Get Ready for the Future! Download the State of Checkout 2025 White Paper Today
Platform

Product & Solutions

Learn more about the only open payments platform built for global commerce

Pricing

Solutions

Open Payments Connectivity
Payment Token Ownership & Portability
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Agentic

One integration to sell inside ChatGPT, Gemini, and every agentic platform

Composer

Coming soon

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Resources

The Open Payments Library

Take a look at all of our resources and get the information you need to grow your business

View all Resources

Featured resources

The Payments Guide to Expansion into LATAM
Accelerate Your Growth by Expanding into Brazil
Security, Compliance, and AI: Inside Spreedly’s 2025 Foundation:

Spreedly Makes Agentic Commerce a Live Channel for Merchants

Read More
Company

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Parter Integrations

Partners & Integrations

Integrations Ecosystem
Our Partners

Latest Partner News

Webinars

Paysafe Unveils Strategic Partnership with Spreedly

Featured Partner

PayPal
Product & Solutions

Product & Solutions

Learn more about the only open payments platform built for global commerce

Pricing

Solutions

Open Payments Connectivity
Payment Token Ownership & Portability
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Agentic

One integration to sell inside ChatGPT, Gemini, and every agentic platform

Composer

Coming soon

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Pricing
Resources

The Open Payments Library

Take a look at all of our resources and get the information you need to grow your business

View all Resources

Featured resources

The Payments Guide to Expansion into LATAM
Accelerate Your Growth by Expanding into Brazil
Security, Compliance, and AI: Inside Spreedly’s 2025 Foundation:

Spreedly Makes Agentic Commerce a Live Channel for Merchants

Read More
Developers

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Integrations

Partners & Integrations

Integrations Ecosystem
Our Partners

Latest Partner News

Webinars

Paysafe Unveils Strategic Partnership with Spreedly

Featured Partner

PayPal
Company

Company

About
Leadership
Careers
Contact Us
News
Pricing
Log In
See a Demo
Log In
See a Demo

Product & Solutions

Learn more about the only open payments platform built for global commerce

Pricing

Solutions

Open Payments Connectivity
Payment Token Ownership & Portability
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Agentic

One integration to sell inside ChatGPT, Gemini, and every agentic platform

Composer

Coming soon

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Platform

Product & Solutions

Learn more about the only open payments platform built for global commerce

Pricing

Solutions

Open Payments Connectivity
Payment Token Ownership & Portability
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Agentic

One integration to sell inside ChatGPT, Gemini, and every agentic platform

Composer

Coming soon

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Use Cases
Resources

The Open Payments Library

Take a look at all of our resources and get the information you need to grow your business

View all Resources

Featured resources

The Payments Guide to Expansion into LATAM
Accelerate Your Growth by Expanding into Brazil
Security, Compliance, and AI: Inside Spreedly’s 2025 Foundation:

Spreedly Makes Agentic Commerce a Live Channel for Merchants

Read More
Company

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Blog
Platform

Product & Solutions

Learn more about the only open payments platform built for global commerce

Pricing

Solutions

Open Payments Connectivity
Payment Token Ownership & Portability
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Agentic

One integration to sell inside ChatGPT, Gemini, and every agentic platform

Composer

Coming soon

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Use Cases
Resources

The Open Payments Library

Take a look at all of our resources and get the information you need to grow your business

View all Resources

Featured resources

The Payments Guide to Expansion into LATAM
Accelerate Your Growth by Expanding into Brazil
Security, Compliance, and AI: Inside Spreedly’s 2025 Foundation:

Spreedly Makes Agentic Commerce a Live Channel for Merchants

Read More
Company

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Blog
Log In
See Demo

Product & Solutions

Learn more about the only open payments platform built for global commerce

Pricing

Solutions

Open Payments Connectivity
Payment Token Ownership & Portability
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Agentic

One integration to sell inside ChatGPT, Gemini, and every agentic platform

Composer

Coming soon

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Back to Guides

Payment Security

October 2, 2026

The Master Guide to PCI Compliance

What PCI DSS v4.0.1 requires, how merchant levels and SAQs work, what compliance costs, and how routing card data through a vault reduces your scope.

