PCI Compliance for Shopify Stores: What You Actually Need in 2026

Published on

Updated on

Key Takeaways
  • Shopify is a PCI DSS Level 1 certified service provider; but that certification covers Shopify's infrastructure, not your store.
  • Most standard Shopify merchants qualify for SAQ A, the lightest compliance form, as long as they use Shopify Payments' hosted checkout with no custom code.
  • SAQ A merchants don't need their own ASV scan; Shopify's scan covers the platform; your bank may still request your completed SAQ as evidence.
  • The moment custom JavaScript, a third-party payment app, or a self-hosted component enters your checkout flow, your SAQ shifts to A-EP or D, and quarterly ASV scans become mandatory.
  • Shopify Plus merchants carry the most exposure, custom checkout extensions, headless storefronts, and direct processor integrations all expand your CDE scope beyond Shopify's coverage.
  • Under PCI DSS 4.0.1 Requirement 6.4.3, every third-party script loading on your checkout page, analytics, chat widgets, A/B tools must be inventoried, authorised, and integrity-checked; a breach via those scripts is your liability.
  • TLS 1.0 and 1.1 are explicitly prohibited under PCI DSS 4.0.1, any load balancer, CDN, or middleware layer in your CDE must enforce TLS 1.2 minimum.
  • The most common first-time ASV scan failures on Shopify infrastructure are TLS misconfigurations, exposed server version headers, and expired certificates on non-primary subdomains, all avoidable with a pre-scan checklist.
  • The SAQ logic applies equally to Wix merchants, platform doesn't determine compliance scope; checkout architecture does.

PCI compliance for Shopify stores is a shared responsibility, and most merchants misread where Shopify’s obligation ends and theirs begins.

Shopify holds PCI DSS Level 1 Service Provider certification, which covers its payment infrastructure, hosted checkout, and data centres. It does not cover your custom integrations, third-party apps, or any self-hosted components in your checkout flow. Those remain your compliance scope, your SAQ, and in many configurations, your quarterly ASV scan obligation.

Here’s exactly what Shopify handles, what falls on you, and how to stay compliant without overcomplicating it.

What Does PCI Compliance for Shopify Actually Cover?

Shopify's PCI DSS Level 1 certification covers its payment processing infrastructure, hosted checkout pages, and internal data centres. It does not cover your custom code, third-party apps, or any self-hosted components in your checkout flow. Those fall within your own compliance scope.

Shopify holds PCI DSS Level 1 Service Provider certification; the highest tier of compliance validation in the PCI framework, assessed annually by an independent Qualified Security Assessor (QSA). This covers:

  • Shopify’s payment processing infrastructure
  • Hosted checkout pages when using Shopify Payments or Shop Pay
  • Shopify’s servers, data centres, and internal network segmentation
  • Shopify’s own system components, access controls, and logging

This certification is meaningful. It means the platform you’re building on has passed the most rigorous external validation in the industry.

What it does not mean is that your store is PCI compliant by default.

Under PCI DSS 4.0.1, now the only active version since 31 March 2025, every merchant that accepts card payments carries independent compliance obligations. Shopify’s Level 1 status does not transfer to your merchant account. You are still required to complete the correct Self-Assessment Questionnaire (SAQ), maintain your own environment; and, in many configurations, conduct quarterly ASV scans on internet-facing IPs within your Cardholder Data Environment (CDE). If you’re budgeting for compliance, our guide to PCI ASV scan cost explains how pricing varies by merchant type and infrastructure scope.

Failing to do so puts your merchant account and your ability to accept card payments at risk.

Key Definitions

PCI DSS (Payment Card Industry Data Security Standard): A set of security requirements established by the PCI Security Standards Council (PCI SSC) that applies to any entity that stores, processes, or transmits payment card data, designed to reduce cardholder data breaches across the global payments ecosystem.

Level 1 Service Provider: The highest merchant or service provider tier under PCI DSS, typically assigned to entities that process or facilitate very high transaction volumes annually; Level 1 entities are required to undergo an annual Report on Compliance (ROC) conducted by a Qualified Security Assessor (QSA).

Shared Responsibility Model: A compliance framework in which a cloud or SaaS platform provider (such as Shopify) takes responsibility for securing the underlying infrastructure, while the customer (the merchant) retains responsibility for securing their own configuration, integrations, data handling, and access controls within that platform.

ASV Scan (Approved Scanning Vendor Scan): An external vulnerability scan of internet-facing IP addresses conducted by a PCI-approved vendor. If you're unfamiliar with the process, read our complete guide to PCI ASV scanning explained.

