Radium Technologies

Payment card compliance

PCI DSS Explained: A Guide for Irish Businesses

PCI DSS applies to any Irish business that stores, processes or transmits payment card data, no matter how small the volume. The soft landing is over. This guide covers which version applies, what the twelve requirements ask for, how card volume sets your validation route, and how much of your business you can keep outside the assessment.

7 minute read Compliance

Version 4.0.1 is the only active version. The 51 future-dated requirements became mandatory on 31 March 2025, so assessments now cover the full standard.

In short

Overview

PCI DSS is a contractual condition set by the card brands and enforced through your acquiring bank, which makes it a commercial obligation rather than a regulatory one. It applies to any Irish business that stores, processes or transmits payment card data, no matter how small the volume. It is not Irish or EU law.

The soft landing is over. Version 4.0.1 of the Payment Card Industry Data Security Standard is the only active version, and the requirements that spent years marked as future-dated best practice have been fully in force since 31 March 2025.

So the practical questions are narrow. Which version applies, what the twelve requirements ask for, how card volume sets your validation route, and how much of your business you can keep outside the assessment.

Scope

What Is PCI DSS and Who Needs to Comply in Ireland?

The Payment Card Industry Data Security Standard is a set of technical and operational controls for protecting payment card data, maintained by the PCI Security Standards Council on behalf of Visa, Mastercard, American Express, Discover and JCB.

It applies to every merchant and service provider that handles cardholder data, and there is no minimum transaction threshold. One card terminal in a reception area puts you in scope.

Two data types drive everything else. Cardholder data covers the primary account number, cardholder name, expiry date and service code. Sensitive authentication data covers full track data, the CVV and the PIN, and none of it may be stored once a transaction is authorised.

In practice, the businesses caught by this in Ireland include:

  • Retailers and hospitality venues running card terminals
  • E-commerce sites taking payments through a gateway or hosted checkout
  • Professional firms taking card details over the phone, often called MOTO payments
  • Clinics, practices and charities accepting card donations or deposits
  • Service providers that host, manage or support any of the above

The current standard

Which Version of PCI DSS Applies in 2026?

Version 4.0.1 is the only active version. Version 4.0 was retired on 31 December 2024, and the 51 future-dated requirements became mandatory on 31 March 2025, so assessments now cover the full standard with nothing left in a grace period.

Version 4.0.1 itself added no new requirements. It corrected formatting and clarified intent, and the requirements and testing procedures are published in full if you want the primary text rather than a summary of it.

The requirements that create real work for Irish SMEs are mostly the newer ones:

  • Requirement 8.4.2. Multi-factor authentication on every account that enters the cardholder data environment, including ordinary user accounts.
  • Requirement 8.3.6. Passwords of at least 12 characters, containing numeric and alphabetic characters, where the system supports it.
  • Requirement 6.4.3. An inventory of every script loaded into the customer's browser on a payment page, each one authorised and integrity-checked.
  • Requirement 11.6.1. A change and tamper detection mechanism on payment pages, reviewed at least weekly.
  • Requirement 12.3.1. A documented targeted risk analysis wherever the standard lets you set your own frequency for a control.

The framework

What Are the 12 PCI Requirements?

The twelve requirements sit under six control objectives covering network security, data protection, access control, monitoring and policy. The twelve headings have barely changed since version 3.2.1. What expanded is the detail underneath them, which now runs to several hundred sub-requirements.

Control objectiveRequirements covered
Build and maintain a secure network and systemsReq 1 network security controls, Req 2 secure configurations
Protect account dataReq 3 protect stored account data, Req 4 strong cryptography in transit
Maintain a vulnerability management programmeReq 5 protection from malicious software, Req 6 secure systems and software
Implement strong access control measuresReq 7 access by business need to know, Req 8 user identification and authentication, Req 9 physical access restriction
Regularly monitor and test networksReq 10 logging and monitoring, Req 11 security and vulnerability testing
Maintain an information security policyReq 12 organisational policies and programmes

Requirement 11 carries most of the recurring effort. It drives quarterly external scans by an Approved Scanning Vendor, internal authenticated scanning and, in larger environments, annual penetration testing.

Treating that as ongoing vulnerability management rather than an annual scramble is what separates a clean assessment from a messy one.

Validation routes

How Merchant Levels Set Your Validation Route

Your merchant level comes from annual card transaction volume, and it decides whether you self-assess or engage a Qualified Security Assessor. The card brands define the levels themselves, so the thresholds differ between them and the level you carry is the highest one any brand assigns you.

Since 25 April 2024 the brands no longer even agree on how many levels exist. Visa consolidated its levels 3 and 4 into a single level 3. Mastercard kept all four.

LevelVisaMastercardUsual validation route
1More than 6 million Visa transactions a yearMore than 6 million combined Mastercard and Maestro transactions a yearAnnual assessment producing a Report on Compliance
21 million to 6 million Visa transactions a yearMore than 1 million and up to 6 million transactions a yearAnnual self-assessment questionnaire
3Up to 1 million Visa transactions a year, including everything Visa previously called level 420,000 to 1 million e-commerce transactions a yearAnnual self-assessment questionnaire, scope set by the acquirer
4No longer usedFewer than 20,000 e-commerce transactions a yearAnnual self-assessment questionnaire, validation set by the acquirer

Almost every Irish SME sits in the lowest tier, which means self-validation. That does not reduce the security requirements at all. It changes who signs off the evidence, and your acquirer still decides what you file and when.

