- Job title
- Studio Founder
- Sector
- Media and publishing
- Organization type
- early-stage startup
- Joined
- Feb 2023
- Message
- 165
We run a niche e-commerce store selling custom sports equipment in the US market. We host on our own infrastructure and process around 40,000 credit card transactions per year. We accept card payments via an integration with an external payment gateway.
We recently received an official notice from our payment provider stating that we must comply with PCI DSS standards or our account could face suspension or additional per-transaction penalty fees. The notice mentions different compliance levels and security reports but doesn't go into detail.
With an annual volume of 40k transactions, which PCI DSS compliance level do we fall under? Do we have to hire an external auditor and spend thousands of dollars, or can we complete this just by filling out a self-assessment form? What is the average annual cost of this process?