BAMS featured image showing a secure online payment checkout protected by PCI DSS payment security.

Don’t Have Dangerous Gaps in PCI Compliance

Last Updated on September 4, 2026 by Dimitri Akhrin

How to Choose PCI-Compliant Payment Processing for Your Business

PCI Compliance Depends on More Than the Processor You Choose

PCI compliant payment processing should be part of the conversation before a business decides how it will accept cards. But choosing a processor that follows PCI DSS does not automatically make the merchant compliant.

The way your checkout is built matters. Where card data enters the payment flow matters. Which systems can affect that payment page matters too.

That makes PCI compliance less about finding a processor with the right security badge and more about understanding how responsibilities are divided between your business and every payment provider involved.

When you’re looking for a payment processing service so you can make personal online transactions, you might just use the first thing you come across. But when it comes to your business, you want to back up your choice with some research. Different payment processing tools, like PayPal, Stripe, and BAMS, offer a wide array of benefits and supplemental features. The most important thing for your business, however, is PCI compliance.

TL;DR

  • Using a PCI-compliant processor does not automatically make your business PCI compliant – Merchants still need to understand their own responsibilities, verify that third-party providers are compliant and complete the appropriate PCI validation for their payment environment.
  • Your checkout design can significantly change your PCI scope – A hosted checkout, embedded payment form and merchant-controlled payment page can create very different security and validation requirements depending on where card data enters the transaction.
  • Outsourcing card entry does not eliminate website security requirements – Even when a third party handles payment fields, the merchant’s website can still affect payment security through scripts, redirects, plugins and other components.
  • Every payment channel needs to be considered – eCommerce checkout, recurring billing, virtual terminals, invoices and in-person payments can create different PCI responsibilities, so merchants should map every way customers provide payment information.
  • PCI compliance is an ongoing process, not a one-time setup – Websites, integrations, scripts and employee access change over time, which means merchants need to continue reviewing their environment and completing applicable questionnaires, scans and other validation requirements.

How does this apply to your business?

PCI DSS or the Payment Card Industry Data Security Standard is a list of standards for securing payment processing details. If your company even touches payment information, whether you’re storing the information or just accepting, processing, or transmitting it, then you’re responsible for maintaining a secure environment for that data. That’s why more and more companies are using third-party providers to handle payment processing. If payments are routed through another site entirely, your liabilities are limited.

2026 clarification: Outsourcing payment processing can reduce the number of PCI DSS requirements that directly apply to the merchant, but it does not remove the merchant’s responsibility for PCI compliance.

The PCI Security Standards Council states that merchants using third-party payment providers still need to confirm that those providers are PCI DSS compliant for the services they perform, maintain appropriate agreements, monitor their compliance status and understand which security responsibilities belong to each party.

Merchants also still need to validate their own PCI compliance using the appropriate method, which may include a Self-Assessment Questionnaire.

BAMS infographic showing how PCI DSS responsibilities are shared between merchants and third-party payment providers.

Outsourcing payment processing can reduce PCI scope, but merchants still have responsibilities for their website, provider relationships and compliance validation.

What PCI DSS Actually Covers

PCI DSS applies to businesses that store, process or transmit payment card information. It also reaches systems and environments that can affect the security of cardholder data.

The standard addresses areas such as protecting stored account data, securing systems and networks, managing access, monitoring environments and regularly testing security controls.

The exact requirements that apply to one merchant can look very different from those that apply to another.

A small eCommerce store that sends customers to a compliant third-party checkout may have a much smaller PCI scope than a business whose own website collects card numbers directly.

Both still need to understand their responsibilities.

Your Checkout Design Can Change Your PCI Scope

BAMS infographic comparing hosted checkout, embedded payment forms and merchant-controlled payment pages under PCI DSS.

Where card data enters the transaction can change which PCI DSS requirements apply to an eCommerce merchant.

This is one of the most important distinctions for eCommerce businesses.

PCI SSC separates different payment-page implementations because the merchant’s website can play very different roles in each one.

Hosted or Redirected Checkout

A customer may leave the merchant’s checkout and complete payment on a page supplied by a PCI DSS compliant payment provider.

