What You're Still Responsible for When Your Payment Provider Handles Checkout
Many business owners assume that if they're using Stripe, Square, PayPal, Wix Payments, Shopify Payments, or another hosted payment solution, PCI compliance is completely handled for them.
The reality is a little more nuanced.

Your payment provider may handle the collection and processing of card information. That can significantly reduce what your business needs to manage directly. However, it doesn't eliminate your responsibility for understanding how payments move through your business, who has access to your systems, and how customer information is handled.
In other words, outsourcing payment processing doesn't mean outsourcing accountability.
"Our Provider Handles PCI" Isn't the Whole Story
One of the most common statements we hear is, "Our provider takes care of PCI."
That may be partially true, but it's rarely the complete story.
PCI DSS (Payment Card Industry Data Security Standard) is the security standard used throughout the payment-card industry. While payment providers often manage much of the technical payment environment, merchants still have responsibilities related to how they use those platforms and how payment information flows through their business.
Different companies can use the exact same ecommerce platform and still have very different responsibilities.
One business may redirect customers to a provider-hosted payment page. Another may embed the payment experience directly into its website. A third may accept phone orders and manually enter card information into a virtual terminal.
Those scenarios aren't equivalent.
What matters is not the name of the platform you're paying for. What matters is the path a customer's payment takes through your business.
The 2025 PCI Changes Are Already Here
If you've been hearing about PCI updates over the last couple of years and wondering whether they affect your business, the answer is probably yes... at least indirectly.
The biggest shift isn't really about new paperwork. It's more about recognizing that ecommerce security doesn't stop at the payment processor.
Historically, many businesses viewed online payments as a simple handoff. The customer clicked "Checkout," entered a card number, and the payment provider handled the rest.
Today, attackers increasingly target the customer journey before the payment is processed. If a website is compromised, malicious code can intercept information, redirect customers, or alter what appears on a payment page even before the transaction ever reaches the payment provider.
And that's one reason recent PCI DSS updates placed additional attention on payment-page security, browser-based attacks, and monitoring for unauthorized changes to ecommerce experiences.
The practical takeaway: A payment provider may own the checkout form, but your website still plays a role in getting customers there safely.
Just because someone else collects the card number doesn't mean your website is completely removed from the security equation.
Five Questions Every Business Owner Should Be Able to Answer
To get a clear understanding of how payments move through your business, start with these five questions.
1. Where Do Customers Enter Payment Information?
List every payment channel your business uses.
That includes:
- Ecommerce checkout
- Payment links
- Hosted payment pages
- Online invoices
- Phone orders
- Virtual terminals
- Any other method customers use to pay
Many businesses document only their primary checkout process while overlooking secondary payment methods used by customer service or sales staff.
2. Can You Trace the Entire Transaction?
Follow a single sale from beginning to end.
Can you identify:
- How the order starts?
- Where payment occurs?
- Where customer information is stored?
- How fulfillment happens?
- How refunds are processed?
- Which systems generate reports?
The systems don't need to be consolidated into one platform, they just need to be understood.
3. Who Has Access to Everything?
Most payment-related risks have very little to do with software and a lot to do with access.
You should know who controls:
- Your website
- Domain registration
- Ecommerce platform
- Payment accounts
- Email systems
- Connected applications
- Third-party integrations
Access should be limited to people who genuinely need it.
Former employees, contractors, agencies, and vendors should lose access immediately when their relationship with your business ends.
4. Does Payment Information Appear Outside Approved Processes?
This question catches many businesses off guard.
The payment process itself may be secure, but problems often occur around it.
Examples include:
- Customers emailing payment information
- Card details sent through text messages
- Customer service representatives jotting down card numbers on sticky notes
- Information shared through chat platforms
Phone payments and virtual terminals can be legitimate business tools, but they may introduce additional processes and responsibilities that need to be understood and managed.
5. Who Confirmed Your Validation Requirements?
Don't assume your business qualifies for a specific PCI assessment path because a blog article, sales representative, or platform partner suggested that it does.
Requirements vary based on how payments are processed.
When there's uncertainty, confirm requirements with your acquiring bank, payment facilitator, payment provider, payment brand, or qualified assessor.
Website Age Isn't the Real Question
Business owners often ask whether their ecommerce platform is too old.
Age, by itself, isn't the issue. A supported platform that receives updates, operates reliably, and meets business needs may continue to serve a company very well.
An unsupported system is a different conversation entirely. Software that no longer receives security updates creates additional risk and should be evaluated carefully.
