coral connects commerce communities
compliance  ·  pci dss & security

payment security & PCI DSS

pci dss audits are annual, invasive and disruptive. the words alone are enough to raise blood pressure in most payment operations teams. the good news is that using a certified orchestration platform with hosted checkouts reduces your compliance scope dramatically, in most cases to a self-assessment questionnaire.

5 minute read CoralCommerce team compliance & security
definition

PCI DSS (Payment Card Industry Data Security Standard) is the mandatory security framework for any organisation that stores, processes or transmits cardholder data. PCI DSS compliance scope refers to the systems, people and processes that must meet the standard, and the primary goal of most merchants is to reduce this scope to the minimum possible, since a smaller scope means a less invasive annual audit.

annual
audit frequency
pci dss audits are required annually, and full audits are expensive, disruptive, and reveal compliance gaps that create urgent remediation requirements
SAQ only
scope with hosted checkout
merchants using coralcommerce hosted checkouts qualify for a self-assessment questionnaire only, the lightest-touch pci dss compliance path available
since 2020
coralcommerce certified
coralcommerce has been pci dss certified annually since its platform launch in 2020, compliance is built into the architecture, not added retrospectively
full audit
self-hosted checkout cost
merchants who capture cardholder data in their own environment are subject to a full annual pci dss audit regardless of which payment providers they use

what triggers a full PCI DSS audit

The scope of a PCI DSS audit is determined by one question: does cardholder data pass through, or is it stored in, systems that you control? If the answer is yes, because you host your own payment page, capture card numbers in your own form, or store card data in your own database, you are in scope for a full Level 1 audit. This involves an on-site assessment by a Qualified Security Assessor (QSA), covering every system, network, person and process that touches cardholder data.

If the answer is no, because card data is captured and processed entirely within a certified third-party environment, and your systems never see it, your scope reduces dramatically, typically to a Self-Assessment Questionnaire (SAQ) which you complete without an external auditor.

coralcommerce compliance position

coralcommerce is pci dss level 1 certified annually. every service layer on the platform is compliant, with no cardholder data exposed to any users through our portals. merchants using our hosted checkout solutions have their entire payment flow covered by our certification, the merchant's own compliance scope is reduced to a self-assessment questionnaire.

the six ways orchestration reduces your compliance burden

what remains the merchant's responsibility

Even with a fully hosted orchestration setup, some compliance responsibilities remain with the merchant. A Self-Assessment Questionnaire is still required annually, it asks the merchant to confirm that their own systems do not capture, store or transmit cardholder data, and that they have appropriate controls in place for accessing the payment platform.

Where merchants choose headless integrations, controlling their own payment interface, any step in that interface where cardholder data is captured places that system in full PCI DSS scope. This is a legitimate choice for merchants with the engineering and compliance infrastructure to manage it, but the audit cost and operational disruption should be factored into the build decision.

Similarly, merchants using the CoralCommerce Payserver API who choose to capture cardholder data directly within their own checkout are subject to a full annual audit. CoralCommerce supports this model, but the compliance scope is explicitly the merchant's responsibility in this configuration.

frequently asked

questions about PCI DSS and payment security

What is PCI DSS?

PCI DSS (Payment Card Industry Data Security Standard) is the mandatory security framework for any organisation that stores, processes or transmits cardholder data. It requires annual compliance validation, either a self-assessment questionnaire or a full audit by a Qualified Security Assessor, depending on scope.

How does using CoralCommerce reduce PCI DSS compliance scope?

When merchants use CoralCommerce hosted checkouts, cardholder data is captured and processed entirely within the CoralCommerce certified environment. The merchant's systems never see raw cardholder data, reducing their compliance requirement from a full audit to a self-assessment questionnaire.

Is CoralCommerce PCI DSS certified?

Yes. CoralCommerce has been PCI DSS Level 1 certified annually since 2020. Every service layer on the platform is compliant, and the certification covers all merchants using CoralCommerce hosted checkout environments.

What triggers a full PCI DSS audit for a merchant?

A full audit is triggered when cardholder data passes through or is stored in systems controlled by the merchant, for example, a self-hosted payment form that captures card numbers, or a database that stores card data. Merchants using hosted checkouts exclusively can typically use a self-assessment questionnaire instead.

What is a self-assessment questionnaire in PCI DSS?

A Self-Assessment Questionnaire (SAQ) is the lighter-touch compliance validation available to merchants whose systems do not directly handle cardholder data. It asks the merchant to confirm that appropriate controls are in place and that cardholder data flows through certified third-party environments only.

Does card tokenisation help with PCI DSS compliance?

Yes. Tokenisation converts cardholder data into a non-sensitive token at the point of capture. The token can be used for recurring charges and card-on-file transactions without the raw card number being accessible to the merchant's systems, keeping the merchant's environment out of PCI DSS scope.