Skip to content

Global · Applies by law

PCI DSS compliance

Payment Card Industry Data Security Standard

Anyone who stores, processes or transmits cardholder data, including via a hosted payment page you embed.

The context

What it actually asks of you

PCI DSS is contractual rather than statutory, but the consequences of getting it wrong, fines passed down by your acquirer, or losing card processing entirely, are as real as any regulator's. It applies to anyone who stores, processes or transmits cardholder data.

For SaaS companies the entire question is usually scope. Using Stripe, Adyen or a similar provider dramatically reduces what you are responsible for, but the reduction depends on integration mechanics: a full redirect, an iframe, and a JavaScript element that renders inside your DOM produce three different Self-Assessment Questionnaire types with materially different requirements.

PCI DSS v4.0 also introduced specific requirements for payment pages that most teams have not yet actioned, notably script inventory and integrity monitoring for any page that takes card data.

The common mistake

What teams get wrong.

Using Stripe or Adyen reduces your scope; it does not remove it. Which Self-Assessment Questionnaire applies depends on exactly how the payment form touches your page, and getting that wrong invalidates the whole assessment.

Our scope

What we do for PCI DSS.

  1. 01Scope definition and correct SAQ type selection
  2. 02Cardholder data flow mapping
  3. 03Network segmentation review to keep scope small
  4. 04Control implementation against the applicable requirements
  5. 05Evidence pack and SAQ completion support
  6. 06Coordination with your acquirer or QSA

innsecs provides security and compliance services, not legal advice, and we are not a law firm. We build the technical and organisational measures, evidence and processes these obligations require, and work alongside your counsel on legal interpretation.

Questions

PCI DSS FAQ

For a SaaS company embedding a hosted payment field it is usually SAQ A or SAQ A-EP, and the difference matters, A-EP has substantially more requirements. The determining factor is whether your page can affect the security of the payment transaction. We assess the actual integration rather than the marketing claim.

They are telling you their platform is compliant, which is not the same as yours. Your obligations cover your integration, your scripts, your network segmentation and your vendor management. Providers are clear about this in their documentation; it is simply easy to misread.

Most SaaS companies at this scale self-assess with a SAQ and do not need a Qualified Security Assessor. Above certain transaction volumes, or where your acquirer requires it, a QSA-led Report on Compliance becomes necessary. We will tell you which side of the line you are on.

Find out whether PCI DSS binds you.

Bring your product, your users and your markets. We will tell you what applies, what does not, and what it takes to close the gap.

Book a scoping callsecurity@innsecs.com

No sales sequence. A scoping call and a written proposal cost nothing.