Skip to main content
Cresora Commerce
Merchant Onboarding

Merchant Compliance Requirements

What the merchant application collects, and the two compliance documents the portal takes.

Compliance data for a merchant is collected in two places: the application wizard (structured data, at submission) and the Compliance pages (document uploads, before go-live).

What the application collects

The New Merchant wizard (Partner Portal → Payments → Merchants) collects the underwriting data as structured fields — business details (legal name, contact email, MCC), principals and beneficial owners, funding/banking details, and the processing profile. There is no free-form document checklist: the wizard's required fields are the requirements, and it will not submit without them.

The two document uploads

WhereDocumentNeeded when
Compliance → PCI SAQThe completed, signed PCI SAQAll partners, before go-live
Compliance → HIPAA BAAThe signed Business Associate AgreementHealthcare merchants

Both feed the merchant's go-live gate (PCI_SAQ, HIPAA_BAA items).

Expiry and renewal

The platform does not send document-expiry reminders. A SAQ is an annual obligation — keep your own renewal calendar, and re-upload when you renew.

When Cresora asks for more

Review can pause at AWAITING_CLARIFICATION with a question shown on the merchant's page (clarification_message); answer it there to resume. Enhanced due diligence for high-risk categories is handled through your account manager, case by case.