This can significantly reduce the merchant’s direct involvement with cardholder data because the third party handles the payment page itself.

Embedded Payment Form or iFrame

The customer remains on the merchant’s website visually, but the fields that collect card information come directly from the compliant payment provider.

To qualify for SAQ A, PCI SSC says all elements of the payment page used to collect or process cardholder data must originate from PCI DSS compliant service providers, along with the other applicable eligibility requirements.

Merchant-Controlled Payment Page

If the merchant’s own website creates payment fields or otherwise controls elements involved in collecting payment information, the PCI scope can become broader.

The checkout may look almost identical to the customer while creating very different security responsibilities behind the scenes.

Outsourcing Card Data Does Not Mean You Can Ignore Your Website

This has become particularly important under PCI DSS v4.x.

Attackers do not necessarily need to compromise the payment processor itself. They can attack the merchant’s website and change scripts, redirect customers or manipulate the payment experience before the transaction reaches the legitimate provider.

That is why PCI SSC added stronger eCommerce protections around payment-page scripts and tampering.

Current SAQ A requirements for eCommerce merchants using embedded payment forms include confirmation that the merchant’s site is protected against script attacks that could affect the payment process.

PCI SSC also clarified in 2026 that SAQ A merchants with eCommerce webpages can have external vulnerability-scanning requirements even when the site redirects payment processing to a third party or uses a compliant provider’s embedded iframe.

In other words, outsourcing card entry can reduce your PCI scope. It does not make the merchant’s own website irrelevant to payment security.

How do you know which processing service provides the best compliance?

The best way to know which service is for you is to start studying your own business. How do you usually get paid? Online stores will have a lot of individual transactions. Subscription service providers, whether they provide online services or something physical like landscaping, may have automatic payments. If your company provides freelance services, you may need to invoice clients for monthly services or varying amounts.

Once you know how your company sends requests for payment and receives payment, start looking for exceptions. Stripe, for example, doesn’t have an inbuilt invoicing tool so you will need to check your additional third-party services for PCI compliance. PayPal does offer more PCI compliance, but only at certain levels of subscription.

2026 update: The Stripe and PayPal examples above reflect older versions of those platforms and should not be used as a current comparison. Payment platforms have changed considerably, and PCI compliance should not be judged by whether one provider has invoicing while another does not.

The more useful question is: what parts of the payment process does the provider handle, and what remains under your control?

Start by Mapping How Your Business Gets Paid

Before comparing processors, write down every way customers can pay you.

An eCommerce store may accept card payments through a shopping cart. A subscription business might automatically bill saved payment credentials. A service company may email invoices. A restaurant could accept cards in person and through online ordering.

Each channel can create a different payment environment.

If you accept cards through several channels, do not assume that one compliant integration automatically covers the others.

For example, an eCommerce checkout may outsource card entry entirely while employees also enter phone orders through a virtual terminal. Both payment flows need to be considered when determining the correct PCI validation requirements.

What to Ask a Payment Provider About PCI Compliance

Do not settle for “yes, we’re PCI compliant.” Ask how the provider helps your business maintain compliance.

  • Is the payment service PCI DSS compliant? Verify that the provider’s compliance covers the services you plan to use.
  • Where does cardholder data enter the transaction? Find out whether your website, application or employees ever handle card numbers directly.
  • Which SAQ applies to my setup? Hosted checkout, embedded forms and merchant-controlled payment pages can have different validation requirements.
  • Does my website require vulnerability scans? Current PCI DSS requirements can require scans even for some merchants that outsource payment collection.
  • Who handles security updates? Know whether your business, eCommerce platform, developer or payment provider maintains each part of the checkout.
  • What are our shared responsibilities? PCI SSC expects merchants to understand which party owns each security responsibility.

A PCI-Compliant Gateway Helps, but It Is Not the Whole Answer

A secure payment gateway can reduce the amount of sensitive card information your business handles directly.

BAMS currently offers payment gateway solutions that connect eCommerce checkout, processing and reporting while supporting PCI-compliant payment environments.

That can simplify security compared with building payment handling from scratch.

