Do we need to be PCI DSS compliant if the payment form is embedded within our website?

  • tparo2413
    Asked on May 18, 2018 at 3:13 PM

    I understand that jotform servers are PCI DSS Level One-compliant. My question is, what does embedding a jotform Donation Form (using Stripe) into my web site do to that compliancy? The website has its own verified 3rd part SSL certificate (Comodo), and is driven by the Concrete5 cms.

    Am I better off linking people to the direct jotform page? Or can I safely embed the form on the website and maintain compliancy? And, if so, which is better, the javascript snippet, or the iFrame embed?

    Thanks for your insight.

    Tim

  • Victoria_K
    Replied on May 18, 2018 at 3:56 PM

    Hello,

    JotForm is now PCI DSS Service Provider Level I certified, the highest security attainment you can have as a business that collects payments from, and integrates with, credit cards. So, as long as you do collect payments via our forms (using available payment processors), you do not need to be PCI DSS compliant.

    You can embed the payment form to your web page using one of available embedding options:

    Which-Form-Embed-Code-Should-I-Use

    And, if so, which is better, the javascript snippet, or the iFrame embed?

    Your form will be shown through IFRAME if you choose any of this embedding codes. So, you should try to see if the script embedding code does not have any conflicts with your page content (check if the form works). 

    If you face any difficulties while developing or embedding your form, just let us know.

    Thank you.