Do we need to be PCI DSS compliant if the payment form is embedded within our website?

  • Rashik
    Asked on May 9, 2018 at 5:29 AM

    Hi,

    We are looking at signing up with JotForm, but before we do, our web developer has raised a question regarding whether we need to be PCI DSS compliant if the payment form is embedded within our website and collecting card details.

    Are you able to provide any information on this?

    If easier, would it be possible to speak with a member of your team to discuss the above?


    Thanks,

    Rashik

  • Victoria_K
    Replied on May 9, 2018 at 8:13 AM

    Hello,

    JotForm is now PCI DSS Service Provider Level I certified, the highest security attainment you can have as a business that collects payments from, and integrates with, credit cards. So, as long as you do collect payments via our forms, you do not need to be PCI DSS compliant.

    You can embed the payment form to your web page using one of available embedding options:

    Which-Form-Embed-Code-Should-I-Use

    Unfortunately, we do not provide phone support at the moment, but we are always glad to assist if you post your questions here

    Thank you.