Skip to content
Winslow Compliance Partners
Our position, stated first. Winslow is not a Qualified Security Assessor, so we do not assess, sign Reports on Compliance or certify anybody. We prepare you and also introduce independent QSA firms.

Insight

Braintree PCI compliance: how your integration sets your scope

Braintree PCI compliance depends heavily on how you integrate. So two merchants on the same gateway can face very different questionnaires.

  • Not a QSA, stated first
  • Introductions to independent QSAs
  • Written answers, no call
Braintree pci compliance: check the integration, confirm the saq and keep it that way

Braintree's role in Braintree PCI compliance

Braintree, a PayPal service, is a validated service provider for the card data it handles. However, its validation covers its systems, not your website or processes.

Therefore you still validate your own part each year.

Integration choices and Braintree PCI compliance

Braintree offers client-side options that keep raw card data off your servers. Also, server-side handling of raw card data would sharply widen scope.

IntegrationTypical effect
Drop-in UICard entry served by Braintree, so scope stays small
Hosted fieldsFields served by Braintree inside your page
Your server handles raw card dataLarge scope, usually SAQ D

Braintree PCI compliance check

Tick what is true for your integration.

Your result appears here as you tick, so you can see what is still open.

What stays yours in Braintree PCI compliance

Even with hosted fields, the page around them is yours. For example, a compromised script on that page could interfere with checkout. So page security still matters.

  • Protecting the checkout page and its scripts
  • Securing admin access to your Braintree account
  • Keeping API keys secret
  • Completing your annual questionnaire

Keeping scope small over time

Changes can quietly widen scope. For example, a developer logs request data that includes card details. Therefore review integrations after each major release.

In addition, document which integration you use, because your assessor will ask.

Where Winslow helps

We review the integration, confirm the questionnaire and prepare evidence. We are not a QSA. Gap analysis generally runs $8,000 to $40,000. Forms are in the PCI SSC document library.

Also watch third-party scripts closely. Analytics, chat and marketing tags often load on checkout pages. So limit scripts on payment pages to what is necessary, and keep an inventory of the rest. In addition, review that inventory regularly, because tags tend to multiply quietly. As a result, the page around the hosted fields stays under control.

Braintree PCI compliance questions

Does Braintree PCI compliance cover my store?

No. It covers Braintree's systems, while your site and processes remain yours.

Which SAQ fits Braintree PCI compliance with hosted fields?

Often a shorter form, but confirm the eligibility criteria for your exact setup.

Can logging break Braintree PCI compliance scope?

Yes, if logs capture card data. Review logging after each release.

Do we still need to validate yearly?

Yes, through your acquirer's process.

Related guides

Confirm your Braintree PCI compliance scope

Describe your integration. We reply in writing, usually within one business day.

Ask us anything