Hosted Payment Page

PCIComplianceHubLast updated

A payment page served entirely by a provider, on the provider domain, either embedded in an iframe or reached by a redirect. The merchant never receives the card data. It is the strongest scope reduction available to an e-commerce merchant, and both forms qualify for SAQ A under the same eligibility criteria for e-commerce channels.

Applies to. Merchants whose provider serves the whole payment form, whether the customer is sent to it or sees it inside the merchant's checkout.
Example. A 'Pay now' button sends the customer to the provider's domain, where the card is entered, and the provider sends them back with a result. Or the same provider form is shown inside the merchant's checkout in an iframe. In both, card data never reaches the merchant's systems.
Limits. 'Hosted' describes where the form lives, not the merchant's whole page. In the embedded form, everything around the frame is still the merchant's. SAQ A's criteria for e-commerce require every element of the payment form delivered to the browser to originate only and directly from the compliant provider, and the merchant to confirm its site is not susceptible to script attacks. A merchant that adds its own card fields, or loads a script that builds the form, has left SAQ A for SAQ A-EP.