ALL RESOURCES
Compliance frameworks
Why companies that use Stripe still need PCI compliance

Why companies that use Stripe still need PCI compliance

Stripe is an incredibly common tool for businesses of all sizes today, from one-person freelancers to large-scale, multinational corporations. Stripe takes care of one of the most complex and risky parts of doing business: processing payments.


But that leaves many businesses to wonder, “If I use Stripe, does that take away my need for PCI compliance?” After all, if Stripe is processing your customers’ payments, which takes the payment processing out of your hands, shouldn’t Stripe need PCI compliance instead of you?


It’s not quite that simple. Let’s take a closer look at Stripe and its PCI compliance, and how it affects your own compliance needs.

Is Stripe PCI compliant?

If you’re trusting Stripe with your customers’ payment data, you need to know that they have protocols and protections in place to keep it safe. For this reason, it’s important to know that Stripe does have up-to-date PCI compliance. They are a compliant level 1 service provider.


Because Stripe is a level 1 service provider, it means that they have gone through the strictest PCI compliance process required of service providers. Not only do they adhere to the 12 requirements of PCI DSS and all the sub-requirements within them, but they have been evaluated by an independent auditor to ensure that this is the case.

Does using Stripe eliminate my need for PCI compliance?

Here’s where it gets tricky: No, using Stripe does not mean that your business is already PCI compliant.


PCI DSS applies to everyone involved in collecting, processing, and storing payment data. This includes both you and Stripe - your customers’ security is a shared responsibility. Stripe may be processing the data, but your system is playing a role in this process too, so your system needs to be just as secure.


In fact, Stripe requires all its customers to validate their PCI compliance each year. So, in order to adhere to Stripe’s terms of service, your business needs to be PCI compliant.


Many companies choose to complete a self-assessment questionnaire (SAQ) or Report on Compliance (ROC) because they want to demonstrate to their customers and prospects that they take cardholder data security seriously. PCI compliance demonstrates a company’s security posture and helps a business obtain more deals, while instilling trust with customers.

How can I become PCI compliant while using Stripe?

Whether or not you’re already using Stripe to process payments for your business, becoming PCI compliant as quickly as possible will help you prevent a costly data breach, earn the trust of your customers and partners, and avoid potential problems like non-compliance fees or the inability to use Stripe. Follow these straightforward steps to become compliant.

1. Check where you stand

There are 12 requirements you need to meet for PCI compliance, along with sub-requirements within them. For many companies, the most time-consuming part of PCI compliance is digging into their system to see which of those requirements they already meet and which ones they need to work on.


You can skip that extra time with automated compliance software. This software scans your system in-depth and looks for the PCI compliance criteria. It then gives you a thorough report of which requirements you meet and which you don’t. Effectively, this gives you a streamlined to-do list to become PCI compliant.

2. Complete your remaining requirements

Now that you have a full list of the PCI compliance requirements you don’t yet meet, you can take care of them one by one. This could be a process that requires a lot of resources or it could be quick and simple depending on the security protocols you already have in place.

3. Complete your PCI compliance documentation

While you’re technically complying with PCI standards after you’ve finished that checklist and you meet all 12 requirements, you’ll need to validate your compliance for it to be recognized. Stripe requires this validation for all its customers.


Your documentation can vary. Any merchant that receives less than six million transactions per year will need three pieces of documentation:



Keep in mind that there are some variations. There are several different types of SAQs, and the one you need will depend on how you’ve integrated Stripe or how you’re processing payments. The vulnerability scan can vary too because it’s not required for all types of SAQs.


Note that the three documents above are for businesses with less than six million transactions per year. If your business performs more than six million annual transactions, you’ll need to take the added step of hiring a third-party PCI compliance auditor to do an on-site review of your system.

Get PCI compliant

As useful as Stripe is as a convenient, safe, and efficient way to process customer payments, it doesn’t give you a pass on PCI compliance. Follow the three steps above, starting with Vanta’s PCI compliance software, to bring your business into compliance and to protect the financial health of your company and your customers.



More about PCI

Automate your PCI DSS compliance


Your PCI DSS compliance checklist


Guide to PCI compliance cost



Written by
No items found.
Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail

PCI Compliance Selection Guide

Determine Your PCI Compliance Level

If your organization processes, stores, or transmits cardholder data, you must comply with the Payment Card Industry Data Security Standard (PCI DSS), a global mandate created by major credit card companies. Compliance is mandatory for any business that accepts credit card payments.

When establishing strategies for implementing and maintaining PCI compliance, your organization needs to understand what constitutes a Merchant or Service Provider, and whether a Self Assessment Questionnaire (SAQ) or Report on Compliance (ROC) is most applicable to your business.

Answer a few short questions and we’ll help identify your compliance level.

1
2
3
4
!
👍

Does your business offer services to customers who are interested in your level of PCI compliance?

Yes
No

Identify your PCI SAQ or ROC level

The PCI Security Standards Council has established the below criteria for Merchant and Service Provider validation. Use these descriptions to help determine the SAQ or ROC that best applies to your organization.

Good news! Vanta supports all of the following compliance levels:

SAQ A

A SAQ A is required for Merchants that do not require the physical presence of a credit card (like an eCommerce, mail, or telephone purchase). This means that the Merchant’s business has fully outsourced all cardholder data processing to PCI DSS compliant third party Service Providers, with no electronic storage, processing, or transmission of any cardholder data on the Merchant’s system or premises.

Get PCI DSS certified

SAQ A-EP

A SAQ A-EP is similar to a SAQ A, but is a requirement for Merchants that don't receive cardholder data, but control how cardholder data is redirected to a PCI DSS validated third-party payment processor.

Learn more about eCommerce PCI

SAQ D
for service providers

A SAQ D includes over 200 requirements and covers the entirety of PCI DSS compliance. If you are a Service Provider, a SAQ D is the only SAQ you’re eligible to complete.

Use our PCI checklist

ROC
Level 1 for service providers

A Report on Compliance (ROC) is an annual assessment that determines your organization’s ability to protect cardholder data. If you’re a Merchant that processes over six million transactions annually or a Service Provider that processes more than 300,000 transactions annually, your organization is responsible for both a ROC and an Attestation of Compliance (AOC).

Automate your ROC and AOC

Download this checklist for easy reference

Questions?

Learn more about how Vanta can help. You can also find information on PCI compliance levels at the PCI Security Standards Council website or by contacting your payment processing partner.

The compliance news you need. Delivered securely to your inbox.