Not Sure If Your Shopify Setup Needs an ASV Scan?

Answer three quick questions and get an instant answer, no forms, no sales calls.

The Shared Responsibility Model: Where Shopify's Coverage Stops

Shopify is responsible for securing its own platform. You are responsible for everything built on top of it; your domain, your integrations, your apps, and any custom checkout code you operate. Where Shopify's boundary ends, your PCI scope begins.

Misunderstanding the shared responsibility model is the single most common reason Shopify merchants fail their annual compliance review.

What Shopify’s PCI DSS Level 1 certification covers:
  • Shopify Payments and Shop Pay infrastructure
  • Hosted checkout pages served from Shopify’s domain
  • Shopify’s own servers, physical data centres, and network segmentation
  • Shopify’s internal access control, encryption, and logging systems

 

What it does not cover:
  • Your domain and any custom code running on it
  • Third-party apps installed on your store that interact with payment data
  • Redirect or iframe implementations you have configured
  • Any middleware, proxy, or front-end layer you operate for headless Shopify
  • Self-hosted checkout components or custom payment integrations
  • Marketing and analytics scripts are loading on your checkout page

 

Everything outside Shopify’s hosted boundary is your scope. The size of that scope determines your SAQ type and whether you need an ASV scan.

Is Shopify PCI DSS Compliant? Here's the Accurate Answer

Yes, Shopify is PCI DSS compliant as a Level 1 certified service provider. But that certification does not make your store compliant by default. Merchants must still complete their own SAQ annually and, depending on their checkout setup, conduct quarterly ASV scans on their own infrastructure.

Yes, Shopify is PCI DSS compliant as a Level 1 certified service provider. That is a verifiable, annually renewed certification.

But the question most merchants are actually asking is, ‘Does Shopify’s compliance cover my store?’ The answer to that is conditional.

Your question
Accurate answer
Is Shopify PCI DSS Level 1 certified?
Yes, as a service provider
Does that make my store PCI compliant?
Not automatically
Do I still need to complete an SAQ?
Yes, every year
Do I need an ASV scan?
Depends on your SAQ type
Who is responsible if there’s a breach?
Shared, based on where the breach occurred

The PCI SSC maintains a list of PCI DSS compliant service providers. Shopify appears on this list. Your store does not appear on any list unless you complete your own compliance process.

What SAQ Type Applies to Your Shopify Setup?

Your SAQ type depends entirely on how your store handles cardholder data. Most standard Shopify merchants using Shopify Payments with the default hosted checkout qualify for SAQ A; the lightest option, with no ASV scan required. Any custom code on your checkout page shifts your SAQ to A-EP or D, both of which mandate quarterly ASV scanning.

Your SAQ type is the most important compliance variable you control. Under PCI DSS 4.0.1, the correct SAQ is determined entirely by how your store handles cardholder data, not by which platform you use.

Shopify Configuration
Applicable SAQ
ASV Scan Required?
Shopify Payments, hosted checkout, no custom code
SAQ A
No
Redirect to third-party processor (e.g. PayPal, Stripe)
SAQ A
No
JavaScript-based payment form embedded on your domain
SAQ A-EP
Yes
Custom checkout with direct POST to processor
SAQ D (Merchant)
Yes
Headless Shopify with self-hosted payment component
SAQ D (Merchant)
Yes
Shopify Plus with custom app handling PANs
SAQ D (Merchant)
Yes

Key insight:Most standard Shopify merchants using Shopify Payments with the default hosted checkout qualify for SAQ A, the lightest-touch option, with no ASV scan requirement. However, if you have installed a custom checkout app, a payment extension, or a conversion-optimisation tool that injects JavaScript into your payment flow, you most likely shift into SAQ A-EP territory, which mandates quarterly ASV scanning.

This is the hidden compliance trap that catches mid-market Shopify operators off guard. The threshold is not which payment processor you use. It is whether custom code runs on your domain at the point of payment.

Your SAQ Type Is Clear. Now Close the Compliance Gap.

If your Shopify setup puts you in SAQ A-EP or SAQ D territory, quarterly ASV scanning is a mandatory condition of your merchant agreement, not optional. Secusy delivers your scan results and pass certificate within 24 hours. Starts at $80/year. No contracts, no enterprise pricing.

Shopify Payments PCI Compliance: What the Default Setup Gets You

Merchants using Shopify Payments with the standard hosted checkout are in the most favourable PCI compliance position on the platform. Cardholder data never touches your server or domain, your scope is limited to SAQ A, and no ASV scan is required on your own infrastructure.

