Industry guide

PCI DSS certification for e-commerce

E-commerce certification is a scope-management exercise: your platform choice decides your SAQ type, and your SAQ type decides your workload. Get the architecture right and certification is paperwork; get it wrong and it's a project.

Your platform decides your path

Hosted checkout, iframes, or JavaScript-tokenized integrations keep card data off your servers — usually SAQ A, the lightest questionnaire. Custom checkout code that touches PAN pushes you toward SAQ D, the full requirement set. When replatforming, ask the PCI question before the engineering decision, not after.

Which SAQ will you file?

Most hosted-platform merchants file SAQ A; merchants whose sites affect payment-page security file A-EP; everyone else lands in D. Read our SAQ type guide before you guess — one stored PAN in a log file can move you from A to D.

Physical stores: the P2PE shortcut

If you also take cards in person, validated point-to-point encryption (P2PE) terminals collapse in-store scope dramatically — the single highest-ROI PCI investment most retailers make. Confirm the solution is on the PCI SSC's validated P2PE list.

The seasonal problem

Retail staff turnover breaks PCI controls: shared logins, skipped training, unpatched terminals. QSAs test for it. Unique IDs, documented training, and terminal inventories aren't paperwork — they're findings avoided during fieldwork.

Questions

We're a small shop on a hosted platform — do we need a QSA?

Almost certainly not for validation — you're likely a Level 4 merchant filing a SAQ. Your acquirer confirms; don't buy a ROC nobody asked for.

Does P2PE eliminate PCI entirely?

No — it dramatically reduces scope, but you still validate annually and still own policies, training, and service-provider oversight.

Get quotes from QSAs that know your industry

Tell us your environment once — we’ll match QSA companies with experience in it. Free, two minutes.

Get a free quote

← All QSA companies  ·  Cost guide