PCI Center
Guidance on PCI DSS, SAQ types, merchant responsibilities, and security best practices. ONKORE helps merchants understand their responsibilities but does not certify compliance on their behalf.
We help merchants understand their PCI responsibilities. Requirements vary depending on payment acceptance methods.
Understanding PCI DSS
What PCI DSS is, who it applies to, and how to reduce your scope.
What Is PCI DSS?
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements designed to protect cardholder data. It applies to any organization that processes, stores, or transmits payment card information, regardless of size or transaction volume.
Who Needs to Comply?
If your business accepts card payments, you are responsible for PCI compliance. The level of validation required depends on your annual transaction volume and payment acceptance methods. Compliance is a merchant responsibility — your processor does not certify compliance on your behalf.
Reducing Your Scope
You can reduce your PCI scope by minimizing where cardholder data touches your systems. Using tokenization, hosted checkout pages, payment links, or virtual terminals where supported keeps raw card data off your servers and simplifies your compliance validation.
Explore by Topic
Guidance across PCI compliance and security.
PCI Basics
Understand what PCI DSS is, who it applies to, and why it matters for your business.
SAQ Types
Learn which Self-Assessment Questionnaire applies to your payment acceptance method.
Compliance Checklist
A practical checklist to help you validate and maintain compliance.
Merchant Responsibilities
What merchants are responsible for and what ONKORE handles on the processing side.
Security Best Practices
Reduce your scope and protect cardholder data with proven security practices.
PCI FAQs
Answers to common questions about PCI compliance, validation, and scope.
Self-Assessment Questionnaires
Which SAQ applies to your payment acceptance method.
SAQ A
For merchants who fully outsource all cardholder data functions to a PCI-compliant third party (e.g., hosted checkout with no card data touching your systems).
SAQ A-EP
For e-commerce merchants who outsource payment processing but may interact with cardholder data on their website.
SAQ B
For merchants using imprint machines or standalone dial-up terminals that do not store cardholder data.
SAQ C
For merchants with payment application systems connected to the internet that do not store cardholder data.
SAQ D
For all other merchants and service providers not covered by other SAQs, including those storing cardholder data.
The applicable SAQ depends on how you accept payments. Using hosted checkout, payment links, or tokenization where supported can reduce your scope. Contact ONKORE for guidance on your specific setup.
PCI FAQs
Answers to common questions about PCI compliance.
Is ONKORE PCI certified?
ONKORE helps merchants understand their PCI responsibilities, but does not certify compliance on behalf of merchants. Merchants are responsible for validating their own compliance based on their payment acceptance methods and transaction volume. Requirements vary depending on how you process payments.
What happens if I'm not PCI compliant?
Non-compliance can result in monthly non-compliance fees from your processor, increased liability for breaches, and potential account restrictions. Some processors charge fees until compliance is validated. Check your merchant agreement for specific terms.
How often do I need to validate compliance?
PCI compliance is typically validated annually, though some requirements (like vulnerability scanning) may need to be completed quarterly. Your acquirer or processor will confirm your specific validation schedule and requirements.
Does using a hosted checkout remove my PCI obligations?
Using hosted checkout or payment links can significantly reduce your PCI scope, but it may not eliminate all obligations. You're still responsible for securing your website, protecting customer data, and completing the applicable (typically shorter) SAQ.
What is tokenization and how does it help?
Tokenization replaces sensitive card data with a token that has no exploitable value. Because tokens can't be reverse-engineered into card numbers, using them instead of storing raw card data reduces the systems and processes in scope for PCI assessment.
Have PCI questions?
Our team can help you understand your responsibilities and reduce your compliance scope.
