5 PCI DSS facts every small business owner should know
SAQ levels, scope, fines and validation - the essential PCI DSS v4 facts for UK small businesses.
By the Telappliant team

Most small business owners inherit PCI compliance obligations the moment they accept a card payment, often without anyone explaining what that means. These five facts under PCI DSS v4.x are the ones that matter most in practice.
1. PCI DSS applies to you even as a small business
There is no size exemption. Any business that stores, processes or transmits cardholder data, whether through a card machine, a website or taking numbers over the phone, is in scope for PCI DSS. Your acquiring bank sets the specific validation requirements based on transaction volume.
2. Validation level depends on transaction volume
- Level 1: over 6 million transactions a year, requiring an external Qualified Security Assessor audit
- Level 2: 1 to 6 million transactions, typically requiring an annual Self-Assessment Questionnaire
- Level 3: 20,000 to 1 million e-commerce transactions, usually an SAQ
- Level 4: below those thresholds, which covers most UK small businesses, usually a shorter SAQ
3. The SAQ type depends on how you take payments
There are several SAQ types under PCI DSS v4.x, ranging from SAQ A for businesses that fully outsource card data handling to a compliant third party, through to longer questionnaires for businesses that store or process card data directly. Taking card numbers over the phone and writing them down typically pushes you into a more demanding SAQ than most owners expect.
4. Non-compliance carries real financial consequences
- Card schemes can levy fines on your acquiring bank, which are usually passed on to you
- Non-compliance after a breach significantly increases forensic and remediation costs
- Your merchant account can be suspended, stopping you taking card payments entirely
5. Reducing scope is the fastest route to compliance
The less of your business environment that touches raw card data, the fewer PCI DSS requirements apply. Routing telephone and card-not-present payments through a secure, PCI-compliant payment service removes card data from your network and call recordings, which is usually the single most effective step a small business can take.



