PCI DSS Hosting UK: Complete Merchant Compliance Guide 2025
Everything UK merchants need to know about PCI DSS compliance โ from SAQ selection to hosting requirements, self-assessment workflows, and how European data centre (Poland) hosting simplifies the compliance process.
What Is PCI DSS Compliance?
PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements for any organisation that handles, stores, processes, or transmits credit card data. If your UK business accepts card payments โ whether through Stripe, a payment gateway, or direct merchant processing โ your hosting environment must meet PCI DSS standards.
The standard is managed by the PCI Security Standards Council and enforced by the major card brands (Visa, Mastercard, American Express). For UK merchants, compliance is assessed through a Self-Assessment Questionnaire (SAQ) or, for larger processors, a full Report on Compliance (ROC) by a Qualified Security Assessor (QSA).
Why UK Hosting Matters for PCI DSS
One of the most common compliance mistakes UK merchants make is hosting cardholder data outside the UK or with providers that can't provide a clear compliance boundary. Here's why European data centre (Poland) hosting simplifies PCI DSS:
- Full control over the compliance scope โ with bare metal or dedicated VPS, you define exactly which servers handle cardholder data
- No shared tenancy concerns โ public cloud shared infrastructure creates complex compliance boundaries
- EU data residency โ cardholder data remains within EU jurisdiction under UK GDPR adequacy protections
- Predictable audit trail โ dedicated hardware gives you clean, auditable logs without noisy neighbour data
PCI DSS Requirements for Hosting: The 12 Key Areas
PCI DSS is organised into 6 goals and 12 requirements. Here's how each applies to your hosting setup:
Goal 1: Build and Maintain a Secure Network
Requirement 1: Install and maintain a firewall configuration to protect cardholder data.
Hosting impact: Your hosting provider must support network segmentation between cardholder data environment (CDE) and non-CDE systems. KVM-based virtualisation with VLAN support satisfies this requirement.
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters.
Hosting impact: Bare metal hosting gives you complete control over OS-level configurations, default accounts, and security hardening โ no shared hypervisor defaults to worry about.
Goal 2: Protect Cardholder Data
Requirement 3: Protect stored cardholder data.
Hosting impact: Use ZFS or LUKS encryption at rest on your hosting storage. Hostingowy's NVMe storage supports full-disk encryption.
Requirement 4: Encrypt transmission of cardholder data across open, public networks.
Hosting impact: Ensure TLS 1.2+ is enforced on all data paths. Your hosting provider should support private VLANs and VPN tunnels for internal traffic.
Goal 3: Maintain a Vulnerability Management Program
Requirement 5: Protect all systems against malware and regularly update anti-virus software or programs.
Hosting impact: With dedicated hosting, you control the OS-level anti-malware deployment and can schedule scans without impacting other tenants.
Requirement 6: Develop and maintain secure systems and applications.
Hosting impact: Apply security patches promptly. Bare metal access gives you full control over the patching schedule for kernel, libraries, and applications.
Goal 4: Implement Strong Access Control Measures
Requirement 7: Restrict access to cardholder data by business need-to-know.
Hosting impact: Use SSH key-based authentication with role-based access control on your hosting infrastructure.
Requirement 8: Identify and authenticate access to system components.
Hosting impact: Implement multi-factor authentication for all hosting control panel and SSH access.
Requirement 9: Restrict physical access to cardholder data.
Hosting impact: Your European data centre (Poland) should have ISO 27001 certification with 24/7 security, biometric access controls, and CCTV monitoring.
Goal 5: Regularly Monitor and Test Networks
Requirement 10: Track and monitor all access to network resources and cardholder data.
Hosting impact: Deploy Prometheus + Loki or ELK stack for centralised logging. Bare metal gives you unfiltered access to all system and application logs.
Requirement 11: Regularly test security systems and processes.
Hosting impact: Run regular vulnerability scans and penetration tests. With dedicated hosting, you can schedule scans without provider restrictions.
Goal 6: Maintain an Information Security Policy
Requirement 12: Maintain a policy that addresses information security for all personnel.
Hosting impact: Document your hosting architecture, access controls, and incident response procedures as part of your security policy.
SAQ Types: Which One Applies to Your UK Business?
| SAQ Type | Who It Applies To | Questions |
|---|---|---|
| SAQ A | Card-not-present merchants with fully outsourced cardholder data processing | 22 |
| SAQ A-EP | E-commerce merchants who outcharge but control the payment page | 191 |
| SAQ B | Merchants using standalone dial-up or imprint terminals | 26 |
| SAQ B-IP | Merchants using standalone IP-connected terminals | 33 |
| SAQ C-VT | Merchants using virtual terminals on a web browser | 54 |
| SAQ C | E-commerce merchants with payment application connected to the internet | 160 |
| SAQ D | All other merchants (most common for UK SaaS companies handling payments) | 329 |
Shared Responsibility: What Your Hosting Provider Must Provide
For PCI DSS compliance, your hosting provider must provide evidence of:
- Physical security โ ISO 27001 certification, SOC 2 Type II, or equivalent
- Network security โ Firewalls, intrusion detection, and DDoS protection
- Access controls โ Role-based access to management interfaces
- Logging and monitoring โ Access logs for all infrastructure components
- Change management โ Documented processes for infrastructure changes
With Hostingowy's European data centre (Poland) hosting, you get bare metal isolation โ your workloads run on dedicated hardware with no shared tenancy. This significantly simplifies your compliance scope because the boundary of your CDE is clearly defined.
PCI DSS Compliance Checklist for UK Merchants
- โ Determine your SAQ type (use the table above)
- โ Choose a PCI DSS-compatible hosting provider with UK data centres
- โ Segment your network โ create a dedicated CDE VLAN for cardholder data
- โ Harden your servers using CIS benchmarks or equivalent standards
- โ Enable encryption at rest (LUKS/ZFS) and in transit (TLS 1.2+)
- โ Deploy centralised logging (ELK, Loki) with 12-month retention
- โ Set up intrusion detection (OSSEC, Wazuh, or equivalent)
- โ Schedule quarterly vulnerability scans with an ASV-approved scanner
- โ Document your security policies and incident response plan
- โ Complete and submit your SAQ to your acquiring bank
Common PCI DSS Pitfalls for UK Businesses
Using shared hosting for cardholder data: Shared hosting environments make PCI DSS compliance extremely difficult because you can't control the hypervisor layer or neighbouring tenants. Always use dedicated servers or VPS for CDE workloads.
Storing CVV codes or track data: PCI DSS explicitly prohibits storing CVV2/CVC2 codes or full magnetic stripe data after authorisation. Ensure your payment integration strips this data before storage.
Ignoring third-party dependencies: If you use Stripe, Braintree, or another payment gateway, your SAQ requirements may be reduced โ but you still need to ensure your hosting environment meets the applicable requirements.
Assuming cloud providers handle everything: AWS, GCP, and Azure operate on a shared responsibility model. Even with their PCI DSS attestations, you're responsible for securing your workloads, configurations, and data within their environments.
Need PCI DSS Compliant Hosting?
Our European data centre (Poland) hosting gives you bare metal isolation, full root access, and a clearly defined compliance boundary. Chat with our engineering team about your PCI DSS requirements.
Speak to Our Team โRelated reading: UK GDPR Hosting Compliance Guide โข UK Data Centre Guide 2025 โข Linux Server Hardening Guide