▲ 5 r/pcicompliance
Do I need a quarterly ASV scan when using Stripe Elements in an iframe?
I run a low-volume e-commerce site that will soon accept payments using Stripe Elements, where all credit card data goes through a Stripe iframe popup on my site and is not visible to my digital infrastructure. This means I need SAQ A compliance. Do I need a quarterly scan? I see conflicting information online. Many sites say I do need the scan, while Stripe customer support says that I don't.
u/foo-bar-baz529 — 9 days ago