u/foo-bar-baz529

Do I need a quarterly ASV scan when using Stripe Elements in an iframe?

I run a low-volume e-commerce site that will soon accept payments using Stripe Elements, where all credit card data goes through a Stripe iframe popup on my site and is not visible to my digital infrastructure. This means I need SAQ A compliance. Do I need a quarterly scan? I see conflicting information online. Many sites say I do need the scan, while Stripe customer support says that I don't.

reddit.com
u/foo-bar-baz529 — 9 days ago