At long last, we've finished our thorough research into PCI Compliance! The end result is that Stockashops with PayPal don't need to worry about it (unless you use their virtual terminals). Stockahops with SagePay which don't use their virtual terminal have to fill in a single questionnaire. Companies which use a virtual terminal or in-store dialup terminal have more complex requirements. The guide explains it all, so please see our comprehensive PCI Compliance guide.