Back to PCI DSS

Shopify PCI Compliance: What Merchants Still Own Under PCI DSS

Shopify PCI compliance illustration: colorful payment cards with a lock badge and an SAQ A label

Short answer: Shopify states that it is a PCI DSS Level 1 certified service provider for its platform and Shopify Payments, but that certification covers Shopify's environment, not your business. If you accept card payments, you still have to validate your own PCI DSS compliance, usually with a Self-Assessment Questionnaire. Using Shopify's hosted checkout often keeps that questionnaire short.

Related guides:

Key takeaways

  • Shopify's Level 1 service provider status covers Shopify's platform and Shopify Payments. It does not make your store compliant on its behalf.
  • Merchants that accept cards remain responsible for PCI DSS, and most small Shopify merchants validate with a Self-Assessment Questionnaire (SAQ).
  • A store that uses only Shopify's hosted checkout commonly fits SAQ A. Custom scripts, payment-page apps, in-person hardware, phone orders or stored card data can widen your scope.
  • PCI DSS v4.0 requirements that became mandatory on 31 March 2025 put new focus on scripts and tampering on payment pages.
  • Your acquirer or payment processor tells you how to validate. The card brands define merchant levels.

Is Shopify PCI compliant?

Yes, Shopify states that it is certified as a PCI DSS Level 1 service provider, the most rigorous validation tier for service providers.

It means the systems Shopify operates, including its hosted checkout and Shopify Payments, are assessed against PCI DSS by a qualified assessor. Card details entered at Shopify's checkout are captured inside Shopify's environment, not on servers you run.

The certification does not extend to what Shopify does not control. Your staff accounts, installed apps, shop-floor devices, phone order process and storefront scripts sit on your side of this shared responsibility line:

Area Typically handled by Shopify Typically handled by the merchant
Hosted checkout infrastructure Yes
Shopify Payments processing Yes
Admin accounts, passwords and MFA Provides the tools Configures and enforces them
Third-party apps and custom code Selects, reviews and monitors them
POS devices in your store Supplies hardware if you use it Physical security and inspection
Phone and mail orders Staff procedures and handling
Annual PCI validation for your store Yes

Do Shopify stores still need PCI compliance?

Yes, any merchant that accepts payment cards is expected to comply with PCI DSS, and using a compliant platform reduces your work rather than removing it.

PCI DSS applies to entities that store, process or transmit cardholder data, and to those whose systems can affect its security. A storefront that sends shoppers to Shopify's checkout never handles card numbers, but it is still part of the path a customer takes to pay, so merchants confirm each year that their side is in order.

In practice this usually means:

  1. Confirming with your acquirer or processor how you are expected to validate.
  2. Completing the correct SAQ for how you actually accept payments.
  3. Signing an Attestation of Compliance (AOC) and submitting it if requested.
  4. Maintaining the controls the SAQ asks about for the rest of the year, not only on the day you sign.

For a closer look at how the questionnaires are structured, see our guide to the PCI DSS self-assessment questionnaire.

Which SAQ does a Shopify store need?

It depends on how you take payments: a store that relies solely on Shopify's hosted checkout commonly fits SAQ A, while other channels and customizations can move you to a longer questionnaire.

The SAQ types are defined by the PCI Security Standards Council (PCI SSC), and your acquirer has the final say. The table below shows common Shopify setups and the SAQ that often applies. Treat it as a starting point for the conversation with your acquirer, not a determination.

Scenario Likely SAQ Why
Online store using only Shopify's hosted checkout, no custom payment-page code SAQ A Card data entry is fully outsourced to a PCI DSS compliant provider
Checkout customized only through Shopify's checkout extensions Usually still SAQ A Shopify says its checkout covers the PCI DSS v4 payment page script requirements, including for extensions. Confirm with your acquirer
A payment page or payment form served from your own site or another platform, outside Shopify's hosted checkout SAQ A-EP, possibly higher Your website can influence the security of the payment transaction even though you do not receive card data
In-person sales with standalone card terminals that connect to the processor SAQ B or SAQ B-IP Covers imprint or dial-out terminals (B) and standalone IP-connected terminals (B-IP)
Staff key card details from phone or mail orders into a web-based virtual terminal, one transaction at a time SAQ C-VT Manual entry through a provider's virtual terminal, with no electronic storage
In-person sales on hardware that is part of a validated point-to-point encryption (P2PE) solution SAQ P2PE Card data is encrypted in the device, which keeps your scope small
Any storage of full card numbers, card data in email or spreadsheets, or setups that fit no other SAQ SAQ D The full set of applicable PCI DSS requirements

A few points trip merchants up:

  • Mixed channels combine scope. If you sell online and in person, you may need to address both channels. Your acquirer will tell you whether that means more than one SAQ or a single broader one.
  • Point-of-sale hardware varies. Which SAQ fits in-person sales depends on the device, how it connects and whether it is part of a validated point-to-point encryption solution. Confirm the details for your specific hardware with your acquirer.
  • "We never see card numbers" is not the same as "we have no scope." Writing card details on paper, taking them over email, or saving them in a notes field for repeat orders brings you into a much larger scope.

What PCI DSS v4.0 changed for payment pages

PCI DSS v4.0 introduced future-dated requirements that became mandatory on 31 March 2025, and two of them focus directly on the scripts and content of payment pages.

