PCI DSS Compliance Checklist
Scope and SAQ Determination
Diagram every place card data is captured, processed, transmitted, or stored — checkout page, subscription billing (Recharge, Bold), buy-now-pay-later handoffs, customer service phone orders, refund flows. Note which flows touch your servers vs. iframe to Stripe / Shopify Payments / PayPal.
Shopify Payments / Stripe Checkout / PayPal Standard with full redirect typically qualify for SAQ A. Direct API integrations or self-hosted forms push you to SAQ A-EP or SAQ D — dramatically more controls. Confirm with your acquiring bank before assuming scope.
Level 1 merchants (>6M Visa/MC transactions/year) require ROC by a QSA, not self-assessment. SAQ D scope also benefits from a QSA review even when self-attestation is permitted. Skip if SAQ A applies.
Pull the latest annual transaction count from Shopify Payments, Stripe, and any other processors. Confirm with the acquiring bank which AOC and SAQ they require and the submission deadline.
Network and System Hardening
For SAQ A-EP / D environments, document inbound and outbound rules, deny-by-default posture, and Cloudflare / AWS WAF managed rule coverage. SAQ A merchants on Shopify largely inherit this from Shopify's PCI Level 1 attestation — record the inheritance.
Cover Shopify admin, Klaviyo, Gorgias, Recharge, NetSuite, 3PL portals, and any database / server access. Replace any vendor-default credential and confirm MFA is enforced. Service accounts and API keys count too.
Search support ticket archives (Gorgias, Zendesk), shared drives, and email for PAN. Customer service reps pasting full card numbers into tickets is the most common SAQ A finding. Redact and retrain if found; never store CVV under any circumstance.
Run SSL Labs against the storefront, the checkout subdomain, and any custom payment endpoints. PCI DSS v4.0 requires strong cryptography on all transmissions; TLS 1.0 and 1.1 are explicitly disallowed.
Update theme code, custom Shopify apps, WooCommerce / WordPress core and plugins, and any self-hosted services. Critical patches must be applied within 30 days under v4.0; document the patch cycle and exceptions.
Access Control and Authentication
Pull active users from Shopify, Klaviyo, Gorgias, NetSuite, ShipStation, and any tool with payment or customer-data access. Remove ex-employees, ex-agency users, and dormant accounts. Document the business need for each remaining user.
PCI DSS v4.0 requires MFA on all access into the CDE and on all admin access — not just remote. Verify Shopify staff accounts, processor dashboards, and any VPN / bastion are MFA-enforced; SMS-only is no longer considered strong.
No shared logins — agency, contractor, or VA. Each person needs an individual account so audit trails attribute actions correctly. Common gotcha: a shared 'support@' login on Gorgias used by three reps.
Applies if you have retail POS, warehouse workstations, or office machines used for order entry. Lock server rooms, badge offices, log visitor access, and inventory POS terminals quarterly to detect skimmer tampering.
Monitoring and Testing
Log admin actions, login attempts, and data access on Shopify, processor, and any in-scope server. Retain at least 12 months (3 months immediately accessible). For SAQ A this is largely the platform's responsibility — capture the inheritance evidence.
Required quarterly for SAQ A-EP and SAQ D. Use a PCI SSC-listed Approved Scanning Vendor (Trustwave, SecurityMetrics, ControlScan). All findings ranked High or Medium must be remediated and the scan re-run until passing.
Required annually for SAQ D and after significant changes. Internal and external testing of the CDE perimeter and segmentation. Skip for pure SAQ A merchants — but document the scope decision.
Daily review per v4.0 — automated SIEM (Datadog, Splunk) acceptable for the daily cadence. Look for off-hours admin logins, geo-impossible sessions, repeated failed auths, and bulk customer record exports. Document the reviewer and findings.
PCI DSS v4.0 requirements 6.4.3 and 11.6.1 (effective March 31, 2025) require an inventory of all checkout-page scripts and tamper-detection. Magecart-style skimmers via compromised third-party tags are the primary e-commerce CDE breach vector. Tools like Source Defense, Jscrambler, or HUMAN PerimeterX address this.
