Akurateco
Akurateco

PCI DSS Compliant Payment Gateway: What it is, Benefits and Key Requirements

May 04, 2025
9 min
pci dss compliant payment gateway

A payment gateway transmits card data between the checkout and the acquirer, so it falls under the Payment Card Industry Data Security Standard (PCI DSS). The current version of the standard is PCI DSS v4.0.1, and Akurateco’s platform is certified against it as a Level 1 service provider.

Key takeaways:

  • PCI DSS v4.0.1 has been the only active version of the standard since January 1, 2025.
  • A compliant gateway covers its own platform. Your checkout, integration and connected systems stay in your PCI DSS scope.
  • Your integration method sets your validation route: a hosted payment page or embedded payment form typically means SAQ A, a form that posts directly to the gateway SAQ A-EP, and a server-to-server API SAQ D.
  • Akurateco is certified as a PCI DSS Level 1 service provider against v4.0.1.

What is a PCI Compliant Payment Gateway?

To understand the concept, let’s break it down into two parts. First, let’s look at what a payment gateway is.

A payment gateway is software that enables transaction processing by facilitating electronic transactions and exchanging payment data between customers, payment processors, card networks, issuing banks, acquiring banks, and ultimately merchants, ensuring the secure and efficient transfer of funds. Simply put, it is a technical layer that allows merchants to accept payments from customers.

PCI DSS compliance, often called PCI compliance, stands for compliance with the Payment Card Industry Data Security Standard. It is a set of mandatory security standards and best practices established by the Payment Card Industry Security Standards Council (PCI SSC) to protect customers’ sensitive credit card and payment information during and after transaction processing.

Now, let’s combine these two concepts. A PCI compliant payment gateway is software or a service that meets PCI DSS security requirements and standards. If a payment gateway is PCI DSS certified, it indicates it has implemented the necessary security measures to safeguard sensitive card data. Under PCI DSS, a gateway is a service provider: it transmits card data on behalf of merchants. At Level 1, a Qualified Security Assessor (QSA) assesses the gateway every year, and the result is documented in a Report on Compliance (ROC) and an Attestation of Compliance (AOC).

Understanding PCI DSS Requirements

PCI DSS v4.0.1 is built around 12 core requirements that help organizations protect cardholder data and reduce payment security risks. These requirements apply to merchants and service providers that store, process, transmit, or can affect the security of cardholder data.

The 12 PCI DSS requirements are:

  1. Install and maintain network security controls.
  2. Apply secure configurations to all system components.
  3. Protect stored account data.
  4. Protect cardholder data with strong cryptography during transmission over open, public networks.
  5. Protect all systems and networks from malicious software.
  6. Develop and maintain secure systems and software.
  7. Restrict access to system components and cardholder data by business need to know.
  8. Identify users and authenticate access to system components.
  9. Restrict physical access to cardholder data.
  10. Log and monitor all access to system components and cardholder data.
  11. Test security of systems and networks regularly.
  12. Support information security with organizational policies and programs.

In simple terms, PCI DSS requires companies to secure payment systems, protect stored and transmitted card data, control access to payment environments, monitor activity, test systems regularly, and maintain documented security policies.

What Changed in PCI DSS v4.0.1?

PCI DSS v4.0.1 is the current version of the standard. It is a limited revision of v4.0 that clarifies wording and guidance and adds no new requirements. The key dates:

  • March 2022: PCI SSC publishes PCI DSS v4.0.
  • March 31, 2024: v3.2.1 is retired.
  • June 2024: v4.0.1 is published.
  • December 31, 2024: v4.0 is retired. From January 1, 2025, v4.0.1 is the only active version.
  • March 31, 2025: requirements that v4.0 introduced as future-dated become mandatory.

The changes that matter most for payment platforms came with v4.0: multi-factor authentication for all access into the cardholder data environment, passwords of at least 12 characters, controls on scripts running on payment pages, targeted risk analyses, and a customized approach to meeting requirements that is available only in assessments documented in a Report on Compliance.

Akurateco’s platform is assessed against PCI DSS v4.0.1. In June 2026, PCI SSC opened a consultation on v4.0.1 as the first step toward the next version of the standard. Until a new version is published, assessments use v4.0.1.

The Importance of PCI DSS Compliance

PCI DSS compliance matters to every party that handles card data, for the reasons below.

Legal obligations

PCI DSS compliance is not optional for any organization that accepts, processes, stores, or transmits cardholder data. It is required through card brand, acquirer, and payment partner compliance programs, while local laws and regulations may also apply depending on the market. Failure to comply can lead to fines, higher processing costs, increased audit requirements, or even restrictions on payment processing.

