Insight
Braintree PCI compliance: how your integration sets your scope
Braintree PCI compliance depends heavily on how you integrate. So two merchants on the same gateway can face very different questionnaires.
- Not a QSA, stated first
- Introductions to independent QSAs
- Written answers, no call
Braintree's role in Braintree PCI compliance
Braintree, a PayPal service, is a validated service provider for the card data it handles. However, its validation covers its systems, not your website or processes.
Therefore you still validate your own part each year.
Integration choices and Braintree PCI compliance
Braintree offers client-side options that keep raw card data off your servers. Also, server-side handling of raw card data would sharply widen scope.
| Integration | Typical effect |
|---|---|
| Drop-in UI | Card entry served by Braintree, so scope stays small |
| Hosted fields | Fields served by Braintree inside your page |
| Your server handles raw card data | Large scope, usually SAQ D |
Braintree PCI compliance check
Tick what is true for your integration.
Your result appears here as you tick, so you can see what is still open.
What stays yours in Braintree PCI compliance
Even with hosted fields, the page around them is yours. For example, a compromised script on that page could interfere with checkout. So page security still matters.
- Protecting the checkout page and its scripts
- Securing admin access to your Braintree account
- Keeping API keys secret
- Completing your annual questionnaire
Keeping scope small over time
Changes can quietly widen scope. For example, a developer logs request data that includes card details. Therefore review integrations after each major release.
In addition, document which integration you use, because your assessor will ask.
Where Winslow helps
We review the integration, confirm the questionnaire and prepare evidence. We are not a QSA. Gap analysis generally runs $8,000 to $40,000. Forms are in the PCI SSC document library.
Also watch third-party scripts closely. Analytics, chat and marketing tags often load on checkout pages. So limit scripts on payment pages to what is necessary, and keep an inventory of the rest. In addition, review that inventory regularly, because tags tend to multiply quietly. As a result, the page around the hosted fields stays under control.
Braintree PCI compliance questions
Does Braintree PCI compliance cover my store?
No. It covers Braintree's systems, while your site and processes remain yours.
Which SAQ fits Braintree PCI compliance with hosted fields?
Often a shorter form, but confirm the eligibility criteria for your exact setup.
Can logging break Braintree PCI compliance scope?
Yes, if logs capture card data. Review logging after each release.
Do we still need to validate yearly?
Yes, through your acquirer's process.
Related guides
Confirm your Braintree PCI compliance scope
Describe your integration. We reply in writing, usually within one business day.
Ask us anything