In this guide

Share

PCI compliance is the baseline security standard for any business that stores, processes, or transmits card data, and it's mandatory if you want to keep accepting Visa, Mastercard, or American Express. The standard also changed meaningfully over the last two years, so a setup that passed review in 2023 may not pass today. This guide breaks down what PCI compliance actually requires, what it costs, and which path applies to your business.

What is PCI compliance? 

PCI compliance is a set of security standards for any business that handles credit card transactions. The PCI Security Standards Council sets and updates these standards, and businesses must document and prove compliance annually.

PCI compliance isn't required by law. It's required by contract. Visa, Mastercard, American Express, Discover, and JCB all mandate it as a condition of accepting their cards, and your acquiring bank enforces it through your merchant agreement. Skip it and you risk fines passed down from the card brands and, eventually, losing the ability to process card payments at all.

Any business that transmits, stores, handles, or accepts card data must comply, regardless of size or transaction volume. The specific level of compliance required depends on your transaction volume, covered below.

Some gateways and payment processors claim their drop-in card widgets exempt you from PCI compliance entirely. What tools like Spreedly's checkout SDKs and iFrame actually do is reduce your compliance burden. You still have to certify, but with far less effort than if you handled raw card data yourself.

Merchants, networks, and service providers each carry a piece of the standard

A handful of parties make the card payment ecosystem work, and each one has a defined role under PCI DSS.

  • Merchants sell goods or services and accept card payments to do it.
  • Card networks, known by brand names like Visa and Mastercard, connect issuing banks (which issue cards to cardholders) and acquiring banks (which let merchants accept those cards).
  • Cardholders are the customers paying with a card. Cardholder data includes the primary account number, cardholder name, expiration date, and service code. Add sensitive authentication data (like the CVV or chip data) and there's a lot to protect, which is the entire point of PCI DSS.
  • Service providers store or process cards on behalf of merchants or cardholders. Spreedly is a service provider, along with companies like Stripe, plus any payment gateway or point-of-sale vendor.
  • Payment software vendors build the hardware and software merchants use to process transactions. They're governed by the PCI Software Security Framework, made up of the Secure Software Standard and the Secure Software Lifecycle (Secure SLC) Standard. The framework replaced the now-retired Payment Application Data Security Standard (PA-DSS).
  • The PCI Security Standards Council, founded by the major card networks, writes the Data Security Standards that every other party in this list has to follow.
  • Qualified Security Assessors (QSAs) are certified by the Council to audit and validate PCI DSS implementations.

Spreedly is a service provider and holds Level 1 (L1) certification, the highest level available, validated annually by a QSA. Spreedly isn't classified as a payment software vendor, since the platform isn't installed in an environment outside Spreedly's control.

PCI scope determines both your cost and your risk

Scope is every system component involved in processing, storing, or transmitting card data, collectively called the cardholder data environment (CDE). Getting scope right early is cheaper than fixing it later. A single server hosting one page that redirects to an offsite payment processor has minimal scope. A system with databases, log aggregators, application servers, and load balancers all touching card data has much larger scope, and there's often little room to shrink it once that architecture exists.

Scope creep happens in a few predictable ways: granting CDE access to people who don't need it, connecting unrelated systems to the CDE, or running unrelated software on in-scope components. Every one of those choices expands what an assessor has to review and what you have to secure.

Both merchants and service providers reduce scope by outsourcing card handling to a PCI DSS-compliant provider. Using Spreedly to store and process cards, for example, can limit a merchant's scope to the page that collects the card number. The PCI SSC's scoping guidance is the standard reference for working through scope decisions in detail.

