Craig Marston
Chief Technology Officer, Paytia Limited
Southampton, United Kingdom
Craig leads the engineering side of Paytia as Chief Technology Officer. He specialises in PCI DSS compliance, secure payment capture, MOTO (Mail Order and Telephone Order) payment architecture, and the GDPR obligations that sit alongside taking card details by phone. Craig is a member of the Institute of Financial Accountants and the Institute of Public Accountants, and is based in the Southampton area.
View LinkedIn ProfileCredentials
- Chief Technology Officer, Paytia
- Member, Institute of Financial Accountants (since 2011)
- Member, Institute of Public Accountants (since 2015)
- PCI DSS and GDPR specialist
Areas of Expertise
Articles by Craig (92)

Is PCI Compliance a Legal Requirement in the UK?

How to Pass a PCI Compliance Scan

How to Take Card Payments Over the Phone (UK)

DTMF Masking: How It Works and How It Cuts PCI Scope

Card Tokenization in Call Centres: Setup & Fixes

Virtual Terminal: The PCI-Secure Guide for Contact Centres

What Are SMS & Text-Message Payments? A Plain-English Guide

Claims Payment Integration — Connect Your System

Cost of PCI Compliance in 2026: The Real Numbers

Detokenization Explained — How Tokens Become PANs

Fraud Detection Tools Compared — What Contact Centres Use

Hidden Costs of PCI Non-Compliance — Fines & Breaches

HIPAA Fines for Payment Processing Breaches — Real Cases

HIPAA Payment Processor Checklist — What to Look For

HIPAA + PCI Compliance for Healthcare Contact Centres

How to Reduce PCI Compliance Cost in Practice

How to Set Up PCI-Compliant IVR Payments

Insurance Company Fraud Detection — Tools and Tactics

Moving from SAQ D to SAQ A — Pinnacle Group Case Study

P2PE vs Tokenization — Which Reduces PCI Scope More

Payment Fraud Red Flags — What Agents Should Watch For

PCI Audit Cost Broken Down — Every Fee, Every Hour

PCI Compliance for Insurance Claims — What You Need to Know

PCI Cost: In-House vs Outsourced — Real Numbers Compared

All 9 PCI SAQ Levels Explained — A to D Compared

SAQ A Controls Explained — All 22 Requirements

SAQ A Documentation Checklist — What Your Auditor Wants

SAQ A Eligibility Checklist — Do You Qualify?

SAQ A vs SAQ A-EP — Which One Are You?

SAQ D-Merchant Explained — All 329 Controls
Showing the 30 most recent of 92 posts.
Ready to take secure payments?
Book a demo with our team. We'll show you DTMF masking live, talk through PCI DSS scope reduction, and put together pricing based on your call volume.
Trusted by law firms, insurers, healthcare providers and regulated businesses worldwide. Learn more about Paytia
