Do I need PCI compliance if I use Stripe or Razorpay?
Yes, but usually far less of it than you fear. A hosted checkout or embedded payment fields keep card numbers off your systems, which shrinks PCI DSS to a short self-assessment. Answer four questions to see which Self-Assessment Questionnaire fits, what changed in 2025, and when you need an assessor.
Yes. Using Stripe, Razorpay, PayU or Square reduces your PCI DSS scope but does not remove it: card brand rules require every merchant that accepts cards to comply, and providers such as Stripe ask you to attest every year. With a hosted checkout or embedded iframe fields you usually qualify for SAQ A, the shortest questionnaire. Since March 2025, embedded forms must also be protected against script attacks.
Result
Embedded fields or an iframe from a PCI-compliant provider keep card data off your systems, so you usually qualify for SAQ A. Since 31 March 2025, SAQ A has a new eligibility criterion: you must confirm your page is not susceptible to script attacks that could affect the payment form, either with your own controls (like 6.4.3 and 11.6.1) or with your provider's confirmation that its solution protects the page when implemented as instructed.
- Ask your provider: for written confirmation that its embedded form protects against script attacks.
- Confirm: ask your acquirer or payment provider which SAQ they expect; they set validation, not the PCI Council.
- Keep it that way: never let card numbers reach your servers, logs, support tickets or spreadsheets.
- Each year: complete the SAQ and Attestation of Compliance your provider asks for, often in its dashboard.
Why Stripe or Razorpay does not make PCI go away
PCI DSS is set by the PCI Security Standards Council, but enforced through card brand rules and the contract with your acquirer. Visa states that PCI DSS compliance is required of every entity that stores, processes or transmits its cardholder data, and that acquirers must ensure their merchants comply. Your payment provider is PCI DSS validated for its part; you are responsible for yours. Stripe's documentation, for example, says businesses accepting payments must do so in a PCI-compliant manner and attest annually. The same logic applies to Razorpay, PayU, Square and QuickBooks Payments.
Which SAQ fits how you take payments
Hosted checkout or redirect (Stripe Checkout, a hosted payment page, payment links): SAQ A. Embedded fields or iframe (Stripe Elements, an embedded checkout): SAQ A, provided you meet the script-attack eligibility criterion. Your page builds the form but card data goes straight to the processor: usually SAQ A-EP. Card data reaches your servers, or you store it: SAQ D. In person: SAQ P2PE for a PCI-listed P2PE solution, otherwise an SAQ for your terminal type. Your acquirer has the final say.
What changed in PCI DSS v4.0.1 and SAQ A
PCI DSS v4.0.1, published in June 2024, is the only active version since v4.0 retired on 31 December 2024; it clarified wording and added no new requirements. The requirements v4 had future-dated, including 6.4.3 (managing payment page scripts) and 11.6.1 (detecting changes to payment pages), became effective on 31 March 2025. In January 2025 the Council removed 6.4.3, 11.6.1 and 12.3.1 from SAQ A and added an eligibility criterion instead: the merchant confirms its site is not susceptible to attacks from scripts. FAQ 1588 says this applies to pages that embed a provider's payment form, not to redirects, and can be met by your own controls or your provider's confirmation.
Merchant levels
Card brands, not the PCI Council, set merchant levels and how you validate. Visa's current definitions count Visa transactions a year: Level 1, more than 6 million, an annual Report on Compliance and Attestation of Compliance; Level 2, 1 to 6 million, an annual SAQ; Level 3, fewer than 1 million, an annual SAQ. Mastercard and others publish their own levels, and your acquirer may ask for more.
Sources
- PCI SSC: Just published, PCI DSS v4.0.1
- PCI SSC: Important updates for merchants validating to SAQ A (January 2025)
- PCI SSC: FAQ clarifies new SAQ A eligibility criteria (February 2025)
- PCI SSC: Merchant resources
- PCI SSC: Document library (PCI DSS v4.0.1 and SAQs)
- Visa: Security compliance, merchant and service provider levels
- Stripe: Integration security guide
- Razorpay: Custom Checkout integration (PCI note)
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
Do I need PCI compliance if I use Stripe?
Yes. Stripe is a PCI DSS Level 1 service provider for its part, but you still have to accept cards in a compliant way and attest every year. With Stripe Checkout or Elements that is usually SAQ A; Stripe lists the documentation it needs from you in your Dashboard.
Do I need PCI compliance if I use Razorpay or PayU?
Yes, on the same terms. A hosted or embedded checkout keeps card data off your servers and usually means SAQ A. Razorpay's documentation warns that payment information should never reach your servers unless you are PCI DSS certified.
Do I need PCI compliance if I use Square or QuickBooks Payments?
Yes. Every merchant that accepts cards has PCI DSS obligations. Using a provider's hosted checkout, invoices or terminals reduces them; ask the provider which SAQ it expects and whether its terminals are PCI-listed P2PE.
What is SAQ A?
The shortest Self-Assessment Questionnaire, for card-not-present merchants that have fully outsourced card data functions to PCI DSS compliant providers and do not store, process or transmit card data electronically on their own systems.
What changed in SAQ A in 2025?
Requirements 6.4.3, 11.6.1 and 12.3.1 were removed from SAQ A, effective 31 March 2025. In their place, merchants that embed a provider's payment form must confirm their site is not susceptible to script attacks, through their own controls or the provider's confirmation.
Is PCI DSS a law?
No. It is an industry standard enforced through card brand rules and your contract with the acquirer or payment provider. Visa, for example, can impose non-compliance assessments on your acquirer, and your contract decides what is passed on to you.
Do small businesses need PCI compliance?
Yes. The PCI Council says PCI DSS applies to all entities involved in payment processing, regardless of size or transaction volume. How you validate is set by the card brands and your acquirer.
Does PCI DSS apply to UPI payments?
No. PCI DSS covers payment card data. UPI and bank transfers do not use card numbers, so they fall outside it, though your payment provider's terms and data protection law still apply.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.