E-commerce
PCIComplianceHubLast updated
Accepting card payments over the internet, through a website or application in which the customer enters their own card data. For PCI DSS it is a payment channel with its own SAQ eligibility rules, and the one where the payment page, rather than a terminal, is the point of attack.
Applies to. Merchants selling online, the providers whose pages and scripts they use, and, where the merchant is hosted, the hosting provider.
Example. Three merchants sell the same product online. One redirects to its provider's page (SAQ A). One serves its own card form and posts to the provider (SAQ A-EP). One stores card numbers for repeat orders (SAQ D). The channel is the same; the questionnaire is not.
Limits. The e-commerce table in the SAQ instructions is the reference for which integration lands on which SAQ, and it draws the line at whether any element of the payment page comes from the merchant's site. SAQ A and A-EP both require that the merchant stores, processes and transmits no account data electronically. Requirements 6.4.3 and 11.6.1 exist for this channel specifically.