Data security

If your gateway provider is not validated against PCI DSS, you have no assurance that it protects card data. The consequences can be severe, ranging from financial loss to lasting reputation damage. The essence of PCI DSS certification is protecting sensitive cardholder data. Compliance requires specific controls against unauthorized access, breaches and theft of card data.

Financial protection

PCI DSS lowers the likelihood of a data breach and of the fines, legal fees and remediation costs that follow one.

Reputational management

A card data breach can cost a merchant or PSP customer trust that is hard to win back.

Customer trust

Whenever a customer wants to make a purchase on a website, they first evaluate how safe it is to enter their payment information. Compliance with PCI DSS signals to customers that their card data is protected, which makes them more willing to complete the purchase.

How a PCI DSS Compliant Payment Gateway Works

A PCI DSS compliant payment gateway facilitates secure online transactions by encrypting and transmitting a customer’s card data, obtaining authorization from the issuing bank through the acquirer, and returning the result to the merchant.

For a deeper understanding of how payment gateways operate, read the article below:

How a Payment Gateway Works

The gateway protects card data at every stage of the transaction. It may also offer additional technologies to protect customers from fraud, such as 3-D Secure authentication, tokenization (replacing actual card data with randomly generated tokens) and fraud prevention to enhance security further.

To maintain PCI DSS compliance, payment gateways undergo annual audits and assessments to verify their adherence to security standards.

How your integration method shapes your PCI DSS scope

How card data reaches the gateway decides how much of your own environment PCI DSS covers. The validation routes below are the typical outcome for merchants; your acquirer or QSA confirms the final one.

Integration methodWhere the customer enters card dataWhat stays in your scopeTypical validation
Hosted payment page (redirect)On the gateway’s pageThe website that sends customers to the payment pageSAQ A
Embedded payment form (iframe)In the gateway’s form inside your pageThe page that embeds the form; you must also confirm your site is not susceptible to script-based attacksSAQ A
Payment form on your own page that posts directly to the gatewayOn your page, sent straight to the gatewayThe web servers and scripts that deliver your payment pageSAQ A-EP
Server-to-server APIOn your systems, which pass it to the gatewayYour application, servers, network and admin accessSAQ D (ROC at Level 1)
Mobile SDKIn your app, through the gateway’s SDKYour app and backend, depending on how the SDK handles card dataConfirm with your QSA

Using a compliant gateway does not take you out of scope. The gateway’s assessment covers its own platform. You remain responsible for what you control: your checkout pages and the scripts on them, your integration, admin access, logs and support tools, and any system connected to where card data flows.

Benefits of Using a PCI DSS Compliant Payment Gateway

A compliant gateway gives merchants and PSPs the following benefits:

  1. Legal and regulatory compliance

Acquirers and card brands expect every provider that handles card data for you to be validated against PCI DSS. A compliant gateway covers the controls on its side of the payment flow. It supports your own compliance but does not replace it.

  1. Security controls you do not have to build

The gateway runs the encryption, tokenization, access control, logging and security testing that PCI DSS requires for card data. For a Level 1 provider, a QSA checks these controls every year.

  1. Global expansion

PCI DSS standards and requirements are internationally recognized and accepted in many countries around the world. That is why merchants using a compliant gateway can accept transactions worldwide and expand their customer base, knowing that they meet established security standards.

  1. Smaller PCI DSS scope

When customers enter card data on the gateway’s hosted page or in its embedded form, card numbers never reach your servers. Fewer of your systems fall under PCI DSS, and your annual validation is shorter. The integration table above shows the typical outcome for each method.

  1. No card numbers in your own database

With the gateway’s tokenization, you store a token instead of the card number, so recurring and repeat payments run without card data in your database.

PCI DSS Compliance Levels

PCI DSS compliance levels are commonly based on annual transaction volume. The exact validation requirements may vary by card brand, acquirer, region, and business model, so companies should always confirm the final validation route with their acquiring bank or payment partner.

LevelTransaction volume thresholdValidation requirementAssessor required
Level 1More than 6 million card transactions per year, or any merchant designated Level 1 by a card brand or acquirerAnnual Report on Compliance (ROC) and Attestation of Compliance (AOC)Yes, usually a Qualified Security Assessor (QSA) or approved internal assessment route where allowed
Level 21 million to 6 million card transactions per yearAnnual Self-Assessment Questionnaire (SAQ) and Attestation of Compliance (AOC), unless a ROC is required by the acquirer or card brandUsually no for SAQ-based validation, but may be required by the acquirer or card brand
Level 320,000 to 1 million e-commerce card transactions per yearAnnual SAQ and AOCUsually no, unless required by the acquirer or card brand
Level 4Fewer than 20,000 e-commerce card transactions per year, or up to 1 million total card transactions per year depending on card brand/acquirer rulesAnnual SAQ and AOC, as required by the acquirer or payment partnerUsually no, unless required by the acquirer or card brand

These levels apply to merchants. Payment gateways, PSPs and other service providers have their own two levels, set by the card brands. Level 1 generally covers service providers above 300,000 card transactions a year and requires an annual ROC by a QSA and quarterly network scans by an Approved Scanning Vendor (ASV). Level 2 covers smaller service providers and allows a self-assessment. Akurateco is certified as a Level 1 service provider.