But using a PCI-compliant gateway does not eliminate the merchant’s PCI requirements. BAMS’ current PCI guidance makes the same distinction: merchants using compliant gateways still need to maintain and validate their own applicable PCI DSS compliance.

PCI Compliance Is Not a One-Time Setup

A business can choose a secure payment provider today and still create problems later.

Websites change. Plugins get added. Developers install scripts. Employees receive new access. Checkout flows get redesigned.

PCI compliance needs to keep up with those changes.

BAMS currently requires its merchants to complete PCI DSS compliance after account approval and provides a guided process that includes the applicable Self-Assessment Questionnaire and security scanning requirements.

Merchants can review BAMS PCI compliance support for help understanding the requirements that apply to their payment environment.

Do Not Forget Third-Party Scripts

An eCommerce payment page may contain far more than payment code.

Analytics tools, advertising tags, chat widgets and other third-party scripts can run on the same website. Under PCI DSS v4.x, merchants need to pay closer attention to whether those scripts can affect the security of the payment environment.

A script that has nothing to do with payments may not automatically create a PCI issue. But if it can influence payment-page security, the business needs to understand that risk.

This is one reason merchants should be cautious about continually adding plugins and scripts without knowing what access they have.

PCI Compliance and Payment Security Are Related but Not Identical

Passing a PCI validation does not mean fraud or security incidents are impossible.

PCI DSS provides a baseline for protecting payment account data. Businesses should still use appropriate fraud controls, strong authentication, secure software practices and monitoring based on their risk.

For an online merchant, that may include AVS and CVV checks, transaction-risk tools and clear procedures for reviewing suspicious orders.

BAMS also provides eCommerce merchant services that combine payment processing with gateway, fraud-management and reporting options for online businesses.

What to Compare Before Choosing a Payment Processor

Question Why It Matters
Is the provider PCI DSS compliant? Your provider needs to protect the payment functions it performs.
Who collects the card data? The answer can significantly affect your PCI scope.
What SAQ applies? Different payment integrations can require different validation paths.
Are website scans required? Current PCI DSS requirements can apply vulnerability scanning to eCommerce webpages even when payment collection is outsourced.
Who manages scripts and updates? Your website can affect payment security even when card fields come from a third party.
What support is included? A provider that helps merchants understand their responsibilities can make ongoing compliance easier to manage.

Frequently Asked Questions – PCI Compliant Payment Processing

What is PCI DSS?

PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of security requirements designed to protect payment account data and applies to organizations that store, process or transmit cardholder information or can affect its security.

Does every business that accepts credit cards need PCI compliance?

Yes. PCI DSS applies to businesses accepting payment cards regardless of their size. The specific requirements and validation method depend on how the business accepts and handles card information.

Does using a third-party payment processor make my business PCI compliant?

No. Outsourcing payment processing can reduce the number of requirements that directly apply to your environment, but merchants still need to ensure their providers are compliant and complete their own applicable PCI validation.

Does using a PCI-compliant gateway eliminate PCI requirements?

No. A compliant gateway can reduce exposure to cardholder data and may reduce PCI scope, but the merchant still has responsibilities under PCI DSS.

What is SAQ A?

SAQ A is a PCI DSS Self-Assessment Questionnaire intended for eligible card-not-present merchants that outsource payment account data functions to compliant third-party service providers and meet the questionnaire’s other eligibility requirements.

Can an embedded payment form qualify for SAQ A?

It can, provided all payment-page elements involved in collecting or processing cardholder data originate from PCI DSS compliant service providers and all other SAQ A eligibility criteria are satisfied.

Do eCommerce merchants using redirects still need security scans?

PCI SSC clarified in 2026 that current SAQ A requirements include applicable external vulnerability scanning for merchant eCommerce webpages, including certain sites that redirect payment processing to third parties or embed third-party payment forms.

How often does PCI compliance need to be reviewed?

PCI compliance is ongoing. Validation requirements can include an annual Self-Assessment Questionnaire, vulnerability scans and other activities depending on the merchant’s environment and compliance program.

Most e-commerce payment processing platforms are all but required to have PCI compliance, but your company may be liable for any gaps. So look for those gaps before finalizing your choice. Contact us to know about more ways to choose the best platform for your business.

Sources