3 ms·
That's not universally true. Unfortunately, the PCI DSS is somewhat subjective and enforced inconsistently, so it's difficult to definitively answer what's requ
by dan_manges 14y ago
That's not universally true. Unfortunately, the PCI DSS is somewhat subjective and enforced inconsistently, so it's difficult to definitively answer what's required for PCI compliance for a certain type of payments integration.
Even for merchants that use third-party hosted payment forms, it's still common to need to complete SAQ A (a short self-assessment questionnaire) and have quarterly network scans. For example, with PayPal[1]: "Our hosted solution takes a lot of the work out of meeting these standards. The only remaining requirements are a Security Self-Assessment Questionnaire (SAQ) and Quarterly Security Scans."
According to MasterCard[2]: "All merchants that store, process, or transmit cardholder data must be PCI compliant." It's subjective whether using Stripe.js could be considered transmitting cardholder data.
Visa[3] holds Acquirers responsible for ensuring their merchants are PCI compliant. Requirements vary depending on processing volume: "In addition to adhering to the PCI DSS, compliance validation is required for Level 1, Level 2, and Level 3 merchants, and may be required for Level 4 merchants." Notice that for Level 4 merchants, validation only may be required, although those merchants should still be adhering to the PCI DSS.
Stripe has several PCI requirements in their terms of service[4], and their FAQ does seem to indicate[5] that merchants have some responsibility for PCI compliance. According to the TOS "It is your responsibility to comply with these standards." and according to the FAQ: "Most Qualified Security Assesors (QSAs) will want to talk through many of the implementation details before giving an opinion"
Disclosure: I work for Braintree.
Disclaimer: This response is my opinion; I'm not speaking for Braintree.
[1] https://merchant.paypal.com/us/cgi-bin/?cmd=_render-content&content_ID=merchant/pci_compliant_solution https://merchant.paypal.com/us/cgi-bin/?cmd=_render-content&...
[2] http://www.mastercard.com/us/company/en/whatwedo/determine_merchant.html http://www.mastercard.com/us/company/en/whatwedo/determine_m...
[3] http://usa.visa.com/merchants/risk_management/cisp_merchants.html http://usa.visa.com/merchants/risk_management/cisp_merchants...
[4] https://stripe.com/terms/US https://stripe.com/terms/US
[5] https://answers.stripe.com/questions/what-exactly-do-i-need-to-do-on-my-end-for-pci-compliance https://answers.stripe.com/questions/what-exactly-do-i-need-...