Merchants using Shopify Payments with the standard hosted checkout operate in the most favourable PCI compliance position available on the platform.

In this configuration:

  • Cardholder data is entered directly on Shopify’s hosted checkout page, served from Shopify’s domain
  • No cardholder data ever touches your server, your domain, or your code
  • Shopify’s Level 1 certification covers the entire payment data flow
  • Your compliance obligation is limited to completing SAQ A annually

 

SAQ A contains 13 requirements. It is designed specifically for merchants in which all payment functions are fully outsourced to a PCI DSS-compliant third party. With Shopify Payments and no customisations to the checkout flow, that is precisely your situation.

Shopify Payments PCI compliance checklist (SAQ A merchants):
  • Complete SAQ A annually and retain the signed document
  • Confirm Shopify Payments is your only payment method
  • Verify that no custom JavaScript touches your checkout page
  • Review and acknowledge Shopify’s Responsibility Matrix
  • Maintain documented evidence for your acquiring bank

 

If your bank requests an ASV scan certificate and you are genuinely SAQ A, with no custom checkout code and no self-hosted components, you can point them to Shopify’s own ASV scan results, which cover the hosted infrastructure. Your own infrastructure is not in scope.

Shopify Plus PCI Compliance: What Changes at Enterprise Scale

Shopify Plus merchants face broader compliance exposure than standard merchants. Custom checkout extensions, headless shopfronts, and direct processor integrations all expand your CDE beyond Shopify's hosted boundary, typically pushing you into SAQ A-EP or SAQ D territory, with mandatory quarterly ASV scanning.

Shopify Plus gives merchants significantly more flexibility in how checkout is configured. That flexibility creates proportionally more compliance exposure.

Standard Shopify merchants typically have a narrow, well-defined CDE. Shopify Plus operators frequently extend that scope through:

  • Custom checkout extensions built with Shopify Functions or Checkout UI Extensions
  • Headless storefronts (Next.js, Hydrogen) with self-hosted payment components
  • Direct API integrations to payment processors outside of Shopify Payments
  • Multi-store or multi-region deployments with separate hosting infrastructure
  • Third-party payment apps that handle or transmit card data

 

Each of these scenarios pushes merchants out of SAQ A territory. Most Shopify Plus merchants running custom checkout configurations fall under SAQ A-EP at minimum, and SAQ D if they directly handle or transmit primary account numbers (PANs).

Shopify Plus hosting and PCI compliance in 2026:

Shopify Plus hosting itself remains managed by Shopify and is covered by their Level 1 certification. The compliance risk is not in Shopify’s infrastructure; it is in any layer you operate on top of it. A headless front-end on Vercel, a middleware API on AWS, or a custom checkout proxy you control: all of these introduce infrastructure that falls outside Shopify’s compliance boundary and into your quarterly ASV scan scope.

PCI DSS v4 Shopify checkout compliance for Plus merchants:

Requirement 6.4.3 under PCI DSS 4.0.1 mandates that every script loading on your checkout page must be explicitly authorised, integrity-checked, and documented. For Shopify Plus operators running analytics platforms, A/B testing tools, live chat widgets, and review platform scripts on checkout, this is a significant governance obligation. Each script requires a defined business justification and a method to verify it has not been tampered with.

This requirement was introduced specifically in response to Magecart-style attacks, where attackers inject malicious JavaScript into payment pages to skim card data silently. Under PCI DSS v4, if a breach occurs via a third-party script on your checkout page, the liability is explicitly yours.

When Do Shopify Stores Need an ASV Scan?

Shopify stores need an ASV scan when they operate under SAQ A-EP, SAQ C, or SAQ D; configurations that involve custom checkout code, embedded JS payment forms, or self-hosted payment components. Standard merchants using only Shopify Payments' hosted checkout do not require their own ASV scan.

An Approved Scanning Vendor (ASV) scan is a quarterly external vulnerability scan of your internet-facing IP addresses that are in scope for PCI. It is required when:

  • You complete an SAQ A-EP, SAQ C, or SAQ D (all require quarterly ASV scanning). Learn more about ASV scan frequency, including what triggers additional scans outside the standard quarterly schedule.
  • You are a Level 1 or Level 2 merchant subject to a Report on Compliance (ROC)
  • Your acquiring bank or payment facilitator explicitly mandates it

If you use standard Shopify Payments with default hosted checkout, You do not need an ASV scan on your own infrastructure. Shopify’s scan covers the platform. Your bank may still request your completed SAQ A as evidence of compliance.

