Binoy Koonammavu
PCI compliance for Shopify stores is a shared responsibility, and most merchants misread where Shopify’s obligation ends and theirs begins.
Shopify holds PCI DSS Level 1 Service Provider certification, which covers its payment infrastructure, hosted checkout, and data centres. It does not cover your custom integrations, third-party apps, or any self-hosted components in your checkout flow. Those remain your compliance scope, your SAQ, and in many configurations, your quarterly ASV scan obligation.
Here’s exactly what Shopify handles, what falls on you, and how to stay compliant without overcomplicating it.
Shopify's PCI DSS Level 1 certification covers its payment processing infrastructure, hosted checkout pages, and internal data centres. It does not cover your custom code, third-party apps, or any self-hosted components in your checkout flow. Those fall within your own compliance scope.
Shopify holds PCI DSS Level 1 Service Provider certification; the highest tier of compliance validation in the PCI framework, assessed annually by an independent Qualified Security Assessor (QSA). This covers:
This certification is meaningful. It means the platform you’re building on has passed the most rigorous external validation in the industry.
What it does not mean is that your store is PCI compliant by default.
Under PCI DSS 4.0.1, now the only active version since 31 March 2025, every merchant that accepts card payments carries independent compliance obligations. Shopify’s Level 1 status does not transfer to your merchant account. You are still required to complete the correct Self-Assessment Questionnaire (SAQ), maintain your own environment; and, in many configurations, conduct quarterly ASV scans on internet-facing IPs within your Cardholder Data Environment (CDE). If you’re budgeting for compliance, our guide to PCI ASV scan cost explains how pricing varies by merchant type and infrastructure scope.
Failing to do so puts your merchant account and your ability to accept card payments at risk.
PCI DSS (Payment Card Industry Data Security Standard): A set of security requirements established by the PCI Security Standards Council (PCI SSC) that applies to any entity that stores, processes, or transmits payment card data, designed to reduce cardholder data breaches across the global payments ecosystem.
Level 1 Service Provider: The highest merchant or service provider tier under PCI DSS, typically assigned to entities that process or facilitate very high transaction volumes annually; Level 1 entities are required to undergo an annual Report on Compliance (ROC) conducted by a Qualified Security Assessor (QSA).
Shared Responsibility Model: A compliance framework in which a cloud or SaaS platform provider (such as Shopify) takes responsibility for securing the underlying infrastructure, while the customer (the merchant) retains responsibility for securing their own configuration, integrations, data handling, and access controls within that platform.
ASV Scan (Approved Scanning Vendor Scan): An external vulnerability scan of internet-facing IP addresses conducted by a PCI-approved vendor. If you're unfamiliar with the process, read our complete guide to PCI ASV scanning explained.
Answer three quick questions and get an instant answer, no forms, no sales calls.
Shopify is responsible for securing its own platform. You are responsible for everything built on top of it; your domain, your integrations, your apps, and any custom checkout code you operate. Where Shopify's boundary ends, your PCI scope begins.
Misunderstanding the shared responsibility model is the single most common reason Shopify merchants fail their annual compliance review.
Everything outside Shopify’s hosted boundary is your scope. The size of that scope determines your SAQ type and whether you need an ASV scan.
Yes, Shopify is PCI DSS compliant as a Level 1 certified service provider. But that certification does not make your store compliant by default. Merchants must still complete their own SAQ annually and, depending on their checkout setup, conduct quarterly ASV scans on their own infrastructure.
Yes, Shopify is PCI DSS compliant as a Level 1 certified service provider. That is a verifiable, annually renewed certification.
But the question most merchants are actually asking is, ‘Does Shopify’s compliance cover my store?’ The answer to that is conditional.
Your question | Accurate answer |
|---|---|
Is Shopify PCI DSS Level 1 certified? | Yes, as a service provider |
Does that make my store PCI compliant? | Not automatically |
Do I still need to complete an SAQ? | Yes, every year |
Do I need an ASV scan? | Depends on your SAQ type |
Who is responsible if there’s a breach? | Shared, based on where the breach occurred |
The PCI SSC maintains a list of PCI DSS compliant service providers. Shopify appears on this list. Your store does not appear on any list unless you complete your own compliance process.
Your SAQ type depends entirely on how your store handles cardholder data. Most standard Shopify merchants using Shopify Payments with the default hosted checkout qualify for SAQ A; the lightest option, with no ASV scan required. Any custom code on your checkout page shifts your SAQ to A-EP or D, both of which mandate quarterly ASV scanning.
Your SAQ type is the most important compliance variable you control. Under PCI DSS 4.0.1, the correct SAQ is determined entirely by how your store handles cardholder data, not by which platform you use.
