forumNew topic

Payment gateway mentioned PCI DSS compliance levels: which level are we and what will it cost?

SSinan Z***Member
Job title
Studio Founder
Sector
Media and publishing
Organization type
early-stage startup
Joined
Feb 2023
Message
165
#1

We run a niche e-commerce store selling custom sports equipment in the US market. We host on our own infrastructure and process around 40,000 credit card transactions per year. We accept card payments via an integration with an external payment gateway.

We recently received an official notice from our payment provider stating that we must comply with PCI DSS standards or our account could face suspension or additional per-transaction penalty fees. The notice mentions different compliance levels and security reports but doesn't go into detail.

With an annual volume of 40k transactions, which PCI DSS compliance level do we fall under? Do we have to hire an external auditor and spend thousands of dollars, or can we complete this just by filling out a self-assessment form? What is the average annual cost of this process?

KKemal G***Member
Job title
Store associate
Sector
IT services
Organization type
medium-sized business
Joined
Apr 2023
Message
7

Doki · Incident response support · 2024

Most Helpful#2

Short answer: With 40k e-commerce card transactions a year you fall under the Level 3 merchant tier and do not need an on-site external audit. At this level, compliance is achieved via an annual Self-Assessment Questionnaire completed in-house and depending on how your payment form is integrated, quarterly external network vulnerability scans.

Card brand rules classify merchants processing between 20,000 and 1,000,000 e-commerce transactions annually as Level 3. What you need to do depends on whether cardholder data touches your servers: 1) If your customer is redirected to a hosted payment page or you use an embedded secure iframe provided by the gateway card data never touches your servers. In that case, completing SAQ A is enough, and network scans are usually not required or very limited. 2) If you collect card details through a form on your own servers and pass them to the gateway API in the background, your scope expands significantly. You'll need to complete SAQ A-EP and have quarterly external network scans performed by an Approved Scanning Vendor.

On the cost side hiring an independent auditor is only mandatory for top-tier Level 1 merchants processing over 6 million transactions annually. For Level 3 if external vulnerability scans are required annual subscriptions from authorized scanning vendors run roughly $200 to $600. The questionnaire itself can be completed directly by your in-house technical lead with no need for outside consulting fees.

MMehmet M***Member
Job title
Digital marketing specialist
Sector
Education
Organization type
regional distributor
Joined
Nov 2025
Message
302
#3

The critical factor is your payment form architecture. Inspect the source code of the card number input on your checkout page. If that field sits inside an iframe loaded from your payment gateway's domain, you're golden. If you collect it directly via your own form using JavaScript, your scope and compliance overhead go up drastically.

VVolkan U***MemberCommunity member
Joined
Feb 2024
Message
56
#4

We went through this last year for our site doing around 60k transactions. We logged into the portal our processor linked us to, filled out an SAQ A questionnaire of about 20 questions, and paid an approved scanning vendor $350 for the year. The whole thing took maybe 2 hours.

İİlker K***Member
Job title
Information Security Specialist
Sector
Glass
Organization type
a company within a holding
Joined
Jul 2025
Message
185
#5

Just go to your payment provider's dashboard, there's usually a compliance wizard ready to walk you through it. Once you check that you don't store card data and collect payments via a third-party hosted iframe the questionnaire drops down to the bare minimum.

SSelim K***Member
Job title
Sales Manager
Sector
Media and publishing
Organization type
120-person company
Joined
Mar 2025
Message
305

Doki · SEO consulting · 2024

#6

You definitely aren't storing card numbers, expiration dates, or CVVs in your database, right? If you're accidentally printing card data even into log files, the questionnaire type and your liability completely change.

MMehmet Ç***MemberCommunity member
Joined
Apr 2023
Message
277
#7

payment processors send these automated warnings every year to scare people. if you're using an embedded form filling out the questionnaire takes 45 minutes tops definitely don't go handing thousands of dollars to an auditor or anything.

Correction: I misremembered the figure, it was a bit lower.

ÖÖmer N***MemberCommunity member
Joined
Jun 2022
Message
62
#8

A ton of agencies have popped up in the market asking small businesses for 3,000-5,000 dollars under the guise of 'PCI DSS consulting'. A small merchant that doesn't store card data on their own server doesn't need to spend a single dime on such consultations.

MMehmet I***MemberCommunity member
Joined
May 2024
Message
3
#9

The core rationale behind PCI DSS rules is reducing cardholder data exposure to zero. The further away you keep payment data from your server when building your infrastructure, the lower your legal liability and your annual scanning and compliance costs will be.

EEsra A***Member
Job title
Information Security Specialist
Sector
Paper
Organization type
boutique agency
Joined
Nov 2024
Message
162
#10

when that first email came, we panicked thinking our account would get shut down and called everyone up to our accountant. tbh turns out we just had to check off an online checklist and don't worry at all; if you've moved your system to an external iframe, the process is pretty much painless.

TTülay K***ExpertCommunity member
Joined
May 2023
Message
182
#11

I'm curious too.

OOkan I***Member
Job title
Front office accounting
Sector
Cosmetics
Organization type
sole proprietorship
Joined
Nov 2023
Message
260
#12

There's one point I'm curious about. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

If you don't write this down from the start, it leads to arguments later. If you have questions, write them; I'll answer as best I can.

TTaner Y***MemberCommunity member
Joined
Dec 2023
Message
166
#13

Three different views emerged they all complement each other. Start with a small trial; don't commit to everything at once.

I'm also curious if anyone does it differently.

YYavuz G***Member
Job title
Courier coordinator
Sector
Packaging
Organization type
family business
Joined
Jun 2025
Message
45

Doki · Log management setup · 2023

#14

I've been dealing with this for a long time. Processes without records never improve, because you don't know what to fix.

I'm also curious if anyone does it differently.

HHilal V***Member
Job title
Board member
Sector
Energy
Organization type
medium-sized business
Joined
Aug 2023
Message
377
#15

My perspective changed after experiencing that. If 2FA is on, a stolen password alone is useless.

If you don't write this down from the start, it leads to arguments later. This is my opinion, I'm not claiming it's absolute truth.

PPolat G***Member
Job title
Chief Technology Officer
Sector
Printing
Organization type
8-person team
Joined
Aug 2023
Message
275
#16

Let me clarify the technical side. Everything goes well for the first three months; problems arise in the fourth.

That's all, sorry if I went on too long.

FFiliz D***Expert
Job title
Customer service representative
Sector
Logistics
Organization type
cooperative
Joined
Jun 2023
Message
170
#17

i completely agree then if you dont write this down from the start it leads to arguments later.

if you post the result here, it will help others too.

GGökhan C***MemberCommunity member
Joined
Apr 2024
Message
336
#18

We experienced almost the exact same thing last year. Forgotten test environments are more often the entry point than live systems.

ZZafer Ö***Member
Job title
Production planning
Sector
Machinery manufacturing
Organization type
a company within a holding
Joined
Apr 2023
Message
247
#19

Could you elaborate on that? Everyone rushing into pci dss compliance levels gets stuck at the same point.

Mistakes made on the pci dss compliance levels side are usually reversible but expensive. Just leaving this note it might be useful.

BBeyza K***Member
Job title
Store Manager
Sector
Electrical-electronics
Organization type
cooperative
Joined
Dec 2025
Message
165
#20

Let me speak from the other side; I'm on the supplier side. If you don't write this down from the start, it leads to arguments later.

If you have questions, write them; I'll answer as best I can.

Reply