We run an e-commerce site based in Frankfurt selling personalized gifts. We process about 1,200 orders a month, with an annual card transaction volume of around 350,000 EUR. We do not store credit card numbers, CVVs, or expiration dates on our own servers or databases under any circumstances.
On the checkout screen, users are redirected directly to a licensed payment institution's hosted payment page, or the transaction is completed via an iframe. In other words, card data flows directly to the payment provider's servers. Despite this, the payment gateway we work with has requested an annual PCI DSS compliance certificate and an approved self-assessment questionnaire from us.
When we spoke with an external auditing firm, we received quotes between 4,000 and 6,000 EUR annually for an independent audit. Does a business like ours that never touches card data really have to undergo an on-site audit? Or can we resolve this ourselves by filling out an SAQ-A form?