If you run any custom checkout component, headless architecture, or embedded JS payment form: Your domain and associated hosting IPs enter your CDE scope and require quarterly ASV scanning under Requirement 11.3.2.

The IPs in scope are typically your primary domain’s hosting IP, any CDN origin IPs you control, load balancer IPs, and any server running middleware or custom checkout logic. Shopify’s own IPs, including the checkout.shopify.com subdomain, are covered by Shopify’s scan and are not your responsibility.

The "Hidden" Scan Failures Most Shopify Operators Don't See Coming

The most common ASV scan failures on Shopify-adjacent infrastructure are predictable and preventable. Before scheduling your assessment, review our guide on how to pass a PCI ASV scan to avoid common mistakes that delay certification.TLS misconfigurations, exposed server version headers, open redirects from third-party apps, and expired certificates on non-primary subdomains account for the majority of first-time failures, none of which require significant technical effort to remediate.

After running thousands of ASV scans, the failure patterns on Shopify-adjacent infrastructure are predictable:

  1. TLS 1.0 / 1.1 Still Enabled on Load Balancers Many custom Shopify deployments sit behind a CDN or load balancer that hasn’t been hardened. TLS 1.0 and 1.1 are explicitly prohibited under PCI DSS 4.0.1 requirements. 4.2.1. Scanners will flag these as a CVSS 4.0 medium-to-high finding and fail your certificate.
  2. Open Redirect Vulnerabilities in Third-Party Apps Shopify apps that redirect users through intermediate domains (affiliate tracking, upsell tools) introduce open redirect risks. ASV scanners check these external-facing endpoints; if a redirect chain passes through your IP scope, it can introduce a finding.
  3. HTTP Headers Exposing Server Versions. If you run a middleware layer, proxy, or custom Node/Next.js app for headless Shopify, Server: and X-Powered- By response headers, exposed version strings are automatically flagged. Remediation is a two-line config change, but it fails first-time scans consistently.
  4. Expired or Self-Signed TLS Certificates on Non-Primary Domains Staging environments, admin subdomains, and webhook endpoints on your IP range that carry expired certificates will fail the scan, even if they’re not production-facing.
  5. CVSS Scoring Misread as “Informational” Under older CVSS 3.x frameworks, some findings scored below 4.0 were treated as informational. Under CVSS 4.0 (adopted in PCI DSS 4.0.1 alignment), several of those findings now carry exploitability context that pushes them into fail territory. If your team hasn’t re-evaluated their scan baseline since 2024, you may be walking into avoidable failures.

PCI DSS v4 Shopify Checkout Compliance: What Changed and What It Means for You

PCI DSS 4.0.1 is now the only active standard. The most significant change for Shopify merchants is Requirement 6.4.3, which mandates that every script loading on your checkout page must be inventoried, authorised, and integrity-checked. TLS 1.0 and 1.1 are explicitly prohibited, and Targeted Risk Analysis is now required for any customised control implementations.

PCI DSS 4.0.1 became the only active version as of 31 March 2025. The transition grace period is over. Key changes with direct relevance to Shopify merchants:

Requirement
Change Under 4.0.1
Shopify Impact
Req 6.4.3
All payment page scripts must be authorised and integrity-checked
Any third-party JS on your checkout page (analytics, chatbots, A/B tools) must be inventoried and validated
Req 11.3.2
Quarterly ASV scans mandatory for in-scope IPs
Headless/custom checkout operators cannot skip this
Req 12.3.2
Targeted Risk Analysis (TRA) now required for customised controls
Custom Shopify Plus configurations need formal risk documentation
Req 4.2.1
TLS 1.0/1.1 explicitly prohibited
Any infrastructure in your CDE must enforce TLS 1.2 minimum
Req 8.3.6
Passwords minimum 12 characters for system components
Admin access to any self-hosted Shopify middleware must comply

Requirement 6.4.3 is the one most Shopify operators are unprepared for. If you have Google Tag Manager, Hotjar, a live chat widget, or a review platform script loading on your checkout page, you are now required to maintain an inventory of those scripts, confirm their purpose, and verify their integrity. A breach via a third-party script (Magecart-style attack) is now explicitly your liability.

SAQ Type for Shopify and Wix Stores: The Same Logic Applies

The SAQ determination process is platform-agnostic. Whether you use Shopify or Wix, your SAQ type is determined by your checkout architecture; specifically whether cardholder data touches code or infrastructure you control. The rules are identical across both platforms.

The SAQ determination process is platform-agnostic. Whether you’re running Shopify, Wix, WooCommerce, or a custom build, the PCI DSS rules assess your checkout configuration, not your platform.

