4 ms·
Any merchant that accepts credit card payments must be PCI compliant. Even if cardholder data never touches the merchant's servers, the merchant still falls und
by michaelfairley 14y ago
Any merchant that accepts credit card payments must be PCI compliant. Even if cardholder data never touches the merchant's servers, the merchant still falls under the scope of SAQ A[1].
1: https://www.pcisecuritystandards.org/documents/pci_saq_a_v2.pdf https://www.pcisecuritystandards.org/documents/pci_saq_a_v2....