Skip to main content
Cresora Commerce
Compliance

PCI DSS Overview

PCI DSS requirements and how Cresora helps you maintain compliance.

Payment Card Industry Data Security Standard (PCI DSS) applies to any organization that stores, processes, or transmits cardholder data. Cresora is PCI DSS validated as a service provider; its Attestation of Compliance (AoC) is available on request.

Your PCI scope

Your scope follows how card data reaches Cresora, and on both Cresora surfaces it never reaches you:

SurfaceWhat happens to card data
Hosted page (redirect or iframe)Entered on a Cresora-served page; never transits your systems. Commonly the SAQ A shape.
Saved-card charge by vault tokenYour server sends a cvt_ token, never a card number; a raw card is rejected with 400.
πŸ”’Your QSA decides

Which SAQ applies to your business is determined by your QSA or compliance advisor, based on your whole environment β€” not by this page.

What Cresora handles

As a PCI DSS validated service provider, Cresora:

  • Stores card data in a PCI-compliant environment
  • Transmits all cardholder data over TLS 1.2+
  • Maintains its own annual PCI assessment
  • Provides you with its Attestation of Compliance (AoC) on request

Your responsibilities

Even with Cresora handling card storage and processing, you are responsible for:

  • Completing your annual SAQ (the one your QSA determines for your environment)
  • Ensuring your servers and systems meet baseline security requirements
  • Not logging cardholder data (card numbers, CVV, full magnetic stripe)
  • Maintaining secure coding practices
  • Training staff on cardholder data handling

Getting Cresora's AoC

Request Cresora's Attestation of Compliance for your records through your Cresora account manager β€” there is no self-service portal page for it yet.