
Update: We originally published this article in 2010 with guidance about PCI compliance for online businesses. Payment technology and security requirements have changed significantly since then, so we updated the article to reflect current PCI DSS guidance for eCommerce merchants.
Accepting card payments comes with responsibilities for protecting customer payment information. Using a hosted storefront or third-party payment processor can reduce how much cardholder data a merchant handles directly, but it does not automatically remove every PCI compliance obligation.
The exact requirements depend on how the business accepts payments, where payment-page elements originate, whether cardholder data enters the merchant’s systems, and what the merchant’s acquiring bank or payment brand requires.
What Is PCI Compliance?
PCI compliance refers to meeting the applicable requirements of the Payment Card Industry Data Security Standard, commonly called PCI DSS.
The standard applies to organizations that store, process, or transmit cardholder data. It also affects merchants that outsource payment processing because they remain responsible for selecting compliant providers and understanding which security responsibilities belong to each party.
The PCI Security Standards Council develops and maintains the standard, but a merchant’s acquiring bank, payment processor, or payment brand generally determines how the business must validate compliance.
Does PCI DSS Apply to Every eCommerce Merchant?
PCI DSS generally applies when a business accepts payment cards, even when another company handles the actual payment processing.
A merchant that completely outsources payment processing may have fewer requirements applying directly to its environment. However, the merchant may still need to:
- Confirm that its payment provider maintains PCI DSS compliance
- Maintain agreements describing the provider’s responsibilities
- Review the provider’s compliance status at least annually
- Understand which security responsibilities remain with the merchant
- Complete the appropriate compliance validation process
The PCI Security Standards Council specifically states that outsourcing payment processing does not eliminate the merchant’s responsibility to protect account data through its third-party relationships.
What Is PCI DSS 4.0.1?
PCI DSS 4.0.1 is the current version of the PCI Data Security Standard. Several future-dated requirements under PCI DSS 4.0.1 became effective on March 31, 2025. These include additional protections intended to address risks involving eCommerce payment pages, scripts, authentication, vulnerability management, and other security concerns.
Merchants should use current PCI Security Standards Council materials rather than relying on older checklists or articles because the requirements and validation documents have changed over time.
What Is a Self-Assessment Questionnaire?
A Self-Assessment Questionnaire, or SAQ, is a PCI compliance validation document designed for certain types of merchants and service providers.
The correct SAQ depends on how the business accepts payments and which parts of the payment process touch its systems. Possible questionnaires for eCommerce environments may include SAQ A, SAQ A-EP, or another form.
A merchant should not select an SAQ based only on the fact that it uses a third-party processor. It must meet all eligibility requirements for that questionnaire. The PCI Security Standards Council recommends confirming the correct validation method with the organization managing the merchant’s compliance program, such as its acquiring bank or payment brand.
How Does Hosted Checkout Affect PCI Scope?
A hosted checkout sends the customer to a payment page operated by a PCI-compliant third-party provider.
Because the provider hosts the payment page, the merchant’s website may handle less cardholder data directly. That can reduce the merchant’s PCI scope, but the merchant still needs to protect its website and the mechanism that directs customers to the provider.
For example, an attacker who alters a payment redirect could send customers to a fraudulent payment page. PCI guidance therefore includes requirements related to access controls, security patches, vulnerability management, and protection of redirect mechanisms.
How Are Embedded Payment Forms Different?
Some merchants embed a payment provider’s form directly into their own checkout page, often through an iframe.
For SAQ A eligibility, all payment-page elements must originate from PCI DSS-compliant service providers, and the merchant must meet the questionnaire’s remaining eligibility requirements. An embedded payment form may also require the merchant to confirm that its website is protected from script-based attacks that could affect the payment process.
This matters because malicious scripts can alter a checkout experience, capture information entered by customers, or interfere with the connection to the payment provider.
Merchants using an embedded form should follow the provider’s implementation instructions and confirm with their acquiring bank or payment brand which SAQ applies.
Why Third-Party Scripts Matter
An eCommerce checkout page may load scripts from analytics tools, advertising platforms, chat applications, personalization software, tag managers, and other third-party services.
Each added script can affect the security of the page. Merchants should understand:
- Which scripts run on payment-related pages
- Who owns and maintains each script
- Whether every script is still necessary
- How changes to scripts are authorized
- How the business detects unexpected changes
- Whether applications can access payment-page information
PCI DSS 4.0.1 guidance gives particular attention to protecting eCommerce environments from attacks involving scripts. The requirements that apply will depend on the merchant’s payment implementation and validation method.
Does Using Shopify or Another SaaS Platform Make a Merchant Compliant?
