Hacker News new | ask | show | jobs
by michaelfairley 4964 days ago
Any merchant that accepts credit card payments must be PCI compliant. Even if cardholder data never touches the merchant's servers, the merchant still falls under the scope of SAQ A[1].

1: https://www.pcisecuritystandards.org/documents/pci_saq_a_v2....