Policy, Training, and Attestation
Refresh annually or after significant change. Cover acceptable use, password rules, incident response, vendor management, and customer-data handling. Reference the actual tools in use — Shopify, Klaviyo, Gorgias — not generic placeholders.
v4.0 introduces targeted risk analyses (TRA) per requirement to justify customized frequency. Cover threats to cardholder data — e-skimming, account takeover, third-party app compromise, insider misuse — and document mitigations.
Annual training plus onboarding for new hires and contractors. Cover phishing recognition, the no-PAN-in-tickets rule for CX agents, and how to escalate suspected card fraud. KnowBe4 or in-house deck both work; track completion.
List every TPSP that touches cardholder data — processor, gateway, subscription billing, fraud tool, 3PL with payment-on-delivery. Collect their AOCs annually and document the responsibility matrix per v4.0 requirement 12.8.
Final attestation by an executive officer. Submit via the acquirer's portal (Chase, Stripe, Adyen each have their own intake). Keep a signed copy in the compliance folder for the next year's audit trail.
Use this template in Manifestly
- Customer Service Ticket Triage Checklist
- Returns Processing Checklist
- Return Authorization Checklist
- Payment Processing Checklist
- Weekly Review Checklist for E-commerce Founders
- Order Fulfillment Checklist
- E-commerce Sales Tax Reporting Checklist
- Shipping and Delivery Checklist
- Content Marketing Checklist
- Returns and Refunds Checklist
- Inventory Management Checklist
- Customer Feedback Review Cycle
- Product Listing Update Checklist
- Payment Reconciliation Checklist
- GDPR Compliance Checklist for E-commerce
- Security and Privacy Review Checklist
- Sales Reporting Checklist
- Data Privacy Checklist
- E-commerce IT Security Checklist
- PPC Campaign Checklist
- E-commerce Website Maintenance Checklist
- Vendor Onboarding Checklist
- Product Discontinuation Checklist
- Monthly Lead Generation Checklist
- Website Launch Checklist
- Social Media Marketing Checklist
- E-commerce Risk Management Checklist
- Website Analytics Checklist
- Delivery Tracking Checklist
- E-commerce SEO Monthly Audit
- E-commerce Backup and Recovery Checklist
- Monthly E-commerce Marketing Checklist
- E-commerce Annual Budget Planning Checklist
- Order Packaging Checklist
- Employee Onboarding Checklist
- E-commerce Sales Funnel Audit
- Ecommerce Customer Onboarding Checklist
- Website Usability Audit Checklist
- Inventory Replenishment Checklist
- E-commerce Legal Compliance Checklist
- Employee Performance Review Checklist
- Warehouse Operations Checklist
- E-commerce Site Quality Assurance Checklist
- E-commerce Financial Audit Checklist
- E-commerce Fraud Prevention Checklist
- Shipping Carrier Selection Checklist
- Email Marketing Campaign Checklist
- Website Security Checklist
- Payment Gateway Integration Checklist
- Website Maintenance Checklist
- E-commerce Platform Update Checklist
- Affiliate Marketing Program Checklist
- Employee Exit Checklist
- Customer Behavior Analysis Checklist
- CRM Audit Checklist
- Product Launch Checklist
- Order Processing Checklist
- Daily Operations Checklist
- Live Chat Operations Checklist
- E-commerce Expense Management Checklist
- International Shipping Checklist
- Stock Level Monitoring Checklist
- CRM Setup Checklist
- Risk Management Checklist
- Regulatory Compliance Checklist
- Quarterly Internal Control Review Checklist
- Sales Tax Reporting Checklist
- Legal Entity Management Checklist
- Employee File Audit Checklist
- Anti-Money Laundering Compliance Checklist
- SOX Compliance Checklist
- GDPR Compliance Review Checklist
- IT Security Audit Checklist
- HR Compliance Checklist
- Payroll Processing Checklist
- Building Code Compliance Checklist
- Employee Records Management Checklist
- Legal Document Storage Checklist
- Security Audit Checklist
- Property Risk Assessment Checklist
- Property Safety Inspection Checklist
- Cybersecurity Protocol Checklist
- Fair Housing Compliance Checklist
- Legal Compliance Checklist for New Properties
- Lease Agreement Checklist
