Answer · Ecommerce (WooCommerce)
What’s PCI Compliance?
The short answer
PCI DSS is the security standard every site accepting card payments must follow. For WooCommerce stores using Stripe Elements or Authorize.net Accept.js, you fall into SAQ A-EP — 30-60 minutes of annual paperwork. Self-hosted card fields put you in SAQ D (300+ question audit). Don’t go there.
№ 01The longer answer
PCI DSS (Payment Card Industry Data Security Standard) is the rulebook Visa, MC, Amex, and Discover require for any business that accepts card payments. Compliance is self-attested annually via a Self-Assessment Questionnaire (SAQ). The SAQ level depends on how you handle card data — not how much revenue you do.
SAQ levels for WooCommerce: SAQ A (card data fully handled by third party like PayPal redirect, easiest), SAQ A-EP (card fields on your site but tokenized via Stripe Elements, most common for mid-market WooCommerce), SAQ D (card data passes through or is stored on your server, hardest, requires pen testing).
How to stay in SAQ A-EP: use Stripe Elements or Authorize.net Accept.js. Card fields render in an iframe from the processor’s domain; your server never sees the card number; you receive a token. Inspect your checkout HTML — if the card fields are inside an iframe pointing to js.stripe.com, you’re good.
Infrastructure requirements at SAQ A-EP: HTTPS everywhere, current WordPress + plugin updates, strong admin passwords with 2FA, quarterly vulnerability scan by an Approved Scanning Vendor ($300-$800/year), hosting on a PCI-compliant provider (Kinsta, Pressable, WP Engine are compliant; shared GoDaddy is not).
№ 02Do I need a separate PCI compliance vendor?
Not at SAQ A-EP. Your processor (Stripe) provides templates; your ASV (SecurityMetrics, Trustwave) provides scans. Total cost: $300-$800/year. SAQ D requires more — pen testing adds $5K-$15K annually.
№ 03What happens if I’m not compliant?
Your processor can refuse to process payments, impose fines ($50-$100/month per non-compliance), or in worst case terminate the account. A breach without compliance documentation also exposes you to card-brand assessments ($50K-$500K).
№ 04Does WooCommerce make me compliant by default?
No platform makes you automatically compliant. The configuration choices (Stripe Elements, current updates, hosting) determine your compliance level. We configure correctly at build time.
Go deeper
Related questions
Three Ways to Start · No Sales Pitch
Want this answered for your business?
$500 audit. 5-day delivery. Refundable on engagement.