Self-assessment

Which Self-Assessment Questionnaire Fits Your Payment Setup?

The questionnaire you complete depends on how card data moves through your business, not on your size. Choosing the wrong one is the most common way a small merchant ends up answering hundreds of questions it never needed to touch.

  • SAQ A. Card-not-present merchants who have fully outsourced payment processing, typically through a redirect or a hosted page.
  • SAQ A-EP. E-commerce merchants whose site does not receive card data but can affect the security of the payment transaction.
  • SAQ B. Imprint machines or standalone dial-out terminals with no electronic cardholder data storage.
  • SAQ B-IP. Standalone IP-connected terminals with no electronic storage.
  • SAQ C-VT. Manual entry into a virtual terminal on an isolated workstation.
  • SAQ C. Payment application systems connected to the internet with no cardholder data storage.
  • SAQ P2PE. Merchants using a validated point-to-point encryption solution, the shortest questionnaire of the set.
  • SAQ D. Everyone else, plus all service providers eligible to self-assess.

One change catches e-commerce operators out. In January 2025 the Council removed requirements 6.4.3 and 11.6.1 from SAQ A and replaced them with an eligibility criterion.

Merchants embedding a provider's payment form in an iframe must now confirm their whole site is not susceptible to script attacks. Anyone running e-commerce IT support on a build carrying a long list of third-party tags should check that before assuming SAQ A still applies.

The cycle

How to Get PCI Accreditation Step by Step

PCI accreditation is really an annual validation cycle. It produces a signed Attestation of Compliance that you file with your acquirer, and it starts again twelve months later.

  • Map the cardholder data environment. Document every system, application, person and third party that touches card data, then confirm what can be removed from scope.
  • Confirm your route with your acquirer. Ask which level you are assigned and which questionnaire or report they expect, in writing.
  • Run a gap assessment. Compare current controls against the requirements that apply to your questionnaire, not against the full standard.
  • Remediate the gaps. Multi-factor authentication, password policy, logging and payment page controls are the usual offenders.
  • Book the scanning. Quarterly external scans by an Approved Scanning Vendor, with clean results in the quarter you attest.
  • Complete and submit. Sign the questionnaire and attestation, submit to the acquirer, and diary the next cycle.

Step two is the one businesses skip. Acquirers apply the brand rules differently, and a written answer from yours settles arguments that otherwise run for weeks.

The downside

What Happens If You Miss PCI Requirements?

Non-compliance usually costs nothing until something goes wrong, then the bill arrives all at once. Acquirers can apply monthly non-compliance fees, increase transaction charges or withdraw card acceptance entirely, and the terms sit in the merchant agreement you already signed.

After a confirmed breach the position is worse:

  • A forensic investigation by an approved investigator, paid for by the merchant
  • Card reissuance and fraud losses passed back through the acquirer
  • Loss of any safe harbour that compliant status would have provided
  • A parallel data protection investigation, entirely separate from the card brands
  • Contractual exposure where clients required proof of compliance

Make it routine

Building PCI Compliance Into Normal IT Operations

Most Irish businesses fail their validation on the same things every year. Undocumented scope, a questionnaire nobody checked against the actual payment flow, and controls that were switched on once and never evidenced again.

Treat it as a twelve-month operating cycle instead and the annual attestation becomes paperwork rather than a project. If card payments run through your systems, talk to our team about compliance and governance support and get your cardholder data environment mapped before the next attestation falls due.

Frequently asked questions

PCI DSS questions from Irish businesses.

Is PCI DSS a legal requirement in Ireland?

No. It is a contractual requirement imposed by the card brands and enforced through your acquiring bank rather than by Irish or EU legislation. In practice it is unavoidable, because accepting card payments means agreeing to it in your merchant agreement.

Do small businesses really need to comply?

Yes. There is no minimum transaction volume. A single terminal or a small online shop is still in scope, although the validation route is usually a short self-assessment questionnaire rather than an assessment by a Qualified Security Assessor.

How often do you need to validate compliance?

Validation is annual, and it produces a signed attestation filed with your acquirer. External vulnerability scans by an Approved Scanning Vendor run quarterly where your questionnaire requires them, so the cycle is really continuous rather than once a year.

Does using Stripe or a hosted checkout make you compliant?

It reduces your scope considerably, but it does not remove the obligation. You still complete the appropriate questionnaire, keep your site free of script-based risks and hold evidence that your payment provider is compliant.

What is a cardholder data environment?

It is every system, process and person that stores, processes or transmits cardholder data, plus anything connected to them that could affect their security. Defining it accurately is the first step of any assessment, and the biggest influence on cost.

How much does PCI compliance cost?

It depends almost entirely on scope. A fully outsourced e-commerce setup may need little beyond quarterly scanning and a short questionnaire, while a stored-card environment assessed by a Qualified Security Assessor becomes a multi-month project with remediation costs attached.

If card payments run through your systems, talk to our team and get your cardholder data environment mapped before the next attestation falls due.

Contact Us