
5 minutes
PCI compliance: what's actually at stake for your business
PCI compliance protects more than your systems. It protects your revenue, your customers and your ability to keep accepting cards. Here's what's on the line, and how to stay ahead of it.
Erin Billhorn
Head of Global Network Compliance
Erin Billhorn leads global network compliance at Worldpay, now Global Payments, where she has spent more than 25 years working with payment networks and sponsor banks to help merchants manage compliance risk.
Key points
- PCI DSS compliance is mandatory for any business that accepts credit or debit cards, regardless of size. Falling out of compliance opens the door to fines, forensic investigation costs and lost customer trust.
- Weak data security widens the door to fraud, and fraud shows up on the other end as chargebacks. A pattern of disputes can get a merchant account flagged for closer review by the card networks.
- Worldpay's SaferPayments programme pairs guided PCI validation with breach support, so small and mid-sized business owners aren’t handling this alone.
A stolen card number rarely starts with a hacker in a hoodie. More often it starts with something ordinary: a card machine left on an unsecured Wi-Fi network, a booking system nobody's patched in years, a spreadsheet of customer details sitting on a shared drive.
Small businesses are common targets, not because criminals think small, but because they know the gaps get overlooked. PCI DSS compliance exists to close those gaps before they turn into an expensive problem, on top of whatever the ICO decides to do about it. Here's what compliance actually protects, what it costs to skip and how we help you stay ahead of it.
What PCI DSS actually covers
The Payment Card Industry Data Security Standard (PCI DSS) protects cardholder data at every point it passes through your business, from the card reader to storage and transmission. It applies whether you take payments in person, online or over the phone. There's no opt-out. Every merchant that accepts card payments must comply, and how much that involves depends on how many transactions you process each year.
For a full walkthrough of the requirements and how to meet them, see How to become PCI compliant. Most small and medium-sized businesses land in the lightest tier. That still means annual reporting you're on the hook for.
What noncompliance can cost you
PCI enforcement isn't hypothetical. When a business falls out of compliance, or a breach turns up gaps that should have been closed, the card networks can apply financial penalties straight to the merchant account. A business caught out of compliance after a breach can also be looking at:
- Card reissuance costs for every customer whose data was exposed
- Forensic investigation fees to pin down the source and scope of the breach
- Ongoing fraud monitoring, paid for by the merchant
- Closer scrutiny from your payment processor and the card networks going forward
In the UK, a breach involving personal data is a data protection matter too, not just a card network one. Under UK GDPR, you generally have to report a qualifying breach to the Information Commissioner's Office within 72 hours of finding out about it, and the ICO can act separately from whatever the card networks do.
The full cost picture, including what a breach means for customer trust, is covered in this guide to preventing data breaches. The short version: The fine is rarely the biggest expense. Rebuilding trust with customers who received a card-replacement notice is the harder cost to recover from.
How PCI compliance connects to chargebacks
PCI compliance and chargebacks aren't the same issue, but they're connected. Weak data security widens the door for fraud, and fraud shows up on the other end as disputes. A pattern of chargebacks, whether from fraud or from confused customers disputing legitimate purchases, can lead the card networks to flag a merchant account for closer review. That review can mean higher processing costs or, in serious cases, restrictions on your ability to keep accepting cards.
If chargebacks are already a challenge for your business, educate yourself about the different types of disputes and how to respond to them. You can also take some practical steps, like clear billing descriptors and stronger authentication, that reduce disputes before they start.
How we help you stay covered
Compliance work doesn't have to fall on you alone. Our SaferPayments programme bundles the tools and support merchants need to meet PCI DSS requirements, in two tiers.
SaferPayments Basic gives you access to an online validation portal where you self-attest your compliance, plus breach waiver if something goes wrong.
SaferPayments Managed adds a guided, step-by-step validation experience from a compliance professional. The team handles your annual reporting and self-assessment questionnaire by phone, manages your required network scans and remediation, and sends reminders so deadlines don't slip. They also monitor for security threats with dedicated cybersecurity tools, and merchants certified through the program are eligible for breach waiver, subject to conditions.
Beyond compliance reporting, our fraud solutions add fraud detection across the customer journey, which reduces the fraud that drives disputes in the first place. And if disputes happen anyway, our dispute management tools help you respond quickly and build a stronger case for recovering revenue.
Customer story
381 Footcare, a podiatry practice in Timperley Village, England, relies on our SaferPayments Managed program to handle its annual PCI DSS validation. Clinical director Andrea Hunt says the process has been straightforward: Any time her team has a question, it gets resolved in one call with the SaferPayments team.
A few things worth remembering
- Compliance is ongoing. An annual report is a checkpoint, not a finish line, and the standards are updated periodically as new risks emerge.
- Your compliance level is based on transaction volume, not business size. A small shop with growing online sales can move levels faster than expected.
- A processor that understands PCI compliance is worth more than a lower rate. The support you get when something goes wrong matters more than the price you pay when nothing does.
PCI compliance FAQ
Does PCI compliance apply to my business if I only take a few card payments a month?
What happens if I fail my PCI self-assessment?
Is PCI compliance a one-time process?
Am I responsible for my vendors' PCI compliance too?
Can Worldpay help if my business has already experienced a breach?
Related insights