Shopify Configuration | Applicable SAQ | ASV Scan Required? |
|---|---|---|
Shopify Payments, hosted checkout, no custom code | SAQ A | No |
Redirect to third-party processor (e.g. PayPal, Stripe) | SAQ A | No |
JavaScript-based payment form embedded on your domain | SAQ A-EP | Yes |
Custom checkout with direct POST to processor | SAQ D (Merchant) | Yes |
Headless Shopify with self-hosted payment component | SAQ D (Merchant) | Yes |
Shopify Plus with custom app handling PANs | SAQ D (Merchant) | Yes |
Key insight:Most standard Shopify merchants using Shopify Payments with the default hosted checkout qualify for SAQ A, the lightest-touch option, with no ASV scan requirement. However, if you have installed a custom checkout app, a payment extension, or a conversion-optimisation tool that injects JavaScript into your payment flow, you most likely shift into SAQ A-EP territory, which mandates quarterly ASV scanning.
This is the hidden compliance trap that catches mid-market Shopify operators off guard. The threshold is not which payment processor you use. It is whether custom code runs on your domain at the point of payment.
If your Shopify setup puts you in SAQ A-EP or SAQ D territory, quarterly ASV scanning is a mandatory condition of your merchant agreement, not optional. Secusy delivers your scan results and pass certificate within 24 hours. Starts at $80/year. No contracts, no enterprise pricing.
Merchants using Shopify Payments with the standard hosted checkout are in the most favourable PCI compliance position on the platform. Cardholder data never touches your server or domain, your scope is limited to SAQ A, and no ASV scan is required on your own infrastructure.
Merchants using Shopify Payments with the standard hosted checkout operate in the most favourable PCI compliance position available on the platform.
In this configuration:
SAQ A contains 13 requirements. It is designed specifically for merchants in which all payment functions are fully outsourced to a PCI DSS-compliant third party. With Shopify Payments and no customisations to the checkout flow, that is precisely your situation.
If your bank requests an ASV scan certificate and you are genuinely SAQ A, with no custom checkout code and no self-hosted components, you can point them to Shopify’s own ASV scan results, which cover the hosted infrastructure. Your own infrastructure is not in scope.
Shopify Plus merchants face broader compliance exposure than standard merchants. Custom checkout extensions, headless shopfronts, and direct processor integrations all expand your CDE beyond Shopify's hosted boundary, typically pushing you into SAQ A-EP or SAQ D territory, with mandatory quarterly ASV scanning.
Shopify Plus gives merchants significantly more flexibility in how checkout is configured. That flexibility creates proportionally more compliance exposure.
Standard Shopify merchants typically have a narrow, well-defined CDE. Shopify Plus operators frequently extend that scope through:
Each of these scenarios pushes merchants out of SAQ A territory. Most Shopify Plus merchants running custom checkout configurations fall under SAQ A-EP at minimum, and SAQ D if they directly handle or transmit primary account numbers (PANs).
Shopify Plus hosting itself remains managed by Shopify and is covered by their Level 1 certification. The compliance risk is not in Shopify’s infrastructure; it is in any layer you operate on top of it. A headless front-end on Vercel, a middleware API on AWS, or a custom checkout proxy you control: all of these introduce infrastructure that falls outside Shopify’s compliance boundary and into your quarterly ASV scan scope.
Requirement 6.4.3 under PCI DSS 4.0.1 mandates that every script loading on your checkout page must be explicitly authorised, integrity-checked, and documented. For Shopify Plus operators running analytics platforms, A/B testing tools, live chat widgets, and review platform scripts on checkout, this is a significant governance obligation. Each script requires a defined business justification and a method to verify it has not been tampered with.
This requirement was introduced specifically in response to Magecart-style attacks, where attackers inject malicious JavaScript into payment pages to skim card data silently. Under PCI DSS v4, if a breach occurs via a third-party script on your checkout page, the liability is explicitly yours.
Shopify stores need an ASV scan when they operate under SAQ A-EP, SAQ C, or SAQ D; configurations that involve custom checkout code, embedded JS payment forms, or self-hosted payment components. Standard merchants using only Shopify Payments' hosted checkout do not require their own ASV scan.
An Approved Scanning Vendor (ASV) scan is a quarterly external vulnerability scan of your internet-facing IP addresses that are in scope for PCI. It is required when:
If you use standard Shopify Payments with default hosted checkout, You do not need an ASV scan on your own infrastructure. Shopify’s scan covers the platform. Your bank may still request your completed SAQ A as evidence of compliance.
If you run any custom checkout component, headless architecture, or embedded JS payment form: Your domain and associated hosting IPs enter your CDE scope and require quarterly ASV scanning under Requirement 11.3.2.
The IPs in scope are typically your primary domain’s hosting IP, any CDN origin IPs you control, load balancer IPs, and any server running middleware or custom checkout logic. Shopify’s own IPs, including the checkout.shopify.com subdomain, are covered by Shopify’s scan and are not your responsibility.
The most common ASV scan failures on Shopify-adjacent infrastructure are predictable and preventable. Before scheduling your assessment, review our guide on how to pass a PCI ASV scan to avoid common mistakes that delay certification.TLS misconfigurations, exposed server version headers, open redirects from third-party apps, and expired certificates on non-primary subdomains account for the majority of first-time failures, none of which require significant technical effort to remediate.
