Hacker News new | ask | show | jobs
by dangrossman 4063 days ago
As of PCI-DSS v3 (January 2015), a transparent redirect qualifies you for SAQ A-EP, which is 100+ questions along with quarterly scans and annual pentesting. Basically, your website is "in scope" for securing.

The iframe option still qualifies you for SAQ A, which is the short questionnaire without scanning/testing requirements.