PCI DSS Hosting UK: Complete Merchant Compliance Guide 2025

Everything UK merchants need to know about PCI DSS compliance โ€” from SAQ selection to hosting requirements, self-assessment workflows, and how European data centre (Poland) hosting simplifies the compliance process.

What Is PCI DSS Compliance?

PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements for any organisation that handles, stores, processes, or transmits credit card data. If your UK business accepts card payments โ€” whether through Stripe, a payment gateway, or direct merchant processing โ€” your hosting environment must meet PCI DSS standards.

The standard is managed by the PCI Security Standards Council and enforced by the major card brands (Visa, Mastercard, American Express). For UK merchants, compliance is assessed through a Self-Assessment Questionnaire (SAQ) or, for larger processors, a full Report on Compliance (ROC) by a Qualified Security Assessor (QSA).

Why UK Hosting Matters for PCI DSS

One of the most common compliance mistakes UK merchants make is hosting cardholder data outside the UK or with providers that can't provide a clear compliance boundary. Here's why European data centre (Poland) hosting simplifies PCI DSS:

PCI DSS Requirements for Hosting: The 12 Key Areas

PCI DSS is organised into 6 goals and 12 requirements. Here's how each applies to your hosting setup:

Goal 1: Build and Maintain a Secure Network

Requirement 1: Install and maintain a firewall configuration to protect cardholder data.
Hosting impact: Your hosting provider must support network segmentation between cardholder data environment (CDE) and non-CDE systems. KVM-based virtualisation with VLAN support satisfies this requirement.

Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters.
Hosting impact: Bare metal hosting gives you complete control over OS-level configurations, default accounts, and security hardening โ€” no shared hypervisor defaults to worry about.

Goal 2: Protect Cardholder Data

Requirement 3: Protect stored cardholder data.
Hosting impact: Use ZFS or LUKS encryption at rest on your hosting storage. Hostingowy's NVMe storage supports full-disk encryption.

Requirement 4: Encrypt transmission of cardholder data across open, public networks.
Hosting impact: Ensure TLS 1.2+ is enforced on all data paths. Your hosting provider should support private VLANs and VPN tunnels for internal traffic.

Goal 3: Maintain a Vulnerability Management Program

Requirement 5: Protect all systems against malware and regularly update anti-virus software or programs.
Hosting impact: With dedicated hosting, you control the OS-level anti-malware deployment and can schedule scans without impacting other tenants.

Requirement 6: Develop and maintain secure systems and applications.
Hosting impact: Apply security patches promptly. Bare metal access gives you full control over the patching schedule for kernel, libraries, and applications.

Goal 4: Implement Strong Access Control Measures

Requirement 7: Restrict access to cardholder data by business need-to-know.
Hosting impact: Use SSH key-based authentication with role-based access control on your hosting infrastructure.

Requirement 8: Identify and authenticate access to system components.
Hosting impact: Implement multi-factor authentication for all hosting control panel and SSH access.

Requirement 9: Restrict physical access to cardholder data.
Hosting impact: Your European data centre (Poland) should have ISO 27001 certification with 24/7 security, biometric access controls, and CCTV monitoring.

Goal 5: Regularly Monitor and Test Networks

Requirement 10: Track and monitor all access to network resources and cardholder data.
Hosting impact: Deploy Prometheus + Loki or ELK stack for centralised logging. Bare metal gives you unfiltered access to all system and application logs.

Requirement 11: Regularly test security systems and processes.
Hosting impact: Run regular vulnerability scans and penetration tests. With dedicated hosting, you can schedule scans without provider restrictions.

Goal 6: Maintain an Information Security Policy

Requirement 12: Maintain a policy that addresses information security for all personnel.
Hosting impact: Document your hosting architecture, access controls, and incident response procedures as part of your security policy.

SAQ Types: Which One Applies to Your UK Business?

SAQ Type Who It Applies To Questions
SAQ A Card-not-present merchants with fully outsourced cardholder data processing 22
SAQ A-EP E-commerce merchants who outcharge but control the payment page 191
SAQ B Merchants using standalone dial-up or imprint terminals 26
SAQ B-IP Merchants using standalone IP-connected terminals 33
SAQ C-VT Merchants using virtual terminals on a web browser 54
SAQ C E-commerce merchants with payment application connected to the internet 160
SAQ D All other merchants (most common for UK SaaS companies handling payments) 329
Important: Most UK SaaS companies and e-commerce merchants fall under SAQ A-EP or SAQ D. If you store, process, or transmit cardholder data on your own hosting infrastructure, SAQ D is likely your starting point. A QSA can help validate your SAQ selection.

Shared Responsibility: What Your Hosting Provider Must Provide

For PCI DSS compliance, your hosting provider must provide evidence of:

With Hostingowy's European data centre (Poland) hosting, you get bare metal isolation โ€” your workloads run on dedicated hardware with no shared tenancy. This significantly simplifies your compliance scope because the boundary of your CDE is clearly defined.

PCI DSS Compliance Checklist for UK Merchants

  1. โ˜ Determine your SAQ type (use the table above)
  2. โ˜ Choose a PCI DSS-compatible hosting provider with UK data centres
  3. โ˜ Segment your network โ€” create a dedicated CDE VLAN for cardholder data
  4. โ˜ Harden your servers using CIS benchmarks or equivalent standards
  5. โ˜ Enable encryption at rest (LUKS/ZFS) and in transit (TLS 1.2+)
  6. โ˜ Deploy centralised logging (ELK, Loki) with 12-month retention
  7. โ˜ Set up intrusion detection (OSSEC, Wazuh, or equivalent)
  8. โ˜ Schedule quarterly vulnerability scans with an ASV-approved scanner
  9. โ˜ Document your security policies and incident response plan
  10. โ˜ Complete and submit your SAQ to your acquiring bank

Common PCI DSS Pitfalls for UK Businesses

Using shared hosting for cardholder data: Shared hosting environments make PCI DSS compliance extremely difficult because you can't control the hypervisor layer or neighbouring tenants. Always use dedicated servers or VPS for CDE workloads.

Storing CVV codes or track data: PCI DSS explicitly prohibits storing CVV2/CVC2 codes or full magnetic stripe data after authorisation. Ensure your payment integration strips this data before storage.

Ignoring third-party dependencies: If you use Stripe, Braintree, or another payment gateway, your SAQ requirements may be reduced โ€” but you still need to ensure your hosting environment meets the applicable requirements.

Assuming cloud providers handle everything: AWS, GCP, and Azure operate on a shared responsibility model. Even with their PCI DSS attestations, you're responsible for securing your workloads, configurations, and data within their environments.

Need PCI DSS Compliant Hosting?

Our European data centre (Poland) hosting gives you bare metal isolation, full root access, and a clearly defined compliance boundary. Chat with our engineering team about your PCI DSS requirements.

Speak to Our Team โ†’

Related reading: UK GDPR Hosting Compliance Guide โ€ข UK Data Centre Guide 2025 โ€ข Linux Server Hardening Guide

๐Ÿš€

The Hostingowy Engineering Digest

Get monthly deep-dives on UK VPS hosting, infrastructure benchmarks, DevOps tooling, and cloud cost optimisation. Built by engineers, for engineers.

2 issues sent ยท 7 subscribers ยท No spam, ever

No spam. Unsubscribe anytime. Read our Privacy Policy.