Get NIST-y

·S2 E28

PCI Compliance Is Not Handled Just Because You Use Stripe

July 14
26 mins

Episode Description

Using Stripe, Square, Shopify, or a hosted checkout can shrink your PCI scope, but it does not make PCI disappear. This episode of Get NIST-y gets into where MSP responsibility actually starts, where it should stop, and why payment page scripts are not “just a marketing thing.”


Takeaways:

- Why every business that accepts cards still has PCI obligations

- How SAQ A can turn into SAQ D when clients get creative

- Why MSPs should help answer SAQs, not sign them

- How analytics tags, chat widgets, pixels, and WordPress plugins can create real payment page risk


We answer:

- Where does the MSP’s PCI responsibility start and stop when clients use Shopify, Stripe, Square, or WordPress payment plugins?

- How should an MSP explain payment page script risk without sounding like the fun police?


Make sure to follow the podcast or ask your own questions at:

https://blacksmithinfosec.com/nisty/

See all episodes