Assessment path depends on transaction volume and merchant level

PCI certification happens one of two ways: a self-assessment questionnaire (SAQ) you complete yourself, or a Report on Compliance (ROC) produced by a QSA. Which path you're eligible for depends on your merchant level, and only your acquiring bank can officially assign that level.

Each card network sets its own merchant level thresholds, and they don't all match. The table below uses Visa's thresholds, which are the most commonly cited. Mastercard, American Express, and Discover each publish their own criteria, so check with your acquiring bank for the network mix you actually process.

SA. Level 2 and 3 merchants may need to do the same if their acquiring bank requires it, but most can self-assess with the appropriate SAQ. Level 4 merchants typically self-assess as well. Ask your acquiring bank which level applies to you before committing time to a compliance path, since they're the ones who assign it.

SAQ A and SAQ A-EP require different levels of scrutiny

How your payment page is built determines which SAQ applies. SAQ A is the lighter path, reserved for e-commerce merchants who fully outsource cardholder data handling to a compliant third party and never touch card data on their own systems. SAQ A-EP applies when a merchant's own website has more influence over the security of the transaction, even without directly touching the card number.

SAQ A has shifted twice under v4.x. The version released alongside PCI DSS v4.0.1 in October 2024 included the new payment-page script controls (Requirements 6.4.3 and 11.6.1). In January 2025, the Council revised SAQ A to remove those two requirements and replace them with a new eligibility criterion: the merchant must confirm its site is not susceptible to attacks from scripts that could affect its e-commerce systems. That revised SAQ A has been the only valid version since March 31, 2025.

In practice, this means SAQ A eligibility now depends on protecting the page that hosts or redirects to the payment form, not just on outsourcing the form itself. Merchants who can't make that confirmation should expect to meet the script controls another way or move to SAQ A-EP.

Hosted iFrames keep most merchants inside SAQ A

A properly implemented iFrame, where all payment page content loads from the payment service provider rather than the merchant's own domain, remains one of the most common ways merchants qualify for SAQ A instead of the more demanding SAQ A-EP.

Spreedly supports four ways to collect payment methods: iFrame, Express, Javascript API, and Direct API. The iFrame was built specifically to give merchants design flexibility while keeping SAQ A eligibility intact. The Javascript API and Direct API give merchants more control over the payment page, which also brings more of that page into scope. See Spreedly's developer documentation for implementation details, or read more about Spreedly's iFrame approach.

Compliance costs scale with scope and assessment path

What PCI compliance costs depends on scope (how much of your environment is in scope) and assessment path (self-assessment versus a QSA-led ROC), and those two factors interact with nearly every other cost driver. A narrow-scope Level 4 merchant using a hosted payment page faces a fundamentally different cost profile than a Level 1 service provider running its own infrastructure.

The biggest line items tend to be the same across businesses: QSA fees if you need a ROC, quarterly vulnerability scans, remediation work to close gaps, and the internal staff time to document and maintain controls. Scope drives every one of them, which is why reducing scope is usually the fastest way to reduce cost.

Whatever the assessment path, compliance isn't a one-time cost. PCI DSS requires ongoing maintenance, including quarterly scans and annual re-assessment, so budget for it as a recurring line item rather than a project expense.

Proving compliance means an SAQ or a ROC, plus a signed AOC

Validating compliance takes one of two forms. Smaller organizations complete a Self-Assessment Questionnaire, ideally led by someone who understands the system's full scope. Larger organizations engage a QSA, who determines scope, reviews configurations and access controls, interviews staff, and produces a detailed Report on Compliance documenting every finding.

Either path ends the same way: signing an Attestation of Compliance (AOC), a formal declaration that your business meets the applicable PCI DSS requirements. The merchant level determines which path you're required to take, not how compliant you actually are. A Level 4 merchant and a Level 1 merchant can both be fully compliant. They just prove it differently.

