forumNew topic

Payment gateway requires PCI DSS compliance — is SAQ-A enough, or do we need an audit?

KKübra Ö***VeteranCommunity member
Joined
Apr 2024
Message
317
#1

We run an e-commerce site based in Frankfurt selling personalized gifts. We process about 1,200 orders a month, with an annual card transaction volume of around 350,000 EUR. We do not store credit card numbers, CVVs, or expiration dates on our own servers or databases under any circumstances.

On the checkout screen, users are redirected directly to a licensed payment institution's hosted payment page, or the transaction is completed via an iframe. In other words, card data flows directly to the payment provider's servers. Despite this, the payment gateway we work with has requested an annual PCI DSS compliance certificate and an approved self-assessment questionnaire from us.

When we spoke with an external auditing firm, we received quotes between 4,000 and 6,000 EUR annually for an independent audit. Does a business like ours that never touches card data really have to undergo an on-site audit? Or can we resolve this ourselves by filling out an SAQ-A form?

VVeli T***Member
Job title
Human Resources Specialist
Sector
Agriculture
Organization type
120-person company
Joined
Apr 2023
Message
1
Most Helpful#2

Short answer: If credit card data never touches your servers and the payment transaction occurs entirely on the licensed provider's hosted page or within an iframe, you do not need an independent on-site audit. For a business in your situation, completing the SAQ-A form and the Attestation of Compliance (AOC) is sufficient.

What determines this is your technical integration model. If the customer is redirected to the payment provider's hosted page during checkout, or if the iframe rendering the payment form is served directly from the third party's servers, card data is completely isolated from your infrastructure. In this scenario, you fall squarely under SAQ-A. SAQ-A consists of roughly 20–25 baseline control questions and can be completed with the signature of an authorized internal executive without hiring an external auditor.

However, you must pay attention to technical nuance: If you render the payment form on your own site and transmit the data to the provider via an API in the background, you fall under SAQ A-EP or SAQ D, not SAQ-A. When SAQ A-EP applies, quarterly external vulnerability scans conducted by an Approved Scanning Vendor (ASV) become mandatory.

Consulting firms providing quotes will almost always try to sell you the most extensive package. With an annual volume of 350,000 EUR, you are classified as a Level 4 merchant; at this level, unless you have experienced a major data breach in the past, an external audit is not mandatory. Inform your payment gateway in writing of your architecture and state that you will be submitting an SAQ-A.

EEsra I***MemberCommunity member
Joined
Dec 2023
Message
214
#3

You can proceed step by step: 1) Download the up-to-date PCI DSS AOC document from your payment provider's dashboard. 2) Obtain the latest SAQ-A document from the official PCI Security Standards Council website. 3) Answer the questions, have an officer of your company sign it, and upload the form to your payment provider's portal.

DDoruk Ç***Expert
Job title
Network Administrator
Sector
Retail
Organization type
boutique agency
Joined
Sep 2024
Message
1
#4

We process an annual volume of 1.5 million EUR, and we got a similar notice. At first, some consultants quoted us around 5,000 EUR for an audit. We spoke with our payment provider's technical rep, confirmed we use an iframe, filled out the SAQ-A form ourselves, and it got approved. It didn't cost us a single penny.

AAslı A***MemberCommunity member
Joined
Oct 2023
Message
19
#5

If you're using an iframe on your site, watch out for the new requirements introduced in PCI DSS v4.0. You are now required to verify the integrity and authorization of all third-party JavaScript running on the payment page. Even with SAQ-A, these controls became mandatory to mitigate the risk of malicious scripts leaking from the parent page into the payment iframe.

RRabia Ç***Member
Job title
IT manager
Sector
Energy
Organization type
40-person manufacturing company
Joined
Jun 2025
Message
354
#6

Exactly which integration method is your payment provider using? For instance, is it a direct redirect, an inline iframe, or a JS library that tokenizes card details? If you're doing tokenization via JavaScript, the bank might sometimes classify it as SAQ A-EP.

