E-commerce and payments
What is PCI DSS?
PCI DSS is the security standard governing how card data is handled. The practical implication for most small merchants is simple: never let card data touch your server, and your compliance obligation shrinks to a short self-assessment questionnaire.
Also called: PCI compliance · card data security
How to keep scope small
- Use a hosted payment page or a provider-hosted iframe, so card numbers never reach your application
- Never log, store or email card details, including in error reports
- Keep the payment step on your own HTTPS domain to avoid customer confusion
- Do not accept card details by phone, email or WhatsApp — this is the most common accidental breach in small businesses
What changes if you build a custom form
Handling card fields yourself, even briefly, moves you into a much larger compliance scope with quarterly scanning and a longer questionnaire. The cost is real and ongoing, which is why hosted checkout is the default recommendation.
The part that is not optional
PCI applies whether or not anyone asks you about it. Most small merchants never complete the questionnaire and only discover the obligation after an incident, when the position is considerably worse.
Where this is covered in depth
A definition can only go so far. E-commerce website development: what the whole build actually involves covers this properly — 7 minutes, free, no email required.
Who wrote this
Anas Bin Masud builds e-commerce sites and does technical SEO for businesses in the UK, Canada and Pakistan. These definitions come from client work rather than from a content brief — where an entry describes a mistake, it is usually one found on a real site. More about how I work.