what triggers a full PCI DSS audit
The scope of a PCI DSS audit is determined by one question: does cardholder data pass through, or is it stored in, systems that you control? If the answer is yes, because you host your own payment page, capture card numbers in your own form, or store card data in your own database, you are in scope for a full Level 1 audit. This involves an on-site assessment by a Qualified Security Assessor (QSA), covering every system, network, person and process that touches cardholder data.
If the answer is no, because card data is captured and processed entirely within a certified third-party environment, and your systems never see it, your scope reduces dramatically, typically to a Self-Assessment Questionnaire (SAQ) which you complete without an external auditor.
coralcommerce is pci dss level 1 certified annually. every service layer on the platform is compliant, with no cardholder data exposed to any users through our portals. merchants using our hosted checkout solutions have their entire payment flow covered by our certification, the merchant's own compliance scope is reduced to a self-assessment questionnaire.
the six ways orchestration reduces your compliance burden
- Embedded compliance. Every layer of the CoralCommerce platform is built to meet PCI DSS requirements. Compliance is not a feature added to the platform, it is a property of the architecture from the ground up.
- Hosted checkout flows. When merchants use CoralCommerce hosted checkouts, the sensitive payment steps, card data capture, tokenisation, 3DS verification, occur entirely within our certified environment. The merchant's website never sees raw cardholder data.
- Secure environment. The CoralCommerce platform is hosted on Microsoft Azure within a PCI DSS compliant infrastructure configuration. Using our environments means your website or application is automatically covered for PCI DSS compliance at the integration point.
- Secured cardholder data. Card tokenisation means cardholder data is converted to a non-sensitive token at capture. The token can be used for recurring charges and card-on-file transactions without the raw card number ever being accessible to the merchant's systems.
- Requirements met. When merchants use CoralCommerce hosted services, the staff, networks, systems and software compliance requirements of PCI DSS are met by the platform certification. The merchant's required compliance activity is limited to a self-assessment.
- Annual audits absorbed. CoralCommerce undergoes a full PCI DSS Level 1 audit annually. This audit covers all clients using our hosted environment, clients benefit from the certification without undergoing the audit themselves.
what remains the merchant's responsibility
Even with a fully hosted orchestration setup, some compliance responsibilities remain with the merchant. A Self-Assessment Questionnaire is still required annually, it asks the merchant to confirm that their own systems do not capture, store or transmit cardholder data, and that they have appropriate controls in place for accessing the payment platform.
Where merchants choose headless integrations, controlling their own payment interface, any step in that interface where cardholder data is captured places that system in full PCI DSS scope. This is a legitimate choice for merchants with the engineering and compliance infrastructure to manage it, but the audit cost and operational disruption should be factored into the build decision.
Similarly, merchants using the CoralCommerce Payserver API who choose to capture cardholder data directly within their own checkout are subject to a full annual audit. CoralCommerce supports this model, but the compliance scope is explicitly the merchant's responsibility in this configuration.