Are card payments a material part of business operations but PCI DSS and insurance feel like different languages? This concise guide explains how PCI DSS and cardholder data handling affect cyber insurance for English SMEs, what insurers commonly expect for a successful claim, and exactly what evidence to keep to prove controls, written for non-technical owners and directors.
Key takeaways: what to know in one minute
- PCI scope and card data directly affect cyber premiums and cover: insurers assess exposed cardholder data and the merchant's PCI scope when pricing and when handling claims.
- Insurers often expect reasonable PCI controls rather than formal certification; lack of basic controls can lead to reduced payout or repudiation.
- A breach involving cardholder data triggers both insurance and GDPR obligations; documented forensic and notification steps are essential.
- Keep clear evidence (logs, SAQ, PSP contracts, forensic reports, remediation plan) to support any claim.
- Prioritise security over relying on insurance: in many card-breach scenarios, good technical controls prevent losses insurers might otherwise exclude.
How PCI DSS & card data affect cyber insurance
Insurers view cardholder data as a high-severity exposure. PCI DSS & card data affect cyber insurance in three principal ways:
- risk assessment and underwriting: insurers ask about merchant level, scoping, third-party payment processors (PSPs), and historical incidents; higher exposure typically means higher premium and stricter conditions; many will request documentation such as SAQ, network diagrams or evidence of segmentation;
- coverage wording and sub-limits: policies may include sub-limits for card-related costs (forensic, fines, card-replacement) or treat card-related liability differently; some wordings explicitly limit coverage for card fraud where contractual obligations with the acquirer or card schemes apply;
- claims handling and proof: insurers expect demonstrable controls and an incident response process—absence of evidence can hinder payout or lead to contributions.
Relevant UK authorities: the PCI Security Standards Council, ICO (GDPR) and the NCSC provide guidance that insurers commonly reference.
How underwriters translate PCI posture into premium
Underwriters typically map PCI posture to expected loss frequency and severity: a merchant that stores or processes cardholder data in-house and does not segment or log access will present higher potential loss than a merchant using a fully outsourced PSP where no card data is stored. Questions underwriters often ask include merchant level, SAQ type, whether the business uses tokenisation, and details of network segmentation.
Do insurers require PCI compliance for payout?
Short answer: rarely is an insurer looking for a certificate of compliance as a binary requirement; they expect evidence of reasonable controls and adherence to PCI DSS where applicable.
Policies differ. Typical insurer positions include:
- requirement for reasonable care: many policies include a clause that the insured must maintain reasonable security measures. Demonstrable PCI controls often satisfy this.
- express warranties or conditions precedent: some cyber policies include conditions that certain controls must be in place and evidenced at inception or on renewal; failure may void cover for related losses.
- exclusions for wilful non-compliance or criminal acts: deliberate or reckless disregard for standards (including PCI) can be excluded.
Examples of insurer behaviour in practice
- many insurers accept a completed SAQ and network diagram as evidence of controls rather than a formal audit report;
- for higher-risk merchants (Level 1/2), insurers may request an external Qualified Security Assessor (QSA) report or an Attestation of Compliance (AOC);
- if card data is held incorrectly (unencrypted storage on a public-facing server) and a breach occurs, insurers may investigate whether the insured met the policy's security obligations, this can materially affect claim outcome.
This is general information and policy wordings vary; consult an insurance broker for wording interpretation.

Assessing breach scenarios involving cardholder data and GDPR
A card-data breach often triggers two parallel processes: incident response/forensics for the card schemes and insurer, and GDPR obligations under UK data protection law (ICO). Typical steps and considerations:
- immediate containment: isolate affected systems and follow an incident response plan; preserve logs and evidence for forensic analysis.
- forensic investigation: use a PCI-experienced forensic firm to determine scope (which PANs, track data, CVV), insurers normally require a forensic report to validate a claim.
- notification: if personal data (which includes cardholder name and PAN linked to the individual) is compromised, the ICO's rules on reporting apply; notification timelines (72 hours for controller) depend on the severity and likelihood of risk to individuals. Refer to ICO guidance.
- card scheme and acquirer engagement: notify the acquiring bank and card schemes as required; they may require specific remediation steps to restore processing.
- insurance notice: notify the insurer promptly and follow policy requirements for early notification; delays or uncontrolled remediation may jeopardise cover.
Scenario mapping: likely insurer expectations by breach type
- malware on POS capturing PANs: insurer expects forensic report, evidence of patching, and PSP/acquirer notification; lack of segmentation or unpatched systems may lead to contested claims.
- stolen database with PANs but encrypted keys stored on separate HSM: insurer will examine key management and encryption strength; well-documented key handling supports the claim.
- charges disputed/chargebacks: insurers may cover costs related to chargeback fees, legal defence and card replacement depending on wording; evidence from acquirer and card scheme communications is crucial.
Practical PCI controls insurers expect from UK SMEs
Insurers generally expect pragmatic, proportionate controls mapped to the merchant's PCI scope. For small merchants (Levels 3–4), common insurer expectations include:
- use of a reputable PSP so the SME does not store PANs locally; evidence: contract with PSP and statement that card data is out of scope for the SME.
- if any cardholder data is stored or processed in-house: segmentation of payment systems, strong access controls, logging, and encryption at rest and in transit.
- completion of the appropriate Self-Assessment Questionnaire (SAQ) with supporting evidence (screenshots, policies).
- regular patching, anti-malware on endpoints that touch card data, and documented backups.
- a tested incident response plan and retention of a PCI-capable forensic partner.
Mapping PCI DSS requirements to insurer-friendly evidence
Below is a practical mapping for common PCI requirements and the evidence insurers like to see.
| PCI DSS area |
Practical control for SMEs |
Evidence insurers typically request |
| Build and maintain secure network (Req 1) |
Segment payment systems and limit inbound access |
Network diagram, firewall rules, VLAN config screenshots |
| Protect cardholder data (Req 3) |
Use tokenisation / encryption; do not store PAN unless necessary |
Encryption config, key management notes, PSP contract |
| Maintain access controls (Req 7–8) |
MFA for admin, role-based access, unique IDs |
Access logs, MFA rollout evidence, user access matrix |
| Logging and monitoring (Req 10) |
Centralised logs, retention policy, alerting for suspicious events |
Log retention policy, SIEM alerts, sample logs |
| Incident response (Req 12) |
Incident plan, forensic firm contacts, breach runbooks |
IR plan, incident table-top records, QSA/forensic contacts |
This table is indicative; the exact evidence an insurer requests depends on the policy wording and underwriting notes.
PCI claim workflow for a card breach
PCI breach to claim: simplified workflow
👀 Detect → 🔒 Contain → 🧪 Forensic → 📣 Notify → 🧾 Claim → 🔁 Remediate
(Preserve logs, inform acquirer & insurer, keep written timelines)
When cyber security trumps insurance for card breaches
Insurance is a risk transfer tool but not a substitute for prevention. There are situations where investment in cyber security measures will be more effective than relying on insurance:
- when business continuity is critical: a breach causing prolonged payment outages can inflict reputational and cashflow damage that insurance may not fully recoup; robust segmentation and failover systems reduce downtime.
- where contractual penalties or merchant termination risk exist: acquirers and card schemes may impose remediation or remove processing privileges despite insurance cover. Preventing breaches preserves merchant relationships.
- when repeated poor security behaviour exists: insurers may decline renewals or apply prohibitive premiums. Improving controls reduces both premium and likelihood of claim.
Cost‑benefit considerations
Security investments such as using a certified PSP, enabling tokenisation, and basic network segmentation often cost less than uninsured business interruption and the operational burden of post-breach remediation. For many SMEs, a modest security spend combined with an appropriate cyber policy gives the best overall risk outcome.
Checklist: evidence to prove PCI DSS & card security
This checklist lists practical documents and artefacts insurers usually request when a claim involves cardholder data. Keep digital copies in a secure, access‑controlled location.
- SAQ or AOC (whichever applies) with completion date and signer.
- Network diagram showing segmentation between payment systems and corporate networks.
- Contract and evidence of scope with PSP/acquirer (statements that card data is tokenised or not stored by SME).
- Access control evidence: user list, role definitions, MFA screenshots, recent access reviews.
- Patch management and endpoint security records (dates of recent patches for POS or servers).
- Encryption and key management descriptions for any stored card data.
- Logs and retention policy: sample logs, evidence that logs were preserved at breach discovery.
- Incident response plan and contact list for forensic provider; table-top exercise notes if available.
- Communications with acquirer/card schemes and any regulatory notices (ICO, police reports).
- Remediation plan and proof of fixes (patch IDs, configuration changes).
Maintaining these items reduces delays and strengthens the insurer’s ability to validate the event quickly.
Analysis: advantages, risks and common mistakes
✅ Benefits of aligning PCI DSS & insurance
- reduced premium and quicker claim outcomes where controls are proven;
- faster acceptance by acquirers and card schemes during remediation;
- clearer obligations and evidence trail if an incident occurs.
⚠️ Risks and mistakes to avoid
- assuming PSP absolves all responsibility: contract wording matters—ensure the PSP's scope is explicit;
- failing to preserve logs at discovery: loss of logs often leads to denied or limited claims;
- not reading policy wordings: silent exclusions or conditions precedent can surprise SMEs during claims.
Frequently asked questions
What is PCI DSS and why does it matter for insurance?
PCI DSS is a security standard for organisations handling cardholder data. Insurers use PCI posture to assess risk and may request evidence of controls during underwriting or claims.
Will an insurer pay if a merchant is non-compliant with PCI?
It depends on the policy wording and whether non-compliance was wilful or negligent. Many insurers require proof of reasonable security, outright negligence can jeopardise cover.
Can using a PSP remove PCI scope entirely?
Using a fully outsourced PSP can reduce the SME's PCI scope but does not automatically eliminate all obligations; the merchant must still validate scope (SAQ A, A‑EP depending on integration).
What documents should be given to the insurer after a card-data breach?
Immediate documents: incident timeline, forensic engagement confirmation, SAQ/AOC, PSP/acquirer communications, preserved logs and screenshots showing containment steps.
How does GDPR interact with a card-data breach?
Cardholder data linked to an identifiable person is personal data. A breach may trigger ICO notification requirements and potential regulatory action; insurers often cover notification and regulatory defence costs subject to policy terms.
Are fines from card schemes covered by cyber insurance?
Coverage varies. Some policies exclude contractual penalties or fines imposed by card schemes; others may cover regulatory defence costs. Check policy wording and speak to a broker.
Should SMEs get a QSA audit to secure insurance cover?
QA audits are typically for higher-level merchants (Level 1). For many SMEs, documented SAQs and practical controls suffice. Underwriters may request a QSA for higher-risk processing.
Your next step:
- Review merchant processing: confirm whether cardholder data is stored or fully outsourced and gather the PSP/acquirer contract.
- Collect evidence: SAQ/AOC, network diagram, access logs and incident response plan into a single secure folder for quick production.
- Speak to an insurance professional: share evidence and policy wording to clarify cover for card breaches and any sub-limits or conditions.