After running thousands of ASV scans, the failure patterns on Shopify-adjacent infrastructure are predictable:
PCI DSS 4.0.1 is now the only active standard. The most significant change for Shopify merchants is Requirement 6.4.3, which mandates that every script loading on your checkout page must be inventoried, authorised, and integrity-checked. TLS 1.0 and 1.1 are explicitly prohibited, and Targeted Risk Analysis is now required for any customised control implementations.
PCI DSS 4.0.1 became the only active version as of 31 March 2025. The transition grace period is over. Key changes with direct relevance to Shopify merchants:
Requirement | Change Under 4.0.1 | Shopify Impact |
|---|---|---|
Req 6.4.3 | All payment page scripts must be authorised and integrity-checked | Any third-party JS on your checkout page (analytics, chatbots, A/B tools) must be inventoried and validated |
Req 11.3.2 | Quarterly ASV scans mandatory for in-scope IPs | Headless/custom checkout operators cannot skip this |
Req 12.3.2 | Targeted Risk Analysis (TRA) now required for customised controls | Custom Shopify Plus configurations need formal risk documentation |
Req 4.2.1 | TLS 1.0/1.1 explicitly prohibited | Any infrastructure in your CDE must enforce TLS 1.2 minimum |
Req 8.3.6 | Passwords minimum 12 characters for system components | Admin access to any self-hosted Shopify middleware must comply |
Requirement 6.4.3 is the one most Shopify operators are unprepared for. If you have Google Tag Manager, Hotjar, a live chat widget, or a review platform script loading on your checkout page, you are now required to maintain an inventory of those scripts, confirm their purpose, and verify their integrity. A breach via a third-party script (Magecart-style attack) is now explicitly your liability.
The SAQ determination process is platform-agnostic. Whether you use Shopify or Wix, your SAQ type is determined by your checkout architecture; specifically whether cardholder data touches code or infrastructure you control. The rules are identical across both platforms.
The SAQ determination process is platform-agnostic. Whether you’re running Shopify, Wix, WooCommerce, or a custom build, the PCI DSS rules assess your checkout configuration, not your platform.
For Wix merchants, the logic maps identically to Shopify:
The practical difference is that Wix’s enterprise offering is less flexible than Shopify Plus, so fewer Wix merchants encounter SAQ A-EP or D scenarios. But if you’ve installed a custom payment app or a third-party checkout plugin that operates on your Wix domain, your compliance scope expands in the same way.
The key question in both cases is the same: ‘Does cardholder data ever touch code you control on infrastructure you operate?’ If yes, your scope expands.
For standard Shopify Payments merchants (SAQ A):
IPs Covered | Annual Price |
|---|---|
1 – 5 IPs | $80 – $350/year |
6 – 15 IPs | $420 – $900/year |
16 – 25 IPs | $928 – 1350/year |
25+ IPs |
Yes. All merchants that accept card payments; regardless of platform; must comply with PCI DSS. Shopify's Level 1 certification covers the platform infrastructure, but merchants retain independent responsibility for their own environment, completing the correct SAQ, and in some configurations, conducting quarterly ASV scans.
Partially. Shopify covers PCI compliance for its own hosted infrastructure, payment processing systems, and default checkout. It does not cover your custom integrations, third-party apps that touch payment data, headless checkout implementations, or your own server infrastructure. You are responsible for completing your SAQ and, where applicable, ASV scans.
Yes. Shopify holds PCI DSS Level 1 Service Provider certification, validated annually by an independent QSA. This is the highest compliance tier under the PCI framework. However, this certification covers Shopify's infrastructure only. It does not extend to your store's custom code, third-party integrations, or any self-hosted components in your checkout flow. Merchants must complete their own SAQ and, where applicable, conduct quarterly ASV scans independently.
An ASV (Approved Scanning Vendor) scan is a quarterly external vulnerability scan of internet-facing IP addresses within your Cardholder Data Environment. Shopify stores need one when they use a custom or embedded checkout (SAQ A-EP), a self-hosted payment component, or any configuration classified as SAQ C or SAQ D. Standard merchants using only Shopify Payments' hosted checkout typically do not.
Merchants using Shopify Payments with the standard hosted checkout; and no custom JavaScript on the payment page; qualify for SAQ A, the lightest form. Merchants using embedded JS payment forms, headless Shopify checkout, or custom payment integrations typically fall under SAQ A-EP or SAQ D, both of which require quarterly ASV scanning.
The most significant change is Requirement 6.4.3, which mandates that all scripts loading on your payment page are authorised, integrity-checked, and inventoried. This directly affects Shopify merchants running third-party JavaScript (analytics, chat, review widgets) on checkout pages. TLS 1.0/1.1 is also now explicitly prohibited, and Targeted Risk Analysis is required for customised control implementations.
With Secusy, ASV scanning starts at $80/year for a single IP. Five IPs costs $350/year and ten IPs costs $600/year. Most Shopify stores with a defined CDE footprint fall within the 1–5 IP range, making annual ASV compliance a minimal line item. All prices are in USD.
Card acceptance suspension is the cost of non-compliance. The cost of compliance with Secusy starts at $80. Run your first scan today, pass certificate delivered within 24 hours.

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.
Subscribe now to keep reading and get access to the full archive.