compliance page so you are not left guessing what sits beneath your shop.
Scope is the word that decides how painful PCI DSS is. Scope means every system, person and process that could touch card data. The smaller you keep it, the less there is to assess, secure and prove.
Practically, that means routing payments through a trusted gateway, never emailing or writing down card numbers, restricting who can access your admin area, and keeping plugins and themes up to date so an old vulnerability does not become an open door. None of these are exotic. They are the same habits that keep any online business out of trouble.
It also helps to remember that PCI DSS sits alongside your wider duty to protect personal data, not instead of it. The Information Commissioner's guide to data protection is the companion piece, covering the names, addresses and order histories that card rules do not. Treat the two as one habit rather than two chores.
Get the structure right early and compliance becomes a yearly tick rather than a recurring panic. Take cards safely, keep the sensitive data off your own systems, host on a platform that pulls its weight, and document what you do. That is most of the battle won.

Compliance
Certification badges are everywhere on hosting sites. Here is what ISO 27001 actually proves, what it does not, and how to question it sensibly.

Compliance
After Brexit the UK kept GDPR but made it its own. If you sell to customers on both sides of the Channel, the small differences are the ones that matter.

Compliance
You are responsible for your customers' data even when someone else stores it. Knowing where it physically sits is part of that responsibility.

Comments