Skip to main content
Cresora Commerce
Portal Guides

Compliance & Certification in the Portal

The certification check run and the compliance uploads in the Partner Portal.

Two portal surfaces cover this: Integration → Certification (the check run that gates production) and the Compliance group (HIPAA BAA, PCI SAQ).

Certification

Partner Portal → Integration → Certification

Certification is a check run, not a document submission:

  1. Start certification — the platform prepares your check catalog
  2. Run checks — automated checks verify your sandbox activity directly (the required scenarios are what they look for)
  3. Confirm the self-attestation checks in the portal where asked; a few checks are ruled by Cresora reviewers
  4. Re-run checks as you close gaps — progress is visible per check

There is no evidence-file upload and no review-by-email path. When the run is complete, production access follows — see Go-live →.

Compliance uploads

WhereWhat
Compliance → PCI SAQUpload your completed, signed SAQ; the page tracks its status
Compliance → HIPAA BAAFor healthcare partners: upload the signed BAA

These are the two compliance documents the portal collects. Reminders are not sent — track your own renewal calendar (a SAQ is an annual obligation on your side).

Per-merchant compliance

Merchant-level gates (gateway account, processor profile, BAA/SAQ where applicable) are visible on each merchant — see Go-live gates →.