E-commerce (web) Redirection Server

PCIComplianceHubLast updated

The merchant-side server that sends a customer's browser from the merchant's website to another location, the payment provider's page, to enter card data. It is the merchant's half of a redirect integration, and the reason a redirect merchant is not entirely out of the picture.

Applies to. E-commerce merchants using a URL redirect to a compliant provider's payment page, which is one of the two SAQ A integrations.
Example. The customer clicks Pay; the merchant's web server responds with a redirect to the provider's hosted page. The merchant never sees card data, but a compromise of that server could send customers to a look-alike page instead.
Limits. The redirection server holds no account data and is not in the CDE, yet it decides where the customer goes, which is why SAQ A for v4.x added quarterly ASV scans (11.3.2) for redirect merchants and why the SAQ A eligibility criteria require the merchant to confirm its site is not susceptible to script attacks. 'We only redirect' describes the data path, not the attack surface.
In PCI DSS v4.0.1. 11.3.2