Episode Description
Using Stripe, Square, Shopify, or a hosted checkout can shrink your PCI scope, but it does not make PCI disappear. This episode of Get NIST-y gets into where MSP responsibility actually starts, where it should stop, and why payment page scripts are not “just a marketing thing.”
Takeaways:
- Why every business that accepts cards still has PCI obligations
- How SAQ A can turn into SAQ D when clients get creative
- Why MSPs should help answer SAQs, not sign them
- How analytics tags, chat widgets, pixels, and WordPress plugins can create real payment page risk
We answer:
- Where does the MSP’s PCI responsibility start and stop when clients use Shopify, Stripe, Square, or WordPress payment plugins?
- How should an MSP explain payment page script risk without sounding like the fun police?
Make sure to follow the podcast or ask your own questions at: