Loading article…
Loading article…
Last updated on Aug 28, 2026
PCI is not the only compliance regime that affects how you configure Maxio: for handling personal data of people in the EU and UK, see Overview of GDPR Compliance.
The acronym “PCI” stands for “Payment Card Industry.” The full name of the organization is “The PCI Security Standards Council,” which is an organization founded by American Express, Discover, JCB International, MasterCard, and Visa. Their website is pcisecuritystandards.org.
For more information on Maxio's Security and Compliance Program, visit the Maxio Trust Center.
Everyone who accepts credit cards must be compliant with PCI data security standards. But the process of validating your company’s compliance varies widely, depending on your type & size of business.
PCI defines a number of security standards. The one that’s relevant for Maxio and our merchants is called “PCI-DSS,” which stands for “PCI Data Security Standard.”
PCI-DSS covers various things about your business, like:
If you’re a small or medium-sized business that uses Advanced Billing for all functions where credit card data is involved, you’ll just need to do a self-assessment.
PCI divides merchants into 4 Levels.
Advanced Billing is a PCI Level 1 merchant. For more information on our security compliance, view our security validations.
Look at the requirements above and see which PCI Level is right for your business.
If you’re a small/medium business and you rely on Advanced Billing for all of your credit card data-handling operations, Advanced Billing handles the heavy lifting of PCI-related concerns. You, as a merchant, can self-assess your PCI level, if you are level 3 or 4.
PCI has developed a set of Self-Assessment Questionnaires (SAQs) that can be used by Level 3 and Level 4 merchants. These questionnaires are referred to as “SAQs”. They help you figure out if you’re compliant with the PCI-DSS standards.
Advanced Billing merchants that use Public Signup Pages or Maxio.js (formerly Chargify.js) will qualify for SAQ-A.
Applies if: All cardholder data functions are outsourced to someone like Advanced Billing. You have no electronic storage, no processing, no transmission of cardholder data, no web pages hosted by you that even “kind of” touch credit card data (see below for what “kind of” means).
Applies if: You are a merchant that partially outsources everything credit card-related to a company like Advanced Billing. Regarding the meaning of “partially”, here’s a summary from the SAQ A-EP document itself, “This SAQ has been created to address requirements applicable to e-commerce merchants with a website(s) that does not itself receive cardholder data but which does affect the security of the payment transaction and/or the integrity of the page that accepts the consumer’s cardholder data.”
This is the proper questionnaire for merchants who touch credit card data with their own web pages… those who use a “transparent redirect” function such as Chargify Direct, or those who use a JavaScript “drop-in” library from some payment gateways, where you host your own consumer-facing forms but all credit card data passes directly from consumers to Advanced Billing servers.
You will be asked to confirm that Advanced Billing is PCI compliant, and you can do this by checking our Certificate of Compliance.
Applies if: Merchant only uses physical card imprint machines or stand-alone dial-out terminals. No electronic cardholder data storage.
Applies if: Payment application connected to the internet. No electronic cardholder data storage.
Applies if: All other merchants not covered above, and service providers.
Download the SAQ forms directly from the PCI site.
Still need help?
Reach out and our support team will take it from here.