---
title: E-Commerce PCI DSS Compliance Choices
description: Learn about the various PCI compliance choices available to E-Commerce websites and solutions.
image: https://blog.enigmavault.io/hubfs/mark-konig-Tl8mDaue_II-unsplash.jpg
---

[![](https://blog.enigmavault.io/hs-fs/hubfs/ev-logo-small-1.png?width=332&height=120&name=ev-logo-small-1.png)](https://blog.enigmavault.io)

Open main menu Close main menu

- [Blog Home](https://blog.enigmavault.io)
- [Enigma Vault Website](https://www.enigmavault.io)
- Docs Open the submenu 
    - [Swagger/OpenAPI docs](https://api.enigmavault.io)
    - [Human friendly API docs](https://docs.enigmavault.io/1.6/redoc-static.html)
    - [Security policy](https://blog.enigmavault.io/hubfs/Enigma+Vault+Security+Policy.pdf)
    - [Privacy policy](https://blog.enigmavault.io/hubfs/Enigma+Vault+Privacy+Policy.pdf)

[PCI](https://blog.enigmavault.io/tag/pci)

# E-Commerce PCI DSS Compliance Choices

![Holly](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) 

[Holly](https://blog.enigmavault.io/author/holly)

[Share this blog post on Twitter](https://twitter.com/intent/tweet?text=I+found+this+interesting+blog+post&url=https://blog.enigmavault.io/e-commerce-pci-dss-compliance-choices) [Share this blog post on Facebook](http://www.facebook.com/share.php?u=https://blog.enigmavault.io/e-commerce-pci-dss-compliance-choices) [Share this blog post on LinkedIn](http://www.linkedin.com/shareArticle?mini=true&url=https://blog.enigmavault.io/e-commerce-pci-dss-compliance-choices)

![](https://blog.enigmavault.io/hubfs/mark-konig-Tl8mDaue_II-unsplash.jpg)

You likely know that e-commerce PCI DSS compliance is a requirement for all businesses that accept or process credit card payments. But what are your options when it comes to meeting this requirement? In this blog post, we'll explore the different compliance choices available to you and discuss the benefits and drawbacks of each. Understanding your options allows you to make the best decision for your business needs. 

## Levels of PCI DSS Compliance

There are four levels of PCI DSS compliance. The level at which your business must comply depends on the number of transactions you process each year.

| Level 1: Businesses that process more than 6 million annual credit card transactions. | Level 2: Businesses that process 1 million to 6 million annual credit card transactions. | Level 3: Businesses that process 20,000 to 1 million annual credit card transactions | Level 4: Businesses that process fewer than 20,000 annual credit card transactions |
| --- | --- | --- | --- |

## E-Commerce Businesses' PCI DSS Requirement

If your business falls into Level 2, 3, or 4, you have a few different PCI DSS compliance options.You can either:

- Self-assess application using the PCI DSS Self-Assessment Questionnaire (SAQ)
- Complete a PCI DSS assessment conducted by a Qualified Security Assessor (QSA) 

There are different requirements for Level 1 companies with greater than 6 million credit card transactions per year (online alone or a combination of online and in-store). In this case, the Company needs to have a Report on Compliance (ROC) from a Qualified Security Assessor (QSA). The use of a third party, such as Enigma Vault, can help to ease the compliance burden.

### SAQ

The SAQ is a list of questions businesses must answer to self-assess their PCI DSS compliance. There are different versions of the SAQ, and which one you need to use depends on the type of credit card transactions you process. 

### QSA

The QSA PCI DSS assessment is a more comprehensive evaluation of your PCI DSS compliance. A QSA will review your policies and procedures and your technical and network environment. They will also interview your staff to understand better how your business processes credit card transactions. 

## What Are the Three SAQ Options Available for E-Commerce Businesses? 

If your company makes less than 6 million card transactions annually, you can apply for PCI DSS compliance with the self-assessment questionnaire (SAQ) approach. However, there are three SAQ options: SAQ A, SAQ A-EP, and SAQ D. So what are the differences among them?

