Skip to content

PCI DSS compliance in UK public sector procurement

PCI DSS produces no certificate. A supplier can send you an Attestation of Compliance, and the two details that decide whether it means anything are the date of the assessment and the environment it covers.

Evidence requests for PCI compliance in UK public sector procurement usually go wrong in one of two ways. Either they name a document that does not exist, which sends the supplier back to ask what you meant, or they arrive on a contract with no card payments anywhere in it, which returns an answer about a payment environment your service never touches. Both cost time at the stage of a procurement where there is least of it.

When is PCI compliance in scope for a UK public sector contract?

PCI compliance is in scope for a UK public sector contract whenever the service being procured handles card payment data at any point. Payment portals, parking and permit charges, licensing fees, course and venue bookings, and anything that takes a card on a council or agency website all sit inside that boundary.

Plenty of public sector digital work sits outside it. A case management system, an internal platform, a website with no transactional element, or hosting for a service with no payment leg will produce nothing useful from a PCI question, because there is no cardholder data environment to assess.

The middle case is the one worth a conversation. Where a separate payments provider handles the transaction, ask whose systems the card data actually passes through before deciding whose attestation you need. The supplier building the service and the organisation processing the payment are often not the same company, and the attestation you want belongs to whichever of them holds the data.

Does a supplier get a PCI DSS certificate?

No. Validating against PCI DSS produces no certificate, and the PCI Security Standards Council issues none. A Qualified Security Assessor carries out the assessment and writes a Report on Compliance, which is the full assessment document. The Attestation of Compliance is the shareable summary of that assessment, and it is the document a buyer should ask for. Smaller or eligible merchants validate using a Self-Assessment Questionnaire instead, and the current forms sit in the PCI Security Standards Council document library.

What to ask a supplier for, and in what order

Start by confirming that card data reaches the service you are buying. Establishing that first saves the supplier assembling evidence you were never going to use, and it stops a compliant answer about the wrong system reading as assurance.

Then ask for the Attestation of Compliance by name. A request for “PCI DSS certification” invites a paragraph of prose in a bid response instead of a document, and prose is not evidence. Naming the document sets a standard the supplier either meets or does not.

Ask for two things alongside it: the date of the assessment, and a description of the environment that assessment covered. Neither is an unreasonable ask, and a supplier who validates properly will have both to hand.

Put all of this at request for information stage. Evidence requests asked early are answered plainly. Asked after a supplier has invested in the bid, the same question tends to attract a more accommodating answer than the facts support. There is no need to ask for the Report on Compliance itself, and a supplier will not send it.

What is an Attestation of Compliance?

An Attestation of Compliance is the summary document produced at the end of a PCI DSS assessment, written to be shared outside the organisation that was assessed. It names the entity assessed, and it is dated. A buyer who asks for a PCI DSS Attestation of Compliance is asking for the only document in the process designed to travel.

Read the date and the covered environment before you score it

Scope is the check buyers most often skip, and it is the one that decides whether the document is relevant at all. An attestation covers a defined environment, which can be one payment channel of a business while the service you are procuring sits entirely outside it. A retail till estate and a citizen-facing payment portal are different environments, and an attestation over the first says nothing about the second.

Match the assessed environment against the service named in your contract. If the two do not line up, you have a genuine document that is evidence about something else, which is a harder thing to spot than a missing one.

An attestation describes a point in time rather than a continuing state, so a signature from eighteen months ago tells you about the estate as it stood then. Ask when the next assessment falls due, and whether anything in the assessed environment has changed since the last one.

What 31 March 2025 changed about older attestations

Version 4.0.1 of the standard is current. Version 4.0 introduced 51 future-dated requirements, and the PCI Security Standards Council made those mandatory on 31 March 2025. An attestation predating that date was assessed against a lower bar, because the assessor was not yet obliged to test against them.

Ask when reassessment is due. The document in front of you records the standard as it stood on the day of the assessment, and on a multi-year contract what the next assessment will cover carries more weight than what the last one did.

Card payments are one part of the evidence set for a public sector digital or secure hosting award, and the rest of it, along with how to verify each certificate on a public register, is covered in our guide to which security accreditations to ask for.

Axistwelve validates to PCI DSS and provides its Attestation of Compliance, with the assessment date and the environment it covers, on request.

Frequently asked questions

What is a Report on Compliance?

The Report on Compliance is the full PCI DSS assessment document, written by a Qualified Security Assessor. It records the assessment in detail and is not the document a supplier sends out to buyers. The Attestation of Compliance is the summary written to be shared.

How long is an Attestation of Compliance valid?

An Attestation of Compliance carries no validity period, because it records the assessed environment as it stood on the assessment date. Read the date on the document and treat anything since as unevidenced.

Who qualifies a Qualified Security Assessor?

The PCI Security Standards Council qualifies Qualified Security Assessor companies and publishes the current list. A buyer can check that the firm named on an attestation appears on it.