Insight
Choosing a PCI compliant payment gateway, and integrating it well
A PCI compliant payment gateway is necessary, but it is not enough. So the way you integrate it decides how much of PCI DSS still lands on your desk.
- Not a QSA, stated first
- Introductions to independent QSAs
- Written answers, no call
What makes a PCI compliant payment gateway
The gateway should be a validated service provider. Therefore ask for its current Attestation of Compliance, and check that it covers the services you will use.
Card brand registries can confirm listings. However, the attestation remains the core evidence.
Integration choices with a PCI compliant payment gateway
Integration is the biggest lever on your scope. Also, it is the decision developers make quickly and merchants regret slowly.
| Integration | Usual questionnaire |
|---|---|
| Full redirect to gateway page | Often SAQ A |
| Embedded payment fields from the gateway | Often SAQ A, depending on design |
| Your page posts card data via script | Often SAQ A-EP |
| Your server receives card data | SAQ D |
PCI compliant payment gateway check
Tick what you have confirmed.
Your result appears here as you tick, so you can see what is still open.
What stays yours with a PCI compliant payment gateway
The gateway protects card data in its systems. However, your website, accounts and processes remain yours.
- Securing the page that loads the payment form
- Protecting admin accounts with MFA
- Keeping API keys secret
- Monitoring scripts on payment pages
Questions to ask before signing
Ask how refunds and recurring payments work, because tokenisation can keep card numbers out of your systems. Also ask what support exists for your questionnaire. As a result, you avoid surprises at validation time.
In addition, ask how incidents are reported, since speed matters after a suspected breach.
Where Winslow helps
We compare gateway options against your scope and prepare your questionnaire. We are not a QSA. Gap analysis generally runs $8,000 to $40,000. Card brand listings include the Visa Global Registry of Service Providers.
Also test the integration after each release. So scope stays small, because changes are caught early.
PCI compliant payment gateway questions
Does a PCI compliant payment gateway make us compliant?
No. It helps, but your integration and processes still need validation.
Which integration is safest with a PCI compliant payment gateway?
Full redirects and gateway-hosted fields usually keep scope smallest.
How do we verify a PCI compliant payment gateway?
Ask for its current attestation and check card brand registries.
Do tokens help with refunds?
Yes. Tokens let you refund without storing card numbers.
Related guides
Pick a PCI compliant payment gateway with confidence
Describe your checkout plans. We reply in writing, usually within one business day.
Ask us anything