Hacker News new | ask | show | jobs
by michaelfairley 5010 days ago
Any merchant that accepts credit card payments must be PCI compliant. Even if cardholder data never touches the merchant's servers, the merchant still falls under the scope of SAQ A[1].

1: https://www.pcisecuritystandards.org/documents/pci_saq_a_v2....