Should my business accept card payments over the phone?
PCI DSS v4 obligations for telephone payments, and the secure ways to take card details by phone in 2026.
By the Telappliant team

Taking a card number over the phone is convenient for customers who cannot or do not want to pay online, but it puts your business directly in the scope of PCI DSS. Whether that is worth it depends on your volumes, your channel mix and how you handle the compliance burden.
Why customers still want it
Telephone payments remain common for older customers, high-value transactions people want reassurance on, and businesses like trades, clinics and agencies where the sale naturally happens on a call. Removing the option can lose business, particularly to competitors who still offer it.
What accepting card payments by phone actually commits you to
- PCI DSS v4.x compliance for any system, person or process that touches cardholder data
- A documented policy on where card numbers can be written down, said aloud or stored, ideally nowhere
- Staff training on secure handling and what not to do, such as writing numbers on paper
- Call recording controls, since a recorded card number is a major compliance and breach risk
The safer alternative most PCI assessors recommend
DTMF masking, sometimes called dual-tone suppression, lets the customer key their card details into the phone keypad while the agent stays on the line, but the tones and the card data never reach the recording, the agent's screen or your network. This removes almost your entire PCI DSS scope compared with an agent typing or reading back numbers.
Deciding whether to offer it
- Estimate genuine demand: how many customers ask for it versus default to card readers or online links
- Weigh the PCI compliance overhead against the alternative of losing those transactions
- Check whether your existing card payment provider or phone system already supports secure telephone payments
- If volumes are low, a payment link sent by SMS during the call is a lower-risk alternative
If you decide to proceed
Do not build ad hoc telephone payment handling around a member of staff reading numbers back. Use a proper secure telephone payment solution integrated with your phone system, keep card data out of recordings entirely, and get your PCI DSS scope confirmed by your acquiring bank or a qualified assessor before you go live.