No platform automatically makes every merchant PCI compliant.
A hosted eCommerce platform may manage much of the underlying hosting, infrastructure, platform security, and payment technology. However, the merchant remains responsible for areas such as:
- Account access
- Strong passwords and authentication
- User permissions
- Connected applications
- Custom code
- Payment-provider configuration
- Employee security practices
- Third-party service providers
- Compliance validation
The division of responsibility is one reason merchants should understand the difference between hosted and self-managed technology. For more context, read Ordoro’s guide to SaaS vs. self-hosted eCommerce.
How Should Merchants Evaluate a Payment Provider?
Before selecting a payment processor or checkout provider, ask:
- Is the provider currently PCI DSS compliant for the services being offered?
- Can it provide appropriate evidence of compliance?
- Which payment functions does it handle?
- Will customers leave the merchant’s website to pay?
- Will the provider’s form appear within the merchant’s website?
- Does any cardholder data pass through the merchant’s servers?
- Which security tasks remain the merchant’s responsibility?
- How will the provider communicate changes to its compliance status?
- What happens if the provider experiences a security incident?
- Which SAQ does the provider expect the merchant to complete?
The merchant should document the answers rather than relying only on general claims such as “PCI ready” or “secure checkout.”
Keep the Rest of the Website Secure
Outsourcing payment processing does not make the merchant’s website irrelevant to payment security.
An attacker may target administrator accounts, plugins, themes, redirect links, scripts, integrations, or outdated software. Merchants should follow appropriate security practices, including:
- Applying software and security updates
- Requiring strong, unique passwords
- Using multifactor authentication where available
- Limiting administrative access
- Removing unused accounts and applications
- Monitoring changes to important pages
- Maintaining secure backups
- Reviewing third-party integrations
- Scanning applicable systems for vulnerabilities
Some eCommerce merchants may need external vulnerability scans performed by a PCI Approved Scanning Vendor. The requirement depends on the environment and applicable SAQ, so merchants should confirm their obligations with their compliance-accepting organization.
Who Can Tell a Merchant Which Requirements Apply?
A merchant’s exact requirements may depend on its payment volume, acquiring bank, payment brands, payment setup, service providers, and technical environment.
For a definitive answer, contact:
- The acquiring bank
- The payment processor
- The applicable payment brand
- A Qualified Security Assessor
- A PCI Approved Scanning Vendor, when scanning is required
The PCI Security Standards Council provides the official standards, questionnaires, FAQs, and lists of qualified professionals.
This article provides general educational information and should not replace guidance from a qualified security professional or the organization responsible for accepting the merchant’s compliance validation.
PCI Compliance FAQs
Is PCI compliance legally required?
PCI DSS is an industry security standard rather than a government law. However, card brands, acquiring banks, and payment-processing agreements can require merchants to comply. Separate privacy, data-security, and breach-notification laws may also apply.
Does a small eCommerce business need PCI compliance?
Yes, PCI DSS can apply regardless of business size. The validation process and specific requirements may differ based on the merchant’s payment environment and the rules established by its acquiring bank or payment brand.
Does using a third-party payment processor eliminate PCI requirements?
No. It may reduce the merchant’s PCI scope, but the merchant must still confirm the provider’s compliance, manage shared responsibilities, protect its own environment, and complete any required validation.
What is the difference between SAQ A and SAQ A-EP?
SAQ A generally applies to eligible merchants that outsource account-data functions to compliant third parties and do not electronically store, process, or transmit account data themselves. SAQ A-EP may apply when parts of the payment page originate from the merchant’s website. All eligibility requirements must be met before using either questionnaire.
How often must merchants validate PCI compliance?
The required schedule depends on the acquiring bank, payment brand, merchant level, and validation method. Some activities occur annually, while certain vulnerability scans may be required at least quarterly. Merchants should confirm the schedule with the organization accepting their compliance documentation.
Can Ordoro help a business become PCI compliant?
Ordoro is not a PCI compliance consultant or payment processor. Ordoro helps merchants manage inventory, orders, shipping, dropshipping, and fulfillment across supported sales channels.
Connect the Systems Around Your Store
Payment security is one part of an eCommerce technology stack. Merchants also need reliable connections between their storefronts, marketplaces, inventory, orders, shipping carriers, suppliers, and fulfillment workflows.
Ordoro connects with major eCommerce platforms, marketplaces, carriers, accounting systems, and other operational tools. See Ordoro’s eCommerce Integrations
Ordoro connects with major eCommerce platforms and helps merchants manage inventory, orders, shipping, and fulfillment from one place. See How Ordoro Works
Already evaluating software for your business? Book a Demo