Who needs a PCI DSS compliant payment gateway?

PCI DSS applies to any organization that stores, processes or transmits cardholder data, or whose systems can affect the security of that data.

A PCI payment gateway is crucial for merchants that process payment card transactions, including e-commerce websites, subscription services, retailers, online marketplaces, and any merchant that handles card data, to secure it during transaction processing.

It is also mandatory for Payment Service Providers (PSPs) who offer their services to merchants, to protect the data they handle on their behalf.

Systems that connect to the cardholder data environment count too, and a payment server on an unsegmented network can bring the whole network into scope.

To learn how to integrate a gateway into your website or application, read the article below:

Payment Gateway Integration: A Step-by-Step Guide for Business Owners

How to achieve PCI DSS compliance cost-effectively

Here is a practical process for approaching PCI DSS compliance without overcomplicating the project. For a breakdown of what each step costs, see our PCI DSS cost guide.

1. Define your PCI DSS scope

Identify where cardholder data is stored, processed, transmitted, or could be affected by your systems, vendors, checkout, payment gateway, integrations, logs, support tools and admin access.

2. Confirm your PCI DSS level and validation route

Your transaction volume, role in the payment flow, and acquirer/card brand requirements determine whether you need a Self-Assessment Questionnaire, Report on Compliance, Attestation of Compliance, or QSA-led assessment.

3. Choose the right payment setup

A compliant gateway such as Akurateco’s white-label payment gateway platform, combined with a hosted payment page, tokenization or a payment orchestration layer, reduces the amount of card data your systems touch. Network segmentation keeps the systems that stay in scope apart from the rest of your infrastructure. For organizations with stricter regulatory, data residency, or infrastructure-control requirements, on-premises infrastructure for compliance can provide greater control over where payment data and critical systems are hosted.

When you compare providers, check:

  • a current Attestation of Compliance that names the services you use and is dated within the last 12 months;
  • the provider’s service-provider level;
  • which integration methods keep card data off your systems;
  • support for tokenization and 3-D Secure;
  • a responsibility matrix that shows which PCI DSS requirements the provider covers and which stay with you.

4. Review gaps against the 12 PCI DSS requirements

Check network security, system configurations, stored data, encryption, malware protection, software security, access control, logging, testing, and internal security policies.

5. Prepare documentation and evidence

Collect policies, architecture diagrams, provider responsibility matrices, scan results, access records, change logs, and other evidence needed for validation.

6. Complete the required assessment

Depending on your level and business model, this may involve completing an SAQ, working with a Qualified Security Assessor, preparing a Report on Compliance, and submitting an Attestation of Compliance.

7. Maintain compliance continuously

PCI DSS compliance is not a one-time task. Merchants and service providers need ongoing monitoring, regular testing, vulnerability management, policy reviews, and annual validation.

Maintaining PCI DSS compliance with Akurateco

Akurateco provides white-label payment gateway and payment orchestration software with 700+ payment integrations for PSPs and merchants. It is the gateway and orchestration layer on top of acquirers and does not process transactions itself.

Certification status

Akurateco is certified as a PCI DSS Level 1 service provider. Its most recent assessment was carried out by a QSA against PCI DSS v4.0.1. Clients can request Akurateco’s Attestation of Compliance.

SaaS and On-Premises: who covers what

DeploymentAkurateco coversYour responsibility
SaaSThe certified platform environment and its controlsYour checkout, integration, scripts, admin access and connected systems
On-PremisesThe software, plus documentation and support for your QSA assessmentCertifying your own infrastructure, plus everything listed for SaaS

Clients with a non-PCI DSS compliant payment page

For merchants without PCI DSS-compliant checkout pages, we offer Hosted Payment Page (HPP) integration coupled with a Software Development Kit (SDK) that enables complete customization according to the client’s logo, color scheme, and other branding preferences.

Also, they can integrate a payment gateway via Server-to-Server (S2S) APM that redirects the user to the Akurateco server for payment. If merchants work on platforms such as WooCommerce or PrestaShop, they can use the plugins for payment gateway integration that Akurateco provides.

Clients with PCI DSS compliant payment page

If a merchant’s checkout page is PCI DSS compliant, they have the flexibility to select from the integration options listed below:

  • HPP
  • API REST/API SOAP (S2S)
  • Mobile SDK
  • CMS plugins

Server-to-server API integration puts card data on your systems; see the integration table above for what that means for your scope.

For merchants and PSPs working toward their own certification, Akurateco supports Level 3 and Level 4 compliance for merchants and Level 2 for PSPs. For example, TESS Payments launched on Akurateco’s SaaS platform in Qatar and obtained PCI DSS certification alongside its Qatar Central Bank PSP license.

As Akurateco collaborates with Qualified Security Assessors (QSAs), our experts can guide you throughout the compliance process step by step, from preparing documents to achieving PCI DSS certification. We’ll also provide the documentation from our side, including details about our system’s architecture and other necessary documents.

Conclusion

A PCI DSS compliant payment gateway protects card data on its side of the payment flow, but how much compliance work stays with you depends on how you integrate it. PCI DSS v4.0.1 is the version every assessment uses today, and Akurateco’s platform is certified against it as a Level 1 service provider.

Would you like to explore Akurateco's PCI DSS-compliant payment system to safeguard your clients' payment journey?
Schedule a free demo with our experts and see it in action.
Request a Demo

PCI DSS Compliance FAQ

What does PCI compliant mean?

PCI compliance means following the Payment Card Industry Data Security Standard, a set of technical and operational security requirements for protecting payment card data. Merchants, PSPs, payment gateways and other service providers that handle cardholder data need to follow PCI DSS requirements based on their role in the payment flow.

Who needs to be PCI DSS compliant?

Any organization that stores, processes, transmits, or can affect the security of cardholder data needs to comply with PCI DSS. This includes merchants, payment gateways, PSPs, processors, acquirers, and third-party service providers involved in payment processing. Even if a merchant uses a PCI DSS compliant payment gateway, the merchant may still have PCI DSS responsibilities depending on how its checkout, website, systems, and providers are set up.

What are the 12 PCI DSS requirements?

The 12 PCI DSS requirements cover network security controls, secure system configurations, protection of stored account data, encryption of transmitted cardholder data, malware protection, secure software development, access control, user authentication, physical access restrictions, logging and monitoring, regular security testing, and information security policies. Together, they define how organizations should protect cardholder data across payment systems and business processes.

How long does PCI DSS certification take?

PCI DSS certification can take from a few weeks to several months, depending on the organization’s size, payment setup, current security maturity, and required validation type. A smaller merchant using a hosted PCI DSS compliant payment page may complete a self-assessment faster, while a payment gateway, PSP, or larger service provider usually needs a more detailed assessment with a Qualified Security Assessor. If remediation is needed, the timeline can extend until systems, policies, documentation, and security controls are ready for validation.

Which version of PCI DSS is current?

PCI DSS v4.0.1 is the current version. It was published in June 2024 and has been the only active version since v4.0 was retired on December 31, 2024. Requirements that v4.0 introduced as future-dated have been mandatory since March 31, 2025. PCI SSC started gathering feedback for the next version in 2026, but assessments still use v4.0.1.

Which PCI DSS version is Akurateco certified against?

Akurateco is certified as a PCI DSS Level 1 service provider against PCI DSS v4.0.1. The certification covers Akurateco’s SaaS platform. Clients running Akurateco On-Premises certify their own infrastructure, and Akurateco provides the documentation their QSA needs. In both models, clients stay responsible for their own checkout, integrations and connected systems.

What is the difference between a PCI compliant payment gateway and a payment processor?

A payment gateway transmits card data from the checkout to the acquirer or processor and returns the authorization result. A payment processor handles authorization and settlement with the card networks and banks. Both must comply with PCI DSS. Akurateco provides gateway and orchestration software on top of acquirers and processors and does not process transactions itself.

How can I check whether a payment gateway provider is PCI DSS compliant?

Ask the provider for its current Attestation of Compliance (AOC). Check that the AOC names the services you use, is dated within the last 12 months and, for a Level 1 service provider, is signed by a QSA. Card brands also list validated service providers, for example in Visa’s Global Registry of Service Providers.

Is PCI DSS a law?

No. PCI DSS is an industry standard, not a law. Card brands enforce it through their agreements with acquirers, and acquirers pass the requirements on to merchants and service providers. Non-compliance can lead to fines, higher processing fees or losing the ability to accept cards, and data protection laws may also apply if card data is breached.

Want to learn how we can benefit your business?
Request a Demo
Enjoyed our content?
Follow us on LinkedIn
Request a Demo