PCI Compliance Basics for Small Online Stores
If your store accepts card payments in any form, PCI DSS (Payment Card Industry Data Security Standard) applies to you — but for most small stores using a hosted checkout, the requirements are lighter than they sound.
The good news: hosted payment pages reduce your scope
If customers enter their card details on your payment gateway’s own page (Stripe Checkout, PayPal, or a redirect-based bKash/Nagad flow) rather than a form on your site, your store never touches raw card data. This puts most small merchants in the simplest PCI compliance category (SAQ A), which mainly requires basic security hygiene rather than a full audit.
What you should still do
- Keep your site on HTTPS everywhere, not just the checkout page.
- Keep WordPress/WooCommerce, plugins and themes updated — most breaches start with an outdated plugin, not a sophisticated attack.
- Use strong, unique passwords for wp-admin, cPanel and your payment gateway dashboard, with two-factor authentication where available.
- Never store card numbers, CVV codes or expiry dates in your own database, spreadsheets, or email — let the payment gateway handle and store that data.
- Restrict wp-admin access with a firewall or IP allow-list if only a few people manage the store.
If you take card details directly on your site
Embedded card fields (even if styled to look native) that pass data to the gateway via JavaScript still usually qualify for a lighter SAQ category, but self-hosted forms that submit card data to your own server put you in full PCI DSS scope, with formal audits required. Avoid this setup unless you have a specific reason and dedicated security resources.
When in doubt, ask your payment gateway which SAQ category your integration falls under — they classify this for every merchant and can point you to the exact checklist.
Our support team is here 24/7
Open a ticket or send us a message -- a real person replies to every request.
Contact support