forumNew topic

Payment Provider Demanding PCI DSS Compliance: Is There a Checklist, Where Do We Even Start?

HHande V***New memberCommunity member
Joined
Sep 2026
Message
318
#1

We run an e-commerce site selling boutique coffee machines and spare parts in the US. We process around 18,000 transactions a year with an annual turnover of roughly 1,200,000 dollars. We don't take payments directly on our own servers; we use the secure iFrame and external redirect flow provided by our payment gateway, so we thought card numbers never even touched our site.

Yesterday we received an urgent email from our payment processor. It says we must complete our annual PCI DSS compliance validation, or else we'll be hit with per-transaction fines and risk having our payment gateway suspended. They sent over complicated forms and links to hundreds of pages of technical standards.

As a small merchant, what is the actual PCI DSS compliance checklist that applies to us? If card data never touches our servers, exactly which Self-Assessment Questionnaire do we need to fill out, and what will this realistically cost us?

KKader Ş***New memberCommunity member
Joined
Sep 2026
Message
297
Most Helpful#2

Short answer: Even if you never physically touch card numbers, any business that accepts credit cards falls under PCI DSS. However, since you don't store or handle cardholder data directly, you qualify as a Level 4 merchant (the lowest tier). Instead of undergoing a massive hundred-point audit, you only need to fill out a brief Self-Assessment Questionnaire (SAQ).

Here are the practical action steps you need to follow:

1) Confirm your integration method. If card details are entered entirely on a hosted checkout page or inside an iFrame managed by the gateway the document you need is 'SAQ A'. It's only about 22 questions confirming that no card data is stored on your servers. If your checkout form uses client-side scripts to post data directly to the provider in the background, you'll need 'SAQ A-EP', which is far more comprehensive.

2) Your checklist for SAQ A: Keeping your web server patched and up to date, enforcing two-factor authentication (2FA) on all admin portals, changing default vendor passwords and monitoring the integrity of all third-party scripts running on your checkout pages.

3) Sign and submit the Attestation of Compliance (AOC) along with the completed questionnaire.

Regarding costs: At the SAQ A level, you don't need to hire a Qualified Security Assessor (QSA). You can download the form from the official PCI Security Standards Council website or complete it directly inside your payment processor's portal for free. The only potential cost is an annual administrative or portal fee of roughly 100 to 300 dollars charged by some merchant providers.

Correction: I misremembered the figure, it was a bit lower.

HHakan A***Member
Job title
Software team lead
Sector
Catering
Organization type
20-person company
Joined
Oct 2023
Message
86
#3

The critical technical catch here is the difference between an iFrame and a full redirect. If you have third-party JavaScript running on your page that gets compromised, attackers can overlay a fake form right on top of your iFrame. That's why your checklist must include verifying the integrity of every single external script loaded on your checkout pages.

AAylinMember
Job title
CRM and email
Organization type
300-person organization
Joined
Jun 2024
Message
118
#4

Just log into your payment gateway dashboard; they usually have a built-in compliance wizard. As you answer the prompts, it automatically directs you to SAQ A. Most questions are no-brainers along the lines of "do you write card numbers on paper or store them on your server?". You can wrap it up in two hours.

MMert K***MemberCommunity member
Joined
Jul 2025
Message
365
#5

We got hit with the exact same notice last year at around 25,000 transactions. We ignored it, and the processor started billing us a 49 dollars monthly "PCI non-compliance fee". Once we realized, we knocked out the SAQ A through their portal in 40 minutes, and the penalty disappeared the following billing cycle.

OOkan K***MemberCommunity member
Joined
Feb 2023
Message
111
#6

Everyone says "SAQ A is a breeze, takes two minutes," but under the newer PCI standards, requirements like script integrity monitoring and checkout page tampering protections were added to SAQ A as well. You can't just check boxes blindly anymore; you might need to set up hash verification or CSP for all scripts on your site.

FFeritMember
Job title
Car dealership
Organization type
8-person team
Joined
Jun 2024
Message
72
#7

Never store CVVs or full 16-digit card numbers on your server. As long as you don't do that and offload the actual checkout form, your audit expenses will stay near zero—submitting the form is all it takes.

AAleyna E***MemberCommunity member
Joined
Aug 2024
Message
80
#8

To keep this painless, follow this order: 1) Get written confirmation from your provider on which specific SAQ type they require. 2) Fill out the questionnaire on their portal and sign the AOC. 3) If your processor requires quarterly external vulnerability scans (ASV scans), set them up for your checkout domain.

LLale Y***Member
Job title
Social media manager
Sector
Software
Organization type
120-person company
Joined
Aug 2024
Message
377
#9

We have a "PCI Self-Assessment" tab in our portal too... If we fill it out ourselves and accidentally check the wrong box on a technical question does that trigger legal liability or an immediate fine, or is the system just looking for a general self-declaration?

Edit: asked below, I wrote the answer in the second message.

İİlker Ö***Expert
Job title
Store associate
Sector
Furniture manufacturing
Organization type
family business
Joined
Jul 2022
Message
9
#10

dont stress every growing merchant goes through this... processors send repeated reminders before slapping you with fees... anyway if you get stuck on a question, reach out to your gateways live chat support—theyll tell you straight up which option to select based on your setup.

GGürkan Y***Member
Job title
Chief Technology Officer
Sector
Cleaning services
Organization type
8-person team
Joined
Aug 2023
Message
7

Doki · Server maintenance contract · 2024

#11

Quick summary for newcomers: If 2FA is on, a stolen password alone is useless.

Proven by experience.

TTolga G***Veteran
Job title
Secretary
Sector
Plastic
Organization type
regional distributor
Joined
Jan 2024
Message
138
#12

i didn't know that.. but the real issue isn't the number but what it's based on.

im also curious if anyone does it differently.

EEfe A***Member
Job title
System support specialist
Sector
Software
Organization type
8-person team
Joined
Jul 2022
Message
136

Doki · Infrastructure migration · 2025

#13

Generally correct, but one part is missing. The real issue isn't the number, but what it's based on.

If you have questions, write them; I'll answer as best I can.

DDoruk T***MemberCommunity member
Joined
Jul 2023
Message
23
#14

Let me write how it's done in practice. When you try to change everything at once, nothing settles.

Good luck with that.

PPolat S***MemberCommunity member
Joined
Mar 2024
Message
110
#15

Let me share my experience. The real issue isn't the number, but what it's based on.

Hope this helps.

BBeyza B***MemberCommunity member
Joined
Jul 2025
Message
254
#16

i went through the same thing.

SSinan Y***Member
Job title
Graphic Designer
Sector
IT services
Organization type
early-stage startup
Joined
Dec 2023
Message
25
#17

Good call starting this thread.

FFerhat G***New memberCommunity member
Joined
May 2026
Message
180
#18

Thanks for writing this, that's the right way. Trying to do this alone is the most expensive way.

Correct me if I'm wrong.

PPerihanMember
Job title
Corporate communications
Organization type
regional distributor
Joined
Dec 2023
Message
118
#19

The answer above hits the nail on the head. Forgotten test environments are more often the entry point than live systems.

If you scold false alarms, nobody will report again. Correct me if I'm wrong.

SSinan Z***Member
Job title
Studio Founder
Sector
Media and publishing
Organization type
early-stage startup
Joined
Feb 2023
Message
165
#20

Correct.

Reply