forumNew topic

Payment provider is asking for PCI-DSS certification — is it really necessary, what does it cost?

AAli Y***Member
Job title
Site Manager
Sector
E-commerce
Organization type
40-person manufacturing company
Joined
Jan 2024
Message
129
#1

We run a boutique e-commerce site based in Berlin selling custom-designed wooden furniture. We process around 4,000 transactions a year with an annual turnover of around 650,000 €. For our payment infrastructure, we use a popular gateway that redirects customers to an external hosted page.

Last week, we got an official email notification from our payment provider stating that we must provide a PCI-DSS compliance certificate or complete validation to avoid account suspension. We don't store any credit card details on our own server; customer info goes straight into the payment provider's secure form. Is this certification really mandatory for a business of our size? Will we have to pay thousands of euros in audit fees, and what's the cheapest way to resolve this?

JJale P***MemberCommunity member
Joined
Mar 2024
Message
207
Most Helpful#2

Short answer: Even if you do not store cardholder data on your own server, any e-commerce business accepting card payments is required to comply with PCI-DSS standards. However, a business of your size does not need to pay thousands of euros to external auditors; the process can be handled entirely through a free or low-cost self-assessment questionnaire.

Since your transaction volume is under 1 million per year, you fall under the Level 4 merchant category. At this level, full on-site audits or external vulnerability scans are not required. Because you accept payments by redirecting customers to an external page or using an iframe, the document you need to complete is the Self-Assessment Questionnaire A, or SAQ A.

SAQ A consists of roughly twenty basic questions confirming that you do not store card data on your servers and that your systems use secure encryption. Most payment providers offer this process directly through their admin dashboard or via a partner compliance portal.

Here is what you should do: Log into your payment provider's dashboard and start the compliance wizard. Select redirect as your integration method, and the system will automatically pull up the SAQ A form. Once you answer the questions and confirm the form, your Attestation of Compliance (AoC) is generated instantly, securing your account.

ZZafer Y***Expert
Job title
Software team lead
Sector
Jewelry
Organization type
8-person team
Joined
Jun 2023
Message
214
#3

Nothing to worry about. If you never see the card numbers on your server, expensive audits don't apply to you. Open the SAQ A form, answer questions like "do you handle card data" along the lines of "outsourced to provider", and submit it. We renew ours every year in 15 minutes.

YYağmur C***MemberCommunity member
Joined
May 2023
Message
274
#4

The technical distinction is critical: even if the form is embedded on your site, if the data is sent directly to the payment gateway's API in the background, you fall under SAQ A-EP and need quarterly vulnerability scans. But if you use a full redirect or an iframe, you only need the simple SAQ A, with no external scans required.

SSelin U***MemberCommunity member
Joined
Mar 2026
Message
2
#5

We got the same notice last year, and auditing firms quoted us 4,000 €. Then we reached out to our payment gateway's support team, and they pointed us to their partner portal. We paid a 60 € annual portal fee, filled out the 20-question SAQ A survey, and got approved.

VVeli T***MemberCommunity member
Joined
Oct 2023
Message
152
#6

Just call your payment gateway's support right away. Tell them you use a redirect and ask how to submit the SAQ A document via the dashboard. They'll send you a link to their online validation page, and you'll be done in half an hour.

ÖÖmer Ö***Member
Job title
Social media manager
Sector
Printing
Organization type
chain store
Joined
Feb 2023
Message
64
#7

Let me summarize the process step-by-step: 1) Verify your integration type (redirect or API?). 2) Identify the right form (most likely SAQ A). 3) Complete the wizard in the provider's portal. 4) Save the resulting Attestation of Compliance to your records.

AAslı Ç***Member
Job title
Production planning
Sector
Consulting
Organization type
300-person organization
Joined
Dec 2025
Message
124

Doki · KVKK compliance consulting · 2026

#8

got the exact same email panicked and talked to support right away... turns out u just answer a few questions in the portal. dont pay any money just do it yourself in the dashboard.

OOya O***Member
Job title
Accounting clerk
Sector
Media and publishing
Organization type
two-branch business
Joined
Dec 2024
Message
113
#9

Payment gateways word these emails aggressively to scare you, making it sound like an auditor will show up at your door tomorrow. Their main goal is often to sell monthly or annual subscriptions to their partner compliance portals. Don't panic and don't hire an outside consultant.

EErcanMember
Job title
Accountant
Joined
Sep 2024
Message
92
#10

Even if you do not store credit card data, the security of the server hosting your website is critical during the cardholder redirection phase. Therefore, even at the SAQ A level, this requirement is mandated by the international card schemes. I advise you to complete the submission within the deadline.

BBurcu Ş***Member
Job title
Social media manager
Sector
Media and publishing
Organization type
workshop
Joined
Mar 2025
Message
406
#11

Just a heads-up. Everything goes well for the first three months; problems arise in the fourth.

If you post the result here, it will help others too.

RRıdvan Y***Expert
Job title
Software team lead
Joined
Sep 2023
Message
196

Doki · Interface design · 2023

#12

Correct.

FFatih E***Member
Job title
Operations manager
Sector
Consulting
Organization type
medium-sized business
Joined
May 2023
Message
26
#13

Same here. People defend habits not processes. Resistance comes from there.

Solutions that work at a small scale collapse when you grow; I learned this late. If you post the result here it will help others too.

CCaner E***MemberCommunity member
Joined
Sep 2024
Message
11
#14

I disagree with you on this point. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Payment information changes are never verified through the channel they came from. Correct me if I'm wrong.

ÖÖzgür A***ExpertCommunity member
Joined
Feb 2025
Message
1
#15

I didn't know that. An automated scan report is not the same as a penetration test.

If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

İİlker Y***Member
Job title
Content Editor
Sector
Software
Organization type
early-stage startup
Joined
Dec 2024
Message
233
#16

We experienced almost the exact same thing last year. If the notification path is long notifications don't arrive; missing notifications mean delayed incident detection.

If it's your first time, start small; scaling comes later. Of course, it varies if your situation is different.

SSena G***MemberCommunity member
Joined
Feb 2023
Message
356
#17

Yes that's exactly how it is with pci dss certification. Your time to detect an issue directly determines its cost.

Just leaving this note it might be useful.

KKübra M***Member
Job title
Accounting Manager
Sector
Consulting
Organization type
early-stage startup
Joined
Oct 2023
Message
140
#18

Let me share what happened to me; it might be useful. Everyone rushing into pci dss certification gets stuck at the same point.

I'm also curious if anyone does it differently.

EEsra D***MemberCommunity member
Joined
Sep 2024
Message
102
#19

You're right.

AAycan B***Member
Job title
Quality Assurance Manager
Sector
Automotive aftermarket
Organization type
40-person manufacturing company
Joined
Mar 2024
Message
6
#20

Let me summarize what's been said so far. Payment information changes are never verified through the channel they came from.

If you post the result here, it will help others too.

Reply