The 12 PCI DSS requirements map to six core objectives

PCI DSS v4.0.1 has 12 requirements organized under six goals for protecting card data. Each requirement breaks down into dozens of sub-requirements and testing procedures that an assessor checks. That's why a full Report on Compliance (ROC) runs long even for a moderately complex environment.

Build and maintain a secure network and systems

  • 1. Install and maintain network security controls. Firewalls, cloud security groups and other controls that filter traffic into and out of the CDE.
  • 2. Apply secure configurations to all system components. Changing vendor defaults, removing unneeded services and hardening system configurations.

Protect account data

  • 3. Protect stored account data. Storing as little data as possible, never keeping sensitive authentication data after authorization, making stored PAN unreadable and managing encryption keys.
  • 4. Protect cardholder data with strong cryptography during transmission over open, public networks. Strong TLS and trusted certificates wherever card data crosses a public network.

Maintain a vulnerability management program

  • 5. Protect all systems and networks from malicious software. Anti-malware and anti-phishing controls.
  • 6. Develop and maintain secure systems and software. Secure development, patching, protecting public-facing web apps and managing payment page scripts.

Implement strong access control measures

  • 7. Restrict access to system components and cardholder data by business need to know. Least privilege, role-based access and regular access reviews.
  • 8. Identify users and authenticate access to system components. Unique user IDs, password rules and multi-factor authentication.
  • 9. Restrict physical access to cardholder data. Facility access, media handling and protecting point-of-interaction devices.

Regularly monitor and test networks

  • 10. Log and monitor all access to system components and cardholder data. Audit logs, log review, time sync and log retention.
  • 11. Test security of systems and networks regularly. Quarterly internal and external (ASV) scans, penetration testing, and intrusion and change detection.

Maintain an information security policy

  • 12. Support information security with organizational policies and programs. Security policy, risk assessments, awareness training, third-party provider oversight and incident response.

What changed from v3.2.1

  • Requirement 1 used to be about firewalls. It now covers network security controls of any kind, including cloud-native and other non-traditional setups.
  • Requirement 2 is about secure configuration, not password policy. Password and authentication rules are in Requirement 8.
  • Requirement 8.4.2 requires MFA for all non-console access into the CDE, not only admin and remote access. It became mandatory on March 31, 2025, so expect it to come up in your next assessment.
  • Requirements 6.4.3 and 11.6.1 are new. They require you to inventory and authorize every script on your payment pages and to detect unauthorized changes to them. These also became mandatory in March 2025 and matter most for e-commerce merchants.

PCI DSS v4.0.1 is the current standard

The Council released PCI DSS v4.0 in March 2022, and v3.2.1 was retired on March 31, 2024. The Council then issued PCI DSS v4.0.1 in June 2024 as a limited revision that clarified language without adding or removing requirements. v4.0.1 is the version in effect today, and v4.0 has been superseded.

At launch, a subset of v4.0's new requirements were future-dated, meaning they counted as best practice rather than mandatory. That grace period ended on March 31, 2025.

Every one of those future-dated requirements, covering areas like multi-factor authentication for all CDE access and payment-page script protection, is now mandatory. A tokenization flow, access control policy, or logging setup that passed review under the older, lighter enforcement can fail an assessment today if it doesn't meet these controls.

A practical PCI compliance checklist to start with

Spreedly reduces PCI compliance scope and complexity

Any business accepting card payments online needs to be PCI compliant, and using a PCI Level 1 vault is one of the most effective ways to shrink that burden. Routing card collection through a compliant service provider keeps the bulk of the CDE off your own infrastructure, which means less to scope, less to assess, and less to maintain.

Staying current with a standard that changes as often as PCI DSS is a real operational cost on its own. Payment orchestration platforms like Spreedly absorb a lot of that burden by building support for new requirements directly into the platform, so customers spend less time chasing the standard and more time on their core business.

