What You're Still Responsible for When Your Payment Provider Handles Checkout

Team McRales • October 6, 2026

Many business owners assume that if they're using Stripe, Square, PayPal, Wix Payments, Shopify Payments, or another hosted payment solution, PCI compliance is completely handled for them.



The reality is a little more nuanced.

Your payment provider may handle the collection and processing of card information. That can significantly reduce what your business needs to manage directly. However, it doesn't eliminate your responsibility for understanding how payments move through your business, who has access to your systems, and how customer information is handled.


In other words, outsourcing payment processing doesn't mean outsourcing accountability.


"Our Provider Handles PCI" Isn't the Whole Story


One of the most common statements we hear is, "Our provider takes care of PCI."


That may be partially true, but it's rarely the complete story.


PCI DSS (Payment Card Industry Data Security Standard) is the security standard used throughout the payment-card industry. While payment providers often manage much of the technical payment environment, merchants still have responsibilities related to how they use those platforms and how payment information flows through their business.


Different companies can use the exact same ecommerce platform and still have very different responsibilities.


One business may redirect customers to a provider-hosted payment page. Another may embed the payment experience directly into its website. A third may accept phone orders and manually enter card information into a virtual terminal.

Those scenarios aren't equivalent.


What matters is not the name of the platform you're paying for. What matters is the path a customer's payment takes through your business.


The 2025 PCI Changes Are Already Here


If you've been hearing about PCI updates over the last couple of years and wondering whether they affect your business, the answer is probably yes... at least indirectly.


The biggest shift isn't really about new paperwork. It's more about recognizing that ecommerce security doesn't stop at the payment processor.


Historically, many businesses viewed online payments as a simple handoff. The customer clicked "Checkout," entered a card number, and the payment provider handled the rest.


Today, attackers increasingly target the customer journey before the payment is processed. If a website is compromised, malicious code can intercept information, redirect customers, or alter what appears on a payment page even before the transaction ever reaches the payment provider.


And that's one reason recent PCI DSS updates placed additional attention on payment-page security, browser-based attacks, and monitoring for unauthorized changes to ecommerce experiences.


The practical takeaway: A payment provider may own the checkout form, but your website still plays a role in getting customers there safely.


Just because someone else collects the card number doesn't mean your website is completely removed from the security equation.



Five Questions Every Business Owner Should Be Able to Answer


To get a clear understanding of how payments move through your business, start with these five questions.


1. Where Do Customers Enter Payment Information?


List every payment channel your business uses.


That includes:


  • Ecommerce checkout
  • Payment links
  • Hosted payment pages
  • Online invoices
  • Phone orders
  • Virtual terminals
  • Any other method customers use to pay


Many businesses document only their primary checkout process while overlooking secondary payment methods used by customer service or sales staff.


2. Can You Trace the Entire Transaction?


Follow a single sale from beginning to end.


Can you identify:


  • How the order starts?
  • Where payment occurs?
  • Where customer information is stored?
  • How fulfillment happens?
  • How refunds are processed?
  • Which systems generate reports?


The systems don't need to be consolidated into one platform, they just need to be understood.


3. Who Has Access to Everything?


Most payment-related risks have very little to do with software and a lot to do with access.


You should know who controls:


  • Your website
  • Domain registration
  • Ecommerce platform
  • Payment accounts
  • Email systems
  • Connected applications
  • Third-party integrations


Access should be limited to people who genuinely need it.


Former employees, contractors, agencies, and vendors should lose access immediately when their relationship with your business ends.


4. Does Payment Information Appear Outside Approved Processes?


This question catches many businesses off guard.


The payment process itself may be secure, but problems often occur around it.


Examples include:


  • Customers emailing payment information
  • Card details sent through text messages
  • Customer service representatives jotting down card numbers on sticky notes
  • Information shared through chat platforms


Phone payments and virtual terminals can be legitimate business tools, but they may introduce additional processes and responsibilities that need to be understood and managed.


5. Who Confirmed Your Validation Requirements?


Don't assume your business qualifies for a specific PCI assessment path because a blog article, sales representative, or platform partner suggested that it does.


Requirements vary based on how payments are processed.


When there's uncertainty, confirm requirements with your acquiring bank, payment facilitator, payment provider, payment brand, or qualified assessor.


Website Age Isn't the Real Question


Business owners often ask whether their ecommerce platform is too old.


Age, by itself, isn't the issue. A supported platform that receives updates, operates reliably, and meets business needs may continue to serve a company very well.


An unsupported system is a different conversation entirely. Software that no longer receives security updates creates additional risk and should be evaluated carefully.


But platform age still isn't the most important question. A brand-new ecommerce site can be difficult to manage if:


  • Access isn't controlled
  • Integrations aren't documented
  • Checkout customizations aren't understood
  • Processes rely on workarounds
  • Nobody knows how data flows between systems


Likewise, an older platform can remain manageable when it's properly maintained and supported.


The better question: "Can we clearly explain how our business accepts orders, processes payments, fulfills those orders, and records what happened?"


Warning Signs Your Current Setup Needs Attention


A business should take a closer look at its ecommerce environment when basic operational questions are difficult to answer.


Common warning signs include:


  • Nobody can identify every payment channel being used.
  • Multiple people share administrator logins.
  • Former employees or vendors may still have access.
  • Software updates are avoided because nobody understands the impact.
  • Staff receive payment information through email, text, or chat.
  • Orders require repeated manual entry between systems.
  • No one can clearly explain who owns which responsibility.


