When it comes to accepting credit card payments online, PCI DSS for merchants is one of the most frequently misunderstood topics in the e-commerce industry. Business owners, CTOs, and payment operations managers often assume it is a strict government law or statutory regulation. In reality, the Payment Card Industry Data Security Standard (PCI DSS) is an industry security standard established by the major payment card schemes: Visa, Mastercard, American Express, Discover, and JCB. It is governed and maintained by the independent body known as the PCI Security Standards Council (PCI SSC).
Because it is not a legal statute, you will not face government prosecution or jail time for non-compliance. However, compliance is strictly enforced contractually through your acquiring banks and payment processors. Failing to secure your checkout and suffering a data breach can result in severe contractual penalties, expensive forensic audit costs, elevated per-transaction fees, or – in the worst-case scenario – the permanent loss of your ability to process payment cards. For an online business, losing the ability to accept cards is often a fatal blow.
Every business accepting, transmitting, or storing cardholder data must comply. However, the actual workload, cost, and technical burden depend entirely on your chosen technical setup. Here is a deep dive into how your integration determines your responsibilities.
The core concept: the Self-Assessment Questionnaire SAQ
The PCI SSC understands that a small boutique e-commerce shop does not have the same resources or risk profile as a massive multinational retailer. To accommodate this, they categorize compliance efforts using different validation forms. To prove you meet the necessary security standards, most e-commerce businesses must fill out a Self-Assessment Questionnaire SAQ.
The length, complexity, and rigorousness of this document depend entirely on your Cardholder Data Environment (CDE). Your CDE encompasses all the people, processes, and technologies (including networks, servers, and applications) that store, process, or transmit sensitive cardholder data.
The golden rule of payment compliance is simple: the less card data touches your servers, the smaller your PCI DSS compliance scope will be. By actively minimizing your CDE – essentially keeping the sensitive data away from your own infrastructure – you can drastically reduce the amount of time, money, and engineering resources spent on security audits and system maintenance.
Which specific Self-Assessment Questionnaire SAQ you are required to submit is dictated directly by your architecture and how you choose to collect payments from your customers.
Open an account
in Genome online
Scope breakdown by integration method
Different checkout experiences require completely different levels of security control and ongoing maintenance. Your PCI DSS compliance scope will depend on the type of technical setup you will choose.
1. Hosted payment pages (lowest scope: SAQ A)
This method is designed for a quick and simple launch and doesn’t require much effort from you. When your customer clicks “Pay,” they are either redirected to a highly secure checkout page hosted entirely by your payment provider, or they enter their details into an isolated iFrame embedded natively on your site.
The mechanism: Raw card data never touches your web server, database, or internal infrastructure. The data flows directly from the customer’s browser to the payment processor.
Merchant effort: Minimal. By using a hosted payment page, PCI DSS requirements are reduced to just a handful of security controls (typically around 24 distinct requirements). These are primarily focused on securing administrative user access to your e-commerce platform (like enforcing strong passwords) and managing third-party vendor relationships. You will easily qualify for SAQ A, freeing your developers to focus on product features rather than security compliance.
2. JavaScript / mobile SDKs (moderate scope: SAQ A-EP or SAQ C-VT)
In this scenario, you host the checkout form’s user interface directly on your website, but you utilize background scripts or native SDKs to securely transmit the card data directly to the payment processor before it hits your server.
The mechanism: While card data does not technically land in your database, your web server does control the environment where the payment form is generated. If a malicious actor compromises your server, they could inject malicious JavaScript code (a tactic known as formjacking or Magecart) to silently steal card details right from the user’s browser before the data is sent.
Merchant effort: Moderate to high. If you go for this setup, your risk profile increases. It means you will need to complete SAQ A-EP (which contains over 190 controls). You will need rigorous web server hardening, sophisticated code integrity monitoring, external vulnerability scans by an Approved Scanning Vendor (ASV), and strict firewall configurations.