Every merchant's environment is different, and there may be steps beyond what's covered here based on your specific setup. Reach out to our team if you want help figuring out where payment orchestration fits into your compliance strategy, or read more about Spreedly's Vault to see how token portability reduces scope in practice.

Read more
Written By
Is PCI compliance required by law?

No. It's required by contract. Visa, Mastercard, American Express, Discover, and JCB make it a condition of accepting their cards, and your acquiring bank enforces it through your merchant agreement. If you don't comply, you can be fined and can eventually lose the ability to process card payments.

Does using a hosted iFrame make my business exempt from PCI compliance?

Every year. You'll complete an SAQ or a QSA-led ROC and sign an Attestation of Compliance. PCI DSS also requires quarterly vulnerability scans, so budget for compliance as an ongoing cost instead of a one-time project.

How often do I need to validate PCI compliance?

Every year. You'll complete an SAQ or a QSA-led ROC and sign an Attestation of Compliance. PCI DSS also requires quarterly vulnerability scans, so budget for compliance as an ongoing cost instead of a one-time project.

Download Free
Get My Report
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Learn More
Download Free
Get My Report
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Read more
Written By
H5 Title

Nisl aenean link in text aliquet risus elit dictumst non nulla ullamcorper. Eu euismod senectus tristique laoreet vel accumsan purus. Lectus ac ante amet risus ut sed blandit sollicitudin cras. Sagittis cursus at purus amet pellentesque sit risus.

H5 Title

Nisl aenean link in text aliquet risus elit dictumst non nulla ullamcorper. Eu euismod senectus tristique laoreet vel accumsan purus. Lectus ac ante amet risus ut sed blandit sollicitudin cras. Sagittis cursus at purus amet pellentesque sit risus.

+ 0%

We help merchants, merchant aggregators, and fintechs scale with speed & confidence.

+ 0%

We help merchants, merchant aggregators, and fintechs scale with speed & confidence.

+ 0%

We help merchants, merchant aggregators, and fintechs scale with speed & confidence.

+ 0%

We help merchants, merchant aggregators, and fintechs scale with speed & confidence.

CTA 1
CTA 2
CTA 3
Get the 2025 State of Checkout Report

1 in 4 executives reported losing over $1M annually at checkout. Find out what's driving cart abandonment and how to fix it. Learn more about:

Navigating AI Risk

Building Resilience for Global Scale

Download Now
Get an Interactive Personalized Demo

Experience how the Spreedly platform can orchestrate and optimize your payments stack.

140+ Payment Integrations

Managed Payment Vault

Learn More
Get the Payment Orchestration e-Book

You'll find everything you need to know about Payments Orchestration in this detailed guide. Find out what you should be looking for, what you'll need to get started, and how to implement changes at every stage.

Download Now

H3 Title

Nisl aenean link in text aliquet risus elit dictumst non nulla ullamcorper. Eu euismod senectus tristique laoreet vel accumsan purus. Lectus ac ante amet risus ut sed blandit sollicitudin cras. Sagittis cursus at purus amet pellentesque sit risus.

No items found.

Related Guides

The Master Guide to PCI Compliance

Payment Security

October 2, 2026

See All

Get Regular Updates From Payments Experts

Subscribe to our newsletter and we’ll send you a monthly update of all of our new content so you don’t miss out on new data, new insights, and news from the world of payments. 

Insights and updates you actually care about

Get practical, actionable insights written by experts from the world of digital payment solutions delivered to your Inbox.

By subscribing, you agree to our Privacy Policy and Terms.

Find Us On

Company
  • Pricing
  • About
  • Careers
  • Contact Us
  • Partners
Resources
  • Support
  • Blog
  • Guides
  • News
  • Webinars
  • Trust Center
Developers
  • Developer Guides
  • Documentation
  • See Demo
  • Status

Find Us On

Privacy SettingsTermsPrivacyStatus
© 2026 Spreedly, Inc. All rights reserved.