← Retailers
PCI DSS for Retail and E-commerce
Retailers usually validate as merchants rather than service providers, and the practical question is which SAQ applies — a decision driven by how payments are accepted across stores, web and app, and one that changes the workload by an order of magnitude.
What PCI DSS requires of retailers
- Merchant level from annual card transaction volume, and the SAQ type matching your acceptance channels.
- Scope across POS estate, e-commerce and any call-centre or mail-order acceptance.
- Evidence that redirect or iframe payment integrations genuinely keep card data out of your systems, where SAQ A is claimed.
- Quarterly ASV scanning for externally reachable systems.
- Third-party management for POS vendors, payment gateways and managed service providers.
Evidence assessors actually ask for
Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.
- Self-Assessment Questionnaire and Attestation of Compliance for the correct type
- ASV scan reports covering all external IP ranges
- POS inventory with firmware and configuration standards
- Evidence of payment page integration method (redirect/iframe) if claiming reduced scope
- Vendor attestations for gateways and POS providers
Where retailers usually come unstuck
- Claiming SAQ A while the payment page is served from your own infrastructure.
- Forgetting call-centre card acceptance, which changes the SAQ type.
- POS devices outside the asset inventory and therefore outside patching.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
