How Stripe and Braintree can help your startup maintain PCI 3.1 compliance
Disclosure: The author the cofounder of Chargebee, a subscription billing solution that works well with gateways including Stripe and Braintree.

According to the Consumer Payments 2015 report, Asia Pacific accounted for the highest overall card payment volume, surpassing North America in 2012. The same report predicts that Asia Pacific will keep fortifying its lead, and would constitute about 48% of the global payment volume by 2019.
This trend has been further strengthened over the past few years, which saw the entry of leading payment gateways like Stripe and Braintree into the East Asian market.
As an obvious result, more and more APAC SaaS businesses have started accepting card payments from their customers. And if you find yourself in that category, this post is for you.
For firms offering card payments, along with the convenience and ease of carrying out transactions, comes the obligation to safeguard the customers’ confidential card details. Even the slightest compromise in security could cost a business its reputation, apart from the financial loss.
It is therefore indispensable for you as an online enterprise to ensure that you have all the security aspects covered, and to assure your customers that their data is safe with you. And for that, a PCI DSS Compliance is the ideal way to go.
What is PCI DSS?
The PCI DSS (Payment Card Industry Data Security Standard) is a set of rules and regulations that assure the security of card transactions (handling, processing, storing, and transmitting of card details) and the card holders’ personal information. By complying with the PCI Standards, you can offer online transactions while handling your customer’s sensitive information in a safe and secure manner.
Latest updates in the PCI arena
The PCI Security Council introduced version 3.0 of PCI standards in January 2015, rendering version 2.0 obsolete. What this means is that if you went for a PCI assessment on or after the 1st of January, 2015, you would’ve been assessed for PCI version 3.0. If you had gone on or before the 31st of December, 2014, you would’ve been assessed for the now defunct PCI version 2.0 which, in other words, means your PCI compliance is invalid and that you’ll have to renew the certification with 3.0. Recertification with 2.0 is not possible anymore.
Version 3.1 almost immediately followed the 3.0 version, in April 2015. The major change that 3.1 brought about was related to the SSL and earlier editions of TLS cryptographic protocols. With the advent of PCI 3.1, SSL and early TLS encryptions are no longer considered to be secure enough, and hence have to be abandoned by June 30, 2016 (Note: The deadline has now been extended to June 2018).
What should you do to meet the PCI standards?
Depending on the volume of transactions processed, businesses either have to submit a QSA (Qualified Security Assessor) approved compliance report, or complete the prescribed SAQ (Self-Assessment Questionnaire).
There is a general confusion about the need for the type of SAQ certification to be followed (A, B, C or D) and the need for a third party QSA to certify your compliance.
The general rule is this: SAQs are meant for those merchants and service providers who process less than 6 million transactions in a year to ensure compliance with the PCI standards – it isn’t mandatory for them to submit a QSA report.
Also, SAQ-B and SAQ-C are generally not applicable to most SaaS and ecommerce businesses. So I will not cover these two types in this post.
SAQs for SaaS and ecommerce transactions
Stripe and PCI Compliance
Braintree and PCI Compliance
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.







