Platform guide
Stripe PCI compliance: your integration decides the work
Stripe PCI compliance depends mostly on how you integrate. Stripe's hosted and embedded payment fields keep card data off your servers, while sending raw card numbers through its API puts your systems in scope.
- Not a QSA, stated first
- Introductions to independent QSAs
- Written answers, no call
How integration changes Stripe PCI compliance
Stripe publishes guidance on which integrations suit which forms. See the Stripe integration security guide.
| Integration | Typical effect |
|---|---|
| Hosted checkout page | Card data never touches your site, often SAQ A. |
| Embedded payment fields | Fields served by Stripe, often SAQ A. |
| Direct API with raw card data | Your systems handle cards, usually SAQ D. |
What you still own in Stripe PCI compliance
Even with hosted fields, some duties stay with you. Therefore review them every year.
- Completing the questionnaire Stripe or your acquirer asks for
- Keeping your site free of unauthorised changes
- Not collecting card data in other channels
- Protecting accounts with access to the Stripe dashboard
Stripe PCI compliance check
Tick each statement that is true.
Your result appears here as you tick, so you can see what is still open.
Stripe PCI compliance and payment page scripts
Version 4.0.1 added rules on payment page scripts. However, some script requirements were later removed from SAQ A. So check the current form and Stripe's guidance, rather than an old checklist.
Common Stripe PCI compliance mistakes
Teams sometimes log full request bodies during debugging. If raw card data ever passes through, those logs become stored card data. Also, building a custom form that posts card numbers to your own server changes your scope completely.
A quick review of logging settings and form code usually catches both. Therefore make it part of each release that touches payments.
Where we help
We review your integration, confirm the form and prepare evidence. However, we are not a QSA, and we are not affiliated with Stripe. The standard is in the PCI SSC document library.
Also keep Stripe's compliance confirmation with your records each year. It shows you checked your provider, which several questionnaires ask about.
Stripe PCI compliance questions
Does Stripe PCI compliance cover our business?
Stripe covers its own systems, but you still confirm your practices each year.
Which SAQ applies with Stripe?
Often SAQ A with hosted checkout or embedded fields, but SAQ D with raw card data.
Can we store cards under Stripe PCI compliance?
Yes, through tokens, so card numbers stay with Stripe rather than you.
Are you affiliated with Stripe?
No. We are independent readiness consultants.
Related guides
Check your Stripe integration
Describe your integration. We reply in writing with the likely form and any gaps.
Ask us anything