What we need to know about ecommerce web design and PCI Compliance…

If you use a hosted payment gate (e.g. your customers leave your Ecommerce Web Design and enter their payment details onto a secure gateway such as WorldPay)…
Nothing changes. All your PCI Compliancy is handled by the gateway.

If people enter card details directly onto your Ecommerce Web Design (Even if the actual payment is processed by a gateway) your website…

  • Should not store unnecessary cardholder data
  • Should be running a PA-DSS Compliant Payment Application
  • Should host the site on a Dedicated Server enviroment with a Level 1 or 2 PCI Compliant Service Provider (with the Database and Application Server seperated). (Yes thats TWO servers!)
  • Should carry out quarterly vulnerability scans of their server network
  • Will need to complete SAQ-D because they are storing data (even though it’s for a short time in system memory). The SAQ-D is complicated and can cost a lot of time and money to complete!

Please note that at the time of writing this, Out of 600+ shopping cart systems out there, Only 60 are currently compliant.

This is a new enforcement by credit card companies and the banks where you can be charged up to £250,000 for every card that is used on a non-compliant ecommerce website.

If you have any ecommere web design questions, please let us know.

Share