Redirect

PCIComplianceHubLast updated

A payment integration that sends the cardholder away from the merchant site to a page on the provider domain, where the card data is entered, before returning them afterwards. The merchant page is out of the data path entirely, and no merchant page is open while the card is typed. It is one of the two SAQ A e-commerce integrations, alongside the embedded provider form, and shares SAQ A's eligibility criteria for e-commerce channels, including the confirmation that the merchant site is not susceptible to script attacks.

Applies to. E-commerce merchants that hand the customer to a compliant provider's page for payment. The Council's glossary names the merchant-side component an E-commerce (web) Redirection Server.
Example. The customer clicks Pay on the merchant site and lands on the provider's domain; after paying they return to the merchant's confirmation page. The merchant's checkout never holds a card field.
Limits. The page that performs the redirect still matters: if it is compromised, the customer can be sent to a look-alike site instead of the provider. That is why SAQ A for v4.x added quarterly ASV scans and scans after significant change (11.3.2 and 11.3.2.1) for redirect and embedded merchants alike, and why the script-attack criterion is written for e-commerce channels rather than for embedded forms alone.
In PCI DSS v4.0.1. 11.3.2, 11.3.2.1