GUIDE
PCI compliance for gateway users
A gateway being "Level 1 PCI compliant" describes the gateway's own infrastructure. It doesn't automatically make the merchant, ISV, or reseller sitting on top of it compliant — that's a separate, ongoing obligation.
What PCI DSS actually covers
The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements for any entity that stores, processes, or transmits cardholder data, maintained by the PCI Security Standards Council on behalf of the major card networks. Compliance level and scope depend on transaction volume and how card data flows through your systems — not on which gateway you use.
How your integration choice changes your scope
This is the most actionable lever available: a hosted payment page or hosted fields integration (see the integration guide) keeps raw card data off your servers entirely, dramatically shrinking your PCI scope down to a much shorter self-assessment questionnaire. A direct API integration that touches raw card numbers, even transiently, puts significantly more of your own infrastructure in scope.
Tokenization reduces ongoing exposure
Once a card is tokenized through the gateway's customer vault, your systems can store and reuse the token for recurring billing without ever holding the actual card number again. This is the standard way ISVs and resellers limit their PCI footprint after the initial transaction.
Self-Assessment Questionnaires (SAQs)
Most small and mid-sized merchants complete a Self-Assessment Questionnaire rather than a full on-site audit. Which SAQ type applies depends on how card data touches your systems — a fully outsourced hosted-page setup typically qualifies for the shortest questionnaire (SAQ A or similar), while a direct integration typically requires a longer one.
What resellers and ISOs should confirm with a gateway
- Current PCI DSS compliance level and validation date for the gateway itself
- Which SAQ type applies to each integration method the gateway offers
- Whether tokenization/vault services are included or a separate add-on
- What breach-notification and liability terms apply contractually