3. Direct API / self-hosted (maximum scope: SAQ D)
If you require absolute total control over the entire checkout experience and decide to build a direct payment gateway integration (host-to-host intgegration or self-hosted payment page), PCI requirements will hit their absolute maximum.
The mechanism: Your servers directly collect, process, and transmit the raw cardholder details via an API.
Merchant effort: Massive. You are entirely responsible for the entire CDE. This requires completing SAQ D, which encompasses over 200 rigorous technical controls. You must manage quarterly ASV vulnerability scans, execute annual internal and external penetration testing, maintain extensive security policies, and potentially undergo highly expensive, time-consuming on-site audits by a Qualified Security Assessor (QSA).
Simplifying compliance and scaling via Genome merchant services
Need a compliant, secure payment infrastructure? Genome merchant services can help.
As a fully licensed EU Electronic Money Institution (EMI) strictly supervised by the Bank of Lithuania, Genome maintains top-tier, bank-grade security standards so you do not have to. By utilizing Genome’s hosted payment page, PCI DSS burdens are virtually eliminated. All sensitive cardholder data bypasses your infrastructure entirely, landing directly on Genome’s hardened, fully compliant servers.
This enables your business to qualify for the simplest Self-Assessment Questionnaire SAQ (SAQ A). You can launch your e-commerce platform rapidly without needing to hire dedicated compliance teams or build complex network architectures.
Beyond drastically reducing your compliance burden, Genome merchant services provide a massive suite of features designed to scale your enterprise globally. We are currently developing a host-to-host integration, which will allow you to implement self-hosted payment pages as well!
Key benefits of Genome for merchants include:
Pay by Bank (instant bank payments): The instant bank payments feature utilizes Open Banking and SEPA Instant to let customers pay directly from their bank accounts. By bypassing traditional credit card networks, merchants can significantly lower processing fees, eliminate card-related chargebacks, and receive their funds in seconds rather than waiting days for standard card settlements. This frictionless “Pay by Bank” checkout process reduces user drop-off while providing your business with immediate liquidity to confidently scale operations.
Coming soon: card payment processing: Soon you will be able to accept major credit and debit cards (Visa, Mastercard) globally in major currencies EUR, USD, GBP). Join the waitlist for the feature.
Multi-currency accounts: Open business accounts in 12 currencies (EUR, USD, GBP, PLN, CHF, JPY, CAD, CZK, HUF, SEK, AUD, and DKK) and manage international transfers.
Advanced fraud prevention: Genome utilizes sophisticated anti-fraud mechanisms and proactive risk management tools to detect suspicious transactions in real time.
B2B and B2C capabilities: Whether you are operating a high-volume B2C retail store or handling massive B2B invoices, Genome supports SEPA and SWIFT transfers, giving you total flexibility in how you pay your suppliers and get paid by clients.
Dedicated support: Unlike faceless payment aggregators, Genome provides dedicated account management, ensuring real experts resolve technical integration, compliance questions, and operational issues swiftly.
Open an account
in Genome online
Merchant checklist: determining your path to compliance
Are you ready to launch your online store or upgrade your existing infrastructure? Follow these three essential steps to finalize your payment and compliance strategy:
Identify your payment capture architecture: Have a frank discussion with your development team. Decide whether you want a simple redirect, an embedded iFrame, or a fully custom API. Keep in mind that with a direct payment gateway integration, PCI scope, operational costs, and legal liability will be heavily impacted.
Match your integration to the correct SAQ: Determine if your choice safely limits you to SAQ A, or if you will be on the hook for the rigorous, time-consuming SAQ A-EP or SAQ D.
Minimize your scope to maximize growth: If you want to streamline PCI DSS for merchants and reduce your overhead, the solution is simple: avoid handling raw card data entirely. Explore Genome merchant services to implement a secure, conversion-optimized, and low-scope checkout solution that keeps your business agile, secure, and fully compliant.