For Wix merchants, the logic maps identically to Shopify:

  • Wix Payments with hosted checkout, no custom code → SAQ A, no ASV scan required
  • Third-party processor via redirect → SAQ A in most cases
  • Embedded JS payment form on your Wix domain → SAQ A-EP, ASV scan required
  • Custom checkout code or self-hosted payment component → SAQ D, ASV scan required

 

The practical difference is that Wix’s enterprise offering is less flexible than Shopify Plus, so fewer Wix merchants encounter SAQ A-EP or D scenarios. But if you’ve installed a custom payment app or a third-party checkout plugin that operates on your Wix domain, your compliance scope expands in the same way.

The key question in both cases is the same: ‘Does cardholder data ever touch code you control on infrastructure you operate?’ If yes, your scope expands.

PCI Compliance Checklist for Shopify Stores (2026)

For standard Shopify Payments merchants (SAQ A):

For custom checkout / headless / SAQ A-EP or D merchants:

Secusy ASV Scanning for Shopify Merchants

Most Shopify merchants don’t need an enterprise-priced scanning platform. They need accurate results, fast turnaround, and a clear pass certificate they can send to their bank. Secusy delivers exactly that:
  • Speed: Scan results and your pass certificate within 24 hours of initiation
  • Remediation guidance: Every finding comes with a plain-English fix, not just a CVE reference
  • Re-scan included: If you fail, we rescan after remediation at no extra cost
Pricing that matches your scope:
IPs Covered
Annual Price
1 – 5 IPs
$80 – $350/year
6 – 15 IPs
$420 – $900/year
16 – 25 IPs
$928 – 1350/year
25+ IPs
For the majority of Shopify operators with a small CDE footprint, that’s the full annual cost of ASV compliance. No per-scan fees, no enterprise contracts. For a full breakdown of what ASV scanning covers and how the process works end-to-end, read our comprehensive PCI ASV guide.

Frequently Asked Questions

Yes. All merchants that accept card payments; regardless of platform; must comply with PCI DSS. Shopify's Level 1 certification covers the platform infrastructure, but merchants retain independent responsibility for their own environment, completing the correct SAQ, and in some configurations, conducting quarterly ASV scans.

Partially. Shopify covers PCI compliance for its own hosted infrastructure, payment processing systems, and default checkout. It does not cover your custom integrations, third-party apps that touch payment data, headless checkout implementations, or your own server infrastructure. You are responsible for completing your SAQ and, where applicable, ASV scans.

Yes. Shopify holds PCI DSS Level 1 Service Provider certification, validated annually by an independent QSA. This is the highest compliance tier under the PCI framework. However, this certification covers Shopify's infrastructure only. It does not extend to your store's custom code, third-party integrations, or any self-hosted components in your checkout flow. Merchants must complete their own SAQ and, where applicable, conduct quarterly ASV scans independently.

An ASV (Approved Scanning Vendor) scan is a quarterly external vulnerability scan of internet-facing IP addresses within your Cardholder Data Environment. Shopify stores need one when they use a custom or embedded checkout (SAQ A-EP), a self-hosted payment component, or any configuration classified as SAQ C or SAQ D. Standard merchants using only Shopify Payments' hosted checkout typically do not.

Merchants using Shopify Payments with the standard hosted checkout; and no custom JavaScript on the payment page; qualify for SAQ A, the lightest form. Merchants using embedded JS payment forms, headless Shopify checkout, or custom payment integrations typically fall under SAQ A-EP or SAQ D, both of which require quarterly ASV scanning.

The most significant change is Requirement 6.4.3, which mandates that all scripts loading on your payment page are authorised, integrity-checked, and inventoried. This directly affects Shopify merchants running third-party JavaScript (analytics, chat, review widgets) on checkout pages. TLS 1.0/1.1 is also now explicitly prohibited, and Targeted Risk Analysis is required for customised control implementations.

With Secusy, ASV scanning starts at $80/year for a single IP. Five IPs costs $350/year and ten IPs costs $600/year. Most Shopify stores with a defined CDE footprint fall within the 1–5 IP range, making annual ASV compliance a minimal line item. All prices are in USD.

Get Compliant. Get Certified. Move On.

Card acceptance suspension is the cost of non-compliance. The cost of compliance with Secusy starts at $80. Run your first scan today, pass certificate delivered within 24 hours.

Authored by

Binoy Koonammavu blog image

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.

Share:

Related Post

 

Discover more from Secusy ASV

Subscribe now to keep reading and get access to the full archive.

Continue reading