But platform age still isn't the most important question. A brand-new ecommerce site can be difficult to manage if:
- Access isn't controlled
- Integrations aren't documented
- Checkout customizations aren't understood
- Processes rely on workarounds
- Nobody knows how data flows between systems
Likewise, an older platform can remain manageable when it's properly maintained and supported.
The better question: "Can we clearly explain how our business accepts orders, processes payments, fulfills those orders, and records what happened?"
Warning Signs Your Current Setup Needs Attention
A business should take a closer look at its ecommerce environment when basic operational questions are difficult to answer.
Common warning signs include:
- Nobody can identify every payment channel being used.
- Multiple people share administrator logins.
- Former employees or vendors may still have access.
- Software updates are avoided because nobody understands the impact.
- Staff receive payment information through email, text, or chat.
- Orders require repeated manual entry between systems.
- No one can clearly explain who owns which responsibility.
No one of these items automatically means there's been a breach or compliance issue.
However, they often indicate something more fundamental: A lack of visibility into how the business operates.
That's an operational problem before it becomes a technology problem.
What Hosted Ecommerce Platforms Can Simplify
Hosted ecommerce platforms can eliminate a tremendous amount of infrastructure work. Depending on the platform and implementation, the provider may handle:
- Server management
- Core software maintenance
- Security updates
- Payment-processing infrastructure
- PCI-validated payment components
Great! But there are still responsibilities that remain with the business itself.
An ecommerce platform cannot:
- Decide who should have access to systems
- Remove former employees from accounts
- Document internal processes
- Prevent customers from emailing payment information
- Clarify ownership of orders and customer records
- Manage vendor relationships for your business
Simply put, the platform manages the services it provides. Your business still manages how those services are used.
Start With a Payment Map
Before rebuilding a website or buying another security tool, document the payment process you already have.
Map out:
- Every way customers place orders
- Every way customers pay
- Where card information is collected
- Which systems and vendors are involved
- Where customer records are stored
- How orders are fulfilled
- Every manual handoff
- Every integration
- Who owns each account and relationship
- What your payment provider requires you to validate
This exercise often uncovers opportunities that have nothing to do with replacing a website.
Sometimes the solution is better documentation.
Sometimes it's improved access control.
Sometimes it's a safer phone-order process.
And sometimes it reveals that years of workarounds have made a platform migration the right next step.
The important thing is that the decision is based on evidence rather than assumptions.
The Real Goal
At McRales, we've found that many ecommerce challenges aren't actually website problems, they're process problems.
Businesses often assume they need a new platform when what they really need is a clearer understanding of how orders, payments, customer records, fulfillment, and reporting connect.
Sometimes that discovery leads to a redesign or migration. Sometimes it reveals a handful of operational improvements that can be made without replacing anything.
The goal shouldn't be to own the newest and shiniest ecommerce platform, but to have a commerce system your team understands, can maintain, and can properly operate as your business grows.
That's a far better investment than replacing technology simply because it's old.
Important Disclaimer
This article provides general information about ecommerce operations and payment security. It is not legal advice, cybersecurity advice, PCI DSS assessment guidance, or payment-processing compliance advice. Businesses should consult their acquiring bank, payment facilitator, payment provider, payment brand, or a Qualified Security Assessor regarding specific compliance obligations.
Sources
- PCI Security Standards Council. Does PCI DSS Apply to Merchants Who Outsource All Payment Processing Operations and Never Store, Process or Transmit Cardholder Data?
View Source - PCI Security Standards Council. Protect Payment Data with PCI Security Standards.
View Source - PCI Security Standards Council. Payment Card Industry Data Security Standard: Self-Assessment Questionnaire A, Version 4.0.1 (January 2025).
View Source - PCI Security Standards Council. Payment Card Industry Data Security Standard: Self-Assessment Questionnaire A-EP, Version 4.0.1 (October 2024).
View Source - PCI Security Standards Council. Payment Card Industry Data Security Standard: Requirements and Testing Procedures, Version 4.0.1 (June 2024).
View Source - PCI Security Standards Council. Important Updates Announced for Merchants Validating to Self-Assessment Questionnaire A. January 30, 2025.
View Source - PCI Security Standards Council. FAQ Clarifies New SAQ A Eligibility Criteria for E-Commerce Merchants. February 28, 2025.
View Source - Federal Trade Commission. Cybersecurity for Small Business.
View Source - Federal Trade Commission. Cybersecurity for Small Business: Vendor Security.
View Source - PCI Security Standards Council. Protecting Telephone-Based Payment Card Data, Version 3.0 (November 2018).
View Source - Cybersecurity and Infrastructure Security Agency. Understanding Patches and Software Updates.
View Source - Cybersecurity and Infrastructure Security Agency. Update Business Software.
View Source