ÖÖmer Ö***Member
Job title
Social media manager
Sector
Printing
Organization type
chain store
Joined
Feb 2023
Message
64
#7

To clarify your standing, run these checks: 1) Is the source code for the card input field actually loaded from the payment provider's domain? 2) Do any request parameters in your server logs contain card numbers or CVVs? 3) Is your merchant level listed as Level 4 in your payment provider's dashboard? If all three check out, you don't need an external audit.

AAhmet E***Member
Job title
System support specialist
Sector
Electrical-electronics
Organization type
chain store
Joined
Mar 2023
Message
197
#8

Risk teams at payment institutions sometimes send out automated canned emails demanding a QSA audit as if you were a Level 1 merchant. Don't waste money on external firms without questioning it first. We got a similar letter last year; we just replied, "We don't store card data on our systems we're submitting an SAQ-A," and that was the end of it.

YYasinNew member
Job title
Technical Service
Joined
Nov 2024
Message
30
#9

SAQ-A is more than enough for your setup. With a 350,000 euro annual turnover, there is zero legal basis to force an independent audit on you. Don't fall for the hefty quotes from QSA firms; just fill out the form yourself and submit it.

BBurcu E***MemberCommunity member
Joined
Feb 2023
Message
94
#10

we had the exact same sare two years ago; the tone of the email was so harsh I thought a massive fine was right around the corner then once we sat down and actually read the form with a clear head it took half a day. anyway the payment providers support docs even spelled out how to answer each question.

KKader B***Expert
Job title
Social media manager
Sector
Sports and fitness
Organization type
boutique agency
Joined
Nov 2024
Message
56
#11

Thanks for posting.

DDeniz K***ExpertCommunity member
Joined
Nov 2024
Message
154
#12

The most overlooked point about pci dss compliance is this: An untested backup is not a backup.

HHüseyin Ö***Member
Job title
Accounting Manager
Sector
Agriculture
Organization type
medium-sized business
Joined
Feb 2025
Message
15
#13

I partly agree, partly disagree. Just because everyone does it doesn't mean it's right.

If I were you, I'd go this route.

TTülay O***MemberCommunity member
Joined
Jan 2023
Message
1
#14

We've heard this a lot but it never happened like that for us. I mean most incidents start with a leaked password, not a vulnerability.

If you have questions write them; Ill answer as best I can.

İİremNew member
Job title
Intern · marketing
Joined
Jan 2025
Message
30
#15

here's how it went for us. just because everyone does it doesn't mean it's right.

this is my oppinion Im not claiming its absolute truth.

AAycan P***Member
Job title
Production planning
Sector
Furniture manufacturing
Organization type
regional distributor
Joined
Apr 2024
Message
109
#16

Noted, thanks. Security isn't absolute; it's about making attacks not worth the effort.

I'm also curious if anyone does it differently.

ÖÖzgür K***MemberCommunity member
Joined
Nov 2023
Message
4
#17

Great work. Trying to do this alone is the most expensive way.

I'm also curious if anyone does it differently.

FFatma U***Member
Job title
Site Manager
Sector
Sports and fitness
Organization type
two-branch business
Joined
Jan 2025
Message
96
#18

Correct in theory, but it doesn't work that way in practice. Start with a small trial; don't commit to everything at once.

If you have questions, write them; I'll answer as best I can.

AAyşegülMember
Job title
Boutique hotel
Organization type
workshop
Joined
Aug 2024
Message
86
#19

Three different views emerged, they all complement each other... People defend habits not processes... Resistance comes from there.

Of course, it varies if your situation is different.

LLeyla Y***Member
Job title
Accounting clerk
Sector
Freight
Organization type
workshop
Joined
Feb 2022
Message
2
#20

The discussion got scattered, let me summarize. anyway if you get three different answers on a topic the question was asked wrong.

If you post the result here, it will help others too.

Reply