No one of these items automatically means there's been a breach or compliance issue.


However, they often indicate something more fundamental: A lack of visibility into how the business operates.


That's an operational problem before it becomes a technology problem.


What Hosted Ecommerce Platforms Can Simplify


Hosted ecommerce platforms can eliminate a tremendous amount of infrastructure work. Depending on the platform and implementation, the provider may handle:


  • Server management
  • Core software maintenance
  • Security updates
  • Payment-processing infrastructure
  • PCI-validated payment components


Great! But there are still responsibilities that remain with the business itself.


An ecommerce platform cannot:


  • Decide who should have access to systems
  • Remove former employees from accounts
  • Document internal processes
  • Prevent customers from emailing payment information
  • Clarify ownership of orders and customer records
  • Manage vendor relationships for your business


Simply put, the platform manages the services it provides. Your business still manages how those services are used.


Start With a Payment Map


Before rebuilding a website or buying another security tool, document the payment process you already have.


Map out:


  • Every way customers place orders
  • Every way customers pay
  • Where card information is collected
  • Which systems and vendors are involved
  • Where customer records are stored
  • How orders are fulfilled
  • Every manual handoff
  • Every integration
  • Who owns each account and relationship
  • What your payment provider requires you to validate


This exercise often uncovers opportunities that have nothing to do with replacing a website.


Sometimes the solution is better documentation.


Sometimes it's improved access control.


Sometimes it's a safer phone-order process.


And sometimes it reveals that years of workarounds have made a platform migration the right next step.


The important thing is that the decision is based on evidence rather than assumptions.


The Real Goal


At McRales, we've found that many ecommerce challenges aren't actually website problems, they're process problems.


Businesses often assume they need a new platform when what they really need is a clearer understanding of how orders, payments, customer records, fulfillment, and reporting connect.


Sometimes that discovery leads to a redesign or migration. Sometimes it reveals a handful of operational improvements that can be made without replacing anything.


The goal shouldn't be to own the newest and shiniest ecommerce platform, but to have a commerce system your team understands, can maintain, and can properly operate as your business grows.


That's a far better investment than replacing technology simply because it's old.


Important Disclaimer


This article provides general information about ecommerce operations and payment security. It is not legal advice, cybersecurity advice, PCI DSS assessment guidance, or payment-processing compliance advice. Businesses should consult their acquiring bank, payment facilitator, payment provider, payment brand, or a Qualified Security Assessor regarding specific compliance obligations.


Sources


  1. PCI Security Standards Council. Does PCI DSS Apply to Merchants Who Outsource All Payment Processing Operations and Never Store, Process or Transmit Cardholder Data?
    View Source
  2. PCI Security Standards Council. Protect Payment Data with PCI Security Standards.
    View Source
  3. PCI Security Standards Council. Payment Card Industry Data Security Standard: Self-Assessment Questionnaire A, Version 4.0.1 (January 2025).
    View Source
  4. PCI Security Standards Council. Payment Card Industry Data Security Standard: Self-Assessment Questionnaire A-EP, Version 4.0.1 (October 2024).
    View Source
  5. PCI Security Standards Council. Payment Card Industry Data Security Standard: Requirements and Testing Procedures, Version 4.0.1 (June 2024).
    View Source
  6. PCI Security Standards Council. Important Updates Announced for Merchants Validating to Self-Assessment Questionnaire A. January 30, 2025.
    View Source
  7. PCI Security Standards Council. FAQ Clarifies New SAQ A Eligibility Criteria for E-Commerce Merchants. February 28, 2025.
    View Source
  8. Federal Trade Commission. Cybersecurity for Small Business.
    View Source
  9. Federal Trade Commission. Cybersecurity for Small Business: Vendor Security.
    View Source
  10. PCI Security Standards Council. Protecting Telephone-Based Payment Card Data, Version 3.0 (November 2018).
    View Source
  11. Cybersecurity and Infrastructure Security Agency. Understanding Patches and Software Updates.
    View Source
  12. Cybersecurity and Infrastructure Security Agency. Update Business Software.
    View Source


By Joseph Morales • September 12, 2024
From Website Tweaks to SEO: Your Holiday Success Guide
A person is holding a credit card and a cell phone.
By Team McRales • March 26, 2024
Experience seamless sales, unrivaled support, and mobile mastery when you upgrade your Square Online Store with Ecwid. Our latest blog post at McRales.com explores the transformative benefits of integrating Square with Ecwid. Discover how to sync your offline and online sales effortlessly, tap into six hours of expert web design assistance, and captivate your customers with a fully-branded mobile shopping experience. Elevate your e-commerce platform today with McRales—where technology meets tailor-made solutions. Read our insightful guide to push your online business ahead of the curve.
FAQ Graphic
August 25, 2021
FAQs (short for frequently asked questions) help your business stay organized and allow customers to find information easily online, rather than having to call or visit your store/office to get the information they need. Your website design company should recommend that you create an FAQ page as part of your digital marketing strategy. If you haven’t created an FAQ page on your website yet, here are some tips on how to do it right and get the most out of it. What is a FAQ? A frequently asked question, or FAQ, is exactly what it sounds like: an answer people might commonly ask about a specific topic. If you are running a business and selling something online, there’s no better way to quell customer concerns than with an easily accessible list of frequently asked questions. They should be short and sweet — just enough info that someone with limited knowledge of your product can grasp its uses quickly and easily.