PCI Compliance for E-Commerce: Your Complete Guide for 2026

Published on

Updated on

Key Takeaways
  • PCI compliance for e-commerce applies to every online store that accepts card payments, regardless of platform, size, or transaction volume.
  • Most e-commerce merchants fall into SAQ A, SAQ A-EP, or SAQ D, depending on how much of the checkout flow touches their own servers.
  • Fully outsourced checkouts (Shopify Payments, Stripe Checkout, hosted payment pages) usually qualify for SAQ A, the lightest tier.
  • Quarterly ASV vulnerability scanning is mandatory for any merchant outside the lowest-risk SAQ A tier.
  • Non-compliance risk isn't just a fine; it's higher processing fees, breach liability, and potential loss of your ability to accept cards.

PCI compliance for e-commerce isn’t optional, and it doesn’t scale down for small stores. If you accept credit or debit cards online, the Payment Card Industry Data Security Standard (PCI DSS) applies to you today, not once you hit a certain revenue threshold. The standard is set by the major card brands (Visa, Mastercard, American Express, Discover, JCB) and enforced through your acquiring bank or payment processor, which means non-compliance shows up as real business risk, not an abstract audit checkbox.

What actually trips up most online retailers isn’t the concept of PCI compliance; it’s figuring out which specific requirements apply to their setup. A Shopify store on Shopify Payments carries a very different compliance burden than a custom-built checkout that touches its own servers. This guide walks through the parts of PCI DSS for online stores that hold true no matter what platform you run, so you know exactly where you stand before diving into platform-specific steps.

Key Definitions

PCI DSS: PCI DSS (Payment Card Industry Data Security Standard) is the security framework that all merchants, processors, and service providers must meet to handle cardholder data.

SAQ (Self-Assessment Questionnaire): The annual compliance validation form. Which version you use depends on how your checkout is architected.

ASV (Approved Scanning Vendor): A company certified by the PCI Security Standards Council to run the external vulnerability scans required under most SAQ types. You can read more in our breakdown of what an ASV scan actually checks.

Cardholder Data Environment (CDE): Any system, network segment, or process that stores, processes, or transmits card data.

Merchant Level: A classification (1–4) based on annual transaction volume that determines how you validate compliance, self-assessment versus a formal audit.

What Is PCI Compliance for E-Commerce, and Why Does It Apply to You?

PCI compliance for e-commerce means meeting PCI DSS requirements for any online store that accepts card payments; there is no size or revenue exemption, only differences in how you validate it.

Many people think PCI DSS is something only large retailers need to worry about. In practice, your merchant level (based on annual card transaction volume) only changes how you prove compliance via self-assessment or a formal Qualified Security Assessor (QSA) audit, not whether you need to comply. Even a Level 4 merchant processing a few hundred transactions a month is contractually obligated by their payment processor to maintain PCI compliance. For a deeper look at where the SAQ and QSA paths diverge, see our comparison of an ASV scan versus a QSA assessment.

Not Sure Which SAQ Applies to You?

Get a free assessment of your e-commerce checkout architecture and find out your exact SAQ type in minutes.

Which SAQ Type Applies to Your Online Store?

Your SAQ type depends on how much of the checkout flow runs through your own servers; fully outsourced checkouts usually qualify for SAQ A, while checkouts that touch your own code need SAQ A-EP or SAQ D.

Choosing the right SAQ for e-commerce is the single decision that determines your entire compliance workload:

  • SAQ A: Checkout is fully outsourced (redirect or iframe to a PCI-compliant processor like Stripe, Shopify Payments, or PayPal). Your servers never touch card data. No ASV scan required.
  • SAQ A-EP: You use a hosted payment page, but your own site’s code influences or controls that page (common with custom checkouts using a controlled iframe). Quarterly ASV scanning is required; see our guide on PCI ASV scan requirements for what’s included.
  • SAQ D: Card data is stored, processed, or transmitted directly on your own systems. The most demanding tier, requiring the full range of PCI DSS controls, including quarterly external scanning.

 

If you’re unsure which applies, your acquirer or ASV can confirm it based on how your checkout is built; this is a common step we walk merchants through directly.

