Skip to content

Security & access

PCI compliant hosting: what an online store should verify

Map your payment flow, request applicable provider evidence, and confirm responsibilities before choosing ecommerce hosting.

By Besthostlab Sources checked
A payment card follows a protected route from an online store to a separate vault.

“PCI compliant hosting” is not a certificate that automatically makes an online store compliant. Evaluate the hosting service within your actual payment flow, and confirm the required validation with the entity accepting your compliance evidence, usually your acquirer or payment brand.

This guide helps you collect the right information before choosing a host. It does not assess a particular store or certify a provider.

Draw the payment flow first

Identify where the customer enters card details, which systems receive them, and which scripts can affect the payment experience. Include the store, checkout integration, payment processor, tag manager, plugins, logs, and any support tools that might receive sensitive information.

IntegrationWhat to establish
Redirect to a payment providerWhether the whole payment interaction occurs on the provider’s hosted page and which merchant responsibilities remain.
Embedded provider payment formWhere the form and surrounding scripts originate, and how the integration meets its eligibility conditions.
Card data handled by your own serverThe broader environment and controls that need a qualified scope assessment.

Do not choose a self-assessment questionnaire simply because the store uses a familiar payment brand. Two integrations from the same provider can expose your systems to different data flows.

Use current SAQ guidance

PCI SSC’s SAQ A script-eligibility FAQ distinguishes embedded payment forms from redirects for the specific script-related eligibility condition it explains. It also directs merchants to confirm the appropriate SAQ with their compliance-accepting entity.

That distinction is not a blanket exemption from payment-security obligations. Ask the processor for secure implementation instructions and evidence that applies to your integration. Have your acquirer or qualified adviser confirm any scanning, reporting, or other requirements for the complete environment.

Ask the host for applicable evidence

Request the provider’s current Attestation of Compliance where relevant, the services and infrastructure it covers, and a responsibility matrix. PCI SSC confirms that an Attestation of Compliance is intended to be shared with requesting entities under the applicable program rules.

Check the service name against the actual product you are buying. Evidence for a data center or a provider’s own payment processing does not automatically describe the managed hosting service that will run your store. Ask what the provider commits to in your agreement.

Record the assessment date, scope, and how updated evidence will be supplied. Marketing badges and an SSL certificate are not substitutes for understanding that scope.

Assign the operational work

Get explicit owners for operating-system updates, application updates, access reviews, logging, vulnerability handling, backup recovery, and incident response. Managed hosting may cover some of these tasks while leaving WordPress plugins and custom checkout code to you.

Ask how required evidence and logs can be obtained, whether authorized scanning is supported, and how security findings are escalated. Confirm what happens if a required control conflicts with a plugin or deployment workflow before the store is live.

Keep card data out of ordinary support tickets, screenshots, analytics, and application logs. Use the payment provider’s supported sandbox and test data when checking the integration.

Make the purchase conditional on the answers

A useful comparison includes the exact hosting plan, payment integration, evidence supplied, customer responsibilities, and the cost of any additional security or assessment work. A low hosting price can become expensive if the required configuration needs a separate management service.

For a small store, an outsourced payment flow can simplify parts of the environment, but only the complete implementation determines eligibility and obligations. Obtain written confirmation of your validation path before committing to a host on the strength of its PCI label.