Portal Guides
Compliance & Certification in the Portal
The certification check run and the compliance uploads in the Partner Portal.
Two portal surfaces cover this: Integration → Certification (the check run that gates production) and the Compliance group (HIPAA BAA, PCI SAQ).
Certification
Partner Portal → Integration → Certification
Certification is a check run, not a document submission:
- Start certification — the platform prepares your check catalog
- Run checks — automated checks verify your sandbox activity directly (the required scenarios are what they look for)
- Confirm the self-attestation checks in the portal where asked; a few checks are ruled by Cresora reviewers
- Re-run checks as you close gaps — progress is visible per check
There is no evidence-file upload and no review-by-email path. When the run is complete, production access follows — see Go-live →.
Compliance uploads
| Where | What |
|---|---|
| Compliance → PCI SAQ | Upload your completed, signed SAQ; the page tracks its status |
| Compliance → HIPAA BAA | For healthcare partners: upload the signed BAA |
These are the two compliance documents the portal collects. Reminders are not sent — track your own renewal calendar (a SAQ is an annual obligation on your side).
Per-merchant compliance
Merchant-level gates (gateway account, processor profile, BAA/SAQ where applicable) are visible on each merchant — see Go-live gates →.