The E-Commerce PCI Compliance Checklist: Core Requirements

Every online store, regardless of SAQ type, should never store sensitive authentication data, use a compliant payment processor, patch software regularly, scan quarterly where required, and submit its SAQ annually.

A working e-commerce PCI compliance checklist looks like this:

  1. Never store sensitive authentication data: full magnetic stripe data, CVV, or PIN after transaction authorisation. This is prohibited across every SAQ type.
  2. Use a compliant payment processor instead of building your own card storage and processing logic.
  3. Keep software and plugins patched. Outdated cart plugins and extensions are one of the most common breach vectors for online retailers.
  4. Run quarterly ASV scans if your SAQ type requires them; see how often scanning actually needs to happen in our guide to PCI ASV scan frequency.
  5. Submit your SAQ annually to your acquiring bank or processor.
  6. Maintain a written information security policy, even as a small merchant; this is part of every SAQ type and often gets skipped.

PCI DSS for Online Stores, by Platform

Your e-commerce platform determines how you meet PCI requirements, not whether they apply; hosted checkout platforms generally simplify compliance, while custom builds carry more of the burden themselves.

PCI DSS for online stores plays out differently depending on your tech stack:

Does Your Store Need Quarterly ASV Scanning?

Confirm your scan requirement based on your platform and payment setup before your next compliance deadline.

How to Choose the Right ASV for Your PCI Compliant Online Store

Look for an ASV that's certified by the PCI Security Standards Council, understands e-commerce-specific architecture, and can work around your scanning windows without disrupting checkout uptime.

Keeping a PCI compliant online store long-term means treating quarterly scanning as an operational habit, not a one-off task. Not every ASV is built for e-commerce specifically; cart integrations, CDN configurations, and peak-traffic scan timing all matter. Our guide on how to choose an ASV vendor covers the questions worth asking before you commit to one.

Common PCI Compliance Requirements for Online Retailers You Can't Skip

Beyond SAQ submission and scanning, retailers often overlook maintaining an asset inventory of anything touching card data and reviewing third-party plugin access regularly.

Some of the most commonly missed PCI compliance requirements for online retailers:

  • Auditing which plugins, apps, or third-party scripts have access to checkout pages.
  • Reassessing your SAQ type after any change to your checkout architecture (new payment gateway, new cart plugin, new integration).
  • Confirming your scan requirement hasn’t changed if you check whether you need PCI ASV scanning at all under your current setup.
  • Budgeting for scanning costs; see our breakdown of PCI ASV scan costs for typical ranges by merchant size.

Conclusion

PCI compliance for e-commerce follows the same logic no matter what you sell or what platform you’re on: identify your SAQ type based on how your checkout is architected, meet the baseline security requirements, scan quarterly if required, and revalidate every year. Get the SAQ type right first; nearly everything else about your compliance workload follows from that one decision.

Ready to Get PCI Compliant?

Run your first PCI ASV scan with a vendor that understands e-commerce checkout architecture.

Frequently Asked Questions

Yes, but the burden is lighter. Hosted, PCI-compliant processors typically qualify you for SAQ A, since your servers never handle raw card data.
Annually via SAQ submission, plus quarterly ASV scans if your SAQ type requires them.

Not a federal law in most jurisdictions; it's a contractual requirement enforced through your payment processor or acquiring bank.

For SAQ A merchants, cost is mostly time. Once ASV scanning is required under SAQ A-EP or D, expect a recurring quarterly scanning cost.

No. SAQ types requiring external scanning must use a PCI SSC-certified Approved Scanning Vendor; self-scans don't satisfy the requirement.

SAQ A applies when your page never renders the card fields at all (full redirect). SAQ A-EP applies when your own code embeds or influences a hosted payment page.

Often the marketplace absorbs most of the compliance burden since it owns the payment flow, but you should confirm this directly with the marketplace's merchant terms.

Processors can charge monthly non-compliance fees, raise transaction rates, or terminate your merchant account. After a breach, non-compliance also removes liability protections you'd otherwise have.

Authored by

Binoy Koonammavu blog image

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.

Share:

Related Post

 

Discover more from Secusy ASV

Subscribe now to keep reading and get access to the full archive.

Continue reading