- Job title
- Site Manager
- Sector
- E-commerce
- Organization type
- 40-person manufacturing company
- Joined
- Jan 2024
- Message
- 129
We run a boutique e-commerce site based in Berlin selling custom-designed wooden furniture. We process around 4,000 transactions a year with an annual turnover of around 650,000 €. For our payment infrastructure, we use a popular gateway that redirects customers to an external hosted page.
Last week, we got an official email notification from our payment provider stating that we must provide a PCI-DSS compliance certificate or complete validation to avoid account suspension. We don't store any credit card details on our own server; customer info goes straight into the payment provider's secure form. Is this certification really mandatory for a business of our size? Will we have to pay thousands of euros in audit fees, and what's the cheapest way to resolve this?