- Software Licensing Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Legal Compliance Checklist
- HIPAA Compliance Checklist
- MLS Listing Review Checklist
- Real Estate License Renewal Checklist
- GDPR Compliance Checklist
- Real Estate Contract Review Checklist
- Fair Housing Compliance Audit
- Listing Agreement Intake Checklist
- ISO/IEC 27001 Compliance Checklist
- HR Compliance Checklist
- Real Estate Ethics & Compliance Review
- Brokerage Trust Account Management Checklist
- Real Estate Professional Development Checklist
- Brokerage Technology Inventory Audit
- Real Estate Website Audit Checklist
- Continuing Education Checklist
- Employee Termination Checklist
- Employee Records File Audit
- Regulatory Compliance Checklist
- Brokerage HR Policy Compliance Checklist
- Employee Handbook Annual Review
- Employee Termination Checklist
- Data Privacy Compliance Checklist
- Risk Management Checklist
- Insurance Compliance Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Claims Auditing Checklist
- Quarterly Industry Standards Compliance Review
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Manufacturing Regulatory Compliance Checklist
- Training Needs Assessment Checklist
- Skills Development Checklist
- Audit Preparation Checklist
- Network Security Checklist
- Employee Offboarding Checklist
- IT Asset Inventory Management Checklist
- Regulatory Reporting Checklist
- Compliance Audit Checklist
- Insurance Program Initiation Checklist
- Insurance Program Launch Project Monitoring Checklist
- Training Materials Checklist
- Quarterly Risk Monitoring Checklist
- System Backup Checklist
- Employee Benefits Checklist
- Insurance Program Launch Execution Checklist
- Insurance Marketing Campaign Checklist
- Email Compliance Checklist
- Law Firm Compliance Checklist
- Anti-Money Laundering Compliance Checklist
- Law Firm Compliance Checklist
- Professional Responsibility Compliance Review
- Data Privacy Compliance Checklist
- Law Firm Risk Management Checklist
- HR Audit Checklist
- HR Compliance Checklist
- Email Deliverability Checklist
- Law Firm Ethics Compliance Review
- Document Retention Policy Checklist
- Employee File Audit Checklist
- Law Firm Risk Management Checklist
- Cloud Security Checklist
- User Access Review Checklist
- IT Regulatory Compliance Review
- Compliance Audit Checklist
- Security Audit Checklist
- Business Continuity Checklist
- Employee Termination Checklist
- Quarterly Operations and Compliance QA Review
- Expense Management Checklist
- Advisor and Employee Onboarding Checklist
- Client Satisfaction Survey Checklist
- Operational Risk Checklist
- Know Your Customer (KYC) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Intellectual Property Management Checklist
- Internal Audit Checklist
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Annual Risk Assessment Checklist
- Data Security Review Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- IT Policy Review Checklist
- Data Protection Checklist
- E-commerce Sales Tax Reporting Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Quarterly Compliance Monitoring Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- Advisor and Staff Onboarding Checklist
- Cybersecurity Incident Response Checklist
- E-commerce Risk Management Checklist
- CRM Data Entry Checklist
- Business Continuity Plan Checklist
- E-commerce Legal Compliance Checklist
- Vendor Contract Review Checklist
- Annual Risk Management Review Checklist
- Risk Assessment Checklist
- Agency Compliance and Risk Management Checklist
- Annual School Compliance Audit
- School First Aid and Emergency Medication Audit
- Motor Carrier TSA Security Compliance Checklist
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Permit and Licensing Renewal Checklist
- New Hire Paperwork Checklist
- Restaurant Policy Update Checklist
- Restaurant New Hire Checklist
- Annual Attorney Professional Conduct Review
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Restaurant Licensing Renewal Checklist
- Marketing Strategy Checklist
- Department of Transportation (DOT) Audit Checklist
- Retail Policy Update and Compliance Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