Online skimming attacks work by slipping malicious JavaScript into a checkout or payment page so card details are copied as the customer types them. To address this, PCI DSS v4.0 added:

  • Requirement 6.4.3: manage the scripts that run on payment pages. Each script should be authorized, its integrity assured, and an inventory kept with a written justification for why it is needed.
  • Requirement 11.6.1: deploy a change and tamper detection mechanism that alerts personnel to unauthorized changes to the security-impacting HTTP headers and contents of payment pages as received by the customer's browser.

These requirements apply fully to merchants on SAQ A-EP and SAQ D. For SAQ A, the PCI SSC updated the questionnaire and its eligibility criteria after publishing v4.0. In general terms, the change asks SAQ A merchants to confirm that their site is not susceptible to script-based attacks that could affect their e-commerce systems, rather than listing every script control as a line item. Read the current SAQ A document and its eligibility criteria carefully before you sign, and ask your acquirer if you are unsure whether your storefront meets them.

For Shopify merchants, every piece of code added near the payment flow is a scope and risk decision. Keep a list, remove what you do not need, and know who can change it. For a wider view of the update, see PCI DSS v4.0 changes.

Who decides your validation requirements?

Your acquiring bank or payment processor decides how you must validate compliance, while the card brands set the merchant levels that usually drive those requirements.

Merchant levels are based mainly on annual transaction volume for each card brand, and each brand publishes its own thresholds. Most small and mid-sized Shopify merchants fall into the lower levels, where self-assessment is the norm. Larger merchants, or those that have experienced a breach, can be asked for more, such as an on-site assessment by a Qualified Security Assessor. Our guide to PCI DSS levels walks through how the tiers work.

Whether you use Shopify Payments or a separate gateway, ask your provider directly: which SAQ do you expect, how often, and where should the AOC go?

A practical PCI checklist for Shopify merchants

Most of the merchant side of Shopify PCI compliance comes down to controlling who and what can touch your store, and being ready if something goes wrong.

Third-party apps and code

  • Keep an inventory of installed apps, themes and custom scripts, with an owner for each.
  • Review what permissions each app requests, especially anything related to checkout, orders or customer data.
  • Remove apps you no longer use.
  • Require approval before anyone adds scripts or tracking tags to storefront or checkout pages.

Staff access

  • Give each person their own account. No shared logins.
  • Grant the minimum permissions each role needs, and review them regularly.
  • Remove access promptly when staff or contractors leave.

Admin account security

  • Turn on multi-factor authentication for every account with access to your Shopify admin.
  • Protect the email accounts tied to store ownership with MFA as well, since they can be used to reset access.

Phishing awareness

  • Train staff to spot fake login pages, invoice scams and messages impersonating your platform, apps or customers.
  • Set a rule that payment or account changes requested by email are confirmed through a separate channel.

Point-of-sale devices

  • Keep an inventory of card readers and terminals, including serial numbers and locations.
  • Inspect devices periodically for tampering or substitution, and train staff on what to look for.

Card data handling

  • Never write down, email or store full card numbers.
  • Document the procedure for phone and mail orders, and keep entries in approved systems only.

Incident response

  • Write a short incident plan: who to call, how to contact your acquirer and Shopify, and how to preserve evidence.
  • Know how to disable an app, rotate credentials and lock down admin accounts quickly.
  • Test the plan at least once a year with a simple tabletop exercise.

How SecureSlate helps

SecureSlate helps you manage the merchant side of PCI DSS without spreadsheets. You can map and track PCI DSS controls in a single control library alongside frameworks such as SOC 2 or ISO 27001, collect evidence automatically from your cloud and SaaS stack, and use policy templates for access control, incident response and acceptable use. The risk register and vendor risk management features give you a place to record the apps and payment providers your store depends on, along with who reviewed them and when.

When your acquirer asks for your SAQ and AOC, audit-ready exports help you show the work behind your answers, and a trust center lets you share your security posture with partners. Your validation itself still follows your acquirer's requirements.

Start your free SecureSlate trial

FAQ

Does using Shopify make my store PCI compliant automatically?

No. Shopify's Level 1 service provider status covers Shopify's own environment and payment services. You remain responsible for validating compliance for your business, usually through an SAQ, and for the controls that fall on your side, such as staff access, apps and devices.

Is SAQ A enough for a Shopify store?

SAQ A is often the right fit for stores that use only Shopify's hosted checkout and do not add code that can affect payment pages. If you customize checkout with scripts, sell in person, key in phone orders or store card data, a different or additional SAQ may apply. Your acquirer confirms which one you need.

Do I need to submit my SAQ to Shopify?

It depends on your payment arrangement. Your acquirer or payment processor sets the validation and reporting requirements, so ask them where the SAQ and Attestation of Compliance should go and how often. Keep a signed copy on file either way.

What happens if I ignore PCI compliance on Shopify?

Consequences are set by your acquirer and the card brands and can include fees or restrictions on accepting cards. The bigger risk is a breach, where weak app controls or compromised admin accounts can lead to fraud, investigation costs and lost customer trust.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.9(409 reviews)

Keep reading

Jun 25, 2026 · PCI DSS

PCI DSS Controls

Jun 24, 2026 · PCI DSS

PCI DSS Compliance

Jun 23, 2026 · PCI DSS

PCI DSS Compliance Goals

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?