### SAQ A

SAQ A is the simplest PCI DSS compliance option intended for businesses that outsource all e-commerce payment handling to a PCI DSS compliant service provider. It has no processing, transmission, and electronic storage of cardholder data. The application includes 24 questions, and a security scan is not required.

### SAQ A-EP

This PCI DSS compliance option is for businesses that outsource all e-commerce payment handling to a PCI DSS compliant service provider and have an e-commerce environment but do not process, transmit, or electronically store cardholder data. The application includes 191 questions, and a security scan procedure is required. 

### SAQ D

This PCI DSS compliance option is for businesses with an e-commerce environment that process, transmit, or electronically store cardholder data. The application includes 329 questions and a security scan procedure. 

### Final Thoughts

PCI DSS compliance is a requirement for all businesses that accept or process credit card payments. Although the process can seem daunting, simpler compliance options are available to you, depending on the size and scope of your e-commerce business. Now that you have a better understanding of your PCI DSS compliance options, you can easily select the best solution for your business needs. 

## Related Articles

[![](https://blog.enigmavault.io/hubfs/pexels-photomix-company-230544.jpg)](https://blog.enigmavault.io/who-requires-pci-dss-compliance)

[PCI](https://blog.enigmavault.io/tag/pci)

### [Who Requires PCI DSS Compliance?](https://blog.enigmavault.io/who-requires-pci-dss-compliance)

As long as you store, process, or transmit credit card data, you need to understand PCI DSS compliance, and how it impacts your business.  

![Holly](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) 

[Holly](https://blog.enigmavault.io/author/holly) 

[Read More](https://blog.enigmavault.io/who-requires-pci-dss-compliance)

[![](https://blog.enigmavault.io/hubfs/regularguy-eth-q7h8LVeUgFU-unsplash.jpg)](https://blog.enigmavault.io/securing-client-credentials)

[API](https://blog.enigmavault.io/tag/api) [Application Security](https://blog.enigmavault.io/tag/application-security)

### [Securing Client Credentials](https://blog.enigmavault.io/securing-client-credentials)

 Securing client credentials and other sensitive API authentication information that you receive from Enigma Vault or any other service provider is crucial in ensuring...

![Holly](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) 

[Holly](https://blog.enigmavault.io/author/holly) 

[Read More](https://blog.enigmavault.io/securing-client-credentials)

#### Resources

- [API Documentation](https://docs.enigmavault.io/1.6/redoc-static.html)
- [AWS Marketplace](https://aws.amazon.com/marketplace/seller-profile?id=c77b8db1-5511-48b7-8ce5-9a8d4a1a8018)
- [Contact Us](https://www.enigmavault.io/#contact)
- [Enigma Vault Website](https://www.enigmavault.io)

#### Services

- [Card Vault](https://www.enigmavault.io/#services)
- [Data Vault](https://www.enigmavault.io/#services)
- [File Vault](https://www.enigmavault.io/#services)

#### Solutions

- [Travel and Hospitality](https://www.enigmavault.io)
- [Financial Services](https://www.enigmavault.io)
- [Online Retail](https://www.enigmavault.io)
- [Government](https://www.enigmavault.io)
- [Education](https://www.enigmavault.io)
- [Healthcare](https://www.enigmavault.io)
- [Enterprises](https://www.enigmavault.io)

### Sign Up for Blog Updates

Follow us on LinkedIn Follow us on Twitter [Follow us on Facebook](https://www.youtube.com/channel/UC69syKEEezqFzuZqb4CTT-A)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Holly",
    "url" : "https://blog.enigmavault.io/author/holly"
  },
  "dateModified" : "2022-10-12T20:19:38.924Z",
  "datePublished" : "2022-09-20T14:45:40.000Z",
  "headline" : "E-Commerce PCI DSS Compliance Choices",
  "image" : [ "https://blog.enigmavault.io/hubfs/mark-konig-Tl8mDaue_II-unsplash.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.enigmavault.io/e-commerce-pci-dss-compliance-choices",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.enigmavault.io/hubfs/ev-logo-small-1.png"
    },
    "name" : "Enigma Vault"
  }
}
```