Skip to main content
Cresora Commerce
Certification

Compliance Requirements for Certification

PCI and NACHA compliance requirements you must meet before going live.

Completing Cresora certification requires demonstrating compliance with relevant payment industry standards.

PCI DSS

You must complete the PCI Self-Assessment Questionnaire (SAQ) that your QSA or compliance advisor determines for your environment. Both Cresora integration surfaces — the hosted page and the saved-card charge by vault token — keep card data off your systems. The hosted page is commonly the SAQ A shape; the determination remains yours to make with your QSA.

Submit your completed SAQ with your certification evidence.

🔒PCI DSS requirement

Your SAQ must be current (within the past 12 months) and signed. Cresora cannot issue live keys without a completed SAQ.

NACHA (if using ACH)

If your integration processes ACH payments, you must confirm:

  • NACHA-compliant authorization language displayed before collecting bank account details
  • Authorization records retained for 2 years after the last ACH entry
  • R10 return handling implemented (stop all retries immediately)
  • Reg E re-notification flow implemented (for recurring ACH plans)

See ACH Authorization Language → for the required authorization text.

Compliance documentation to submit

DocumentRequired for
Completed PCI SAQAll partners
NACHA authorization language screenshotACH integrations
R10 handling flow diagram or codeACH integrations
Security architecture diagramPartners whose QSA determines SAQ D