Understand PCI Compliance
Last updated on Sep 19, 2026
The acronym “PCI” stands for “Payment Card Industry.” The full name of the organization is “The PCI Security Standards Council,” which is an organization founded by American Express, Discover, JCB International, MasterCard, and Visa. Their website is pcisecuritystandards.org.
For more information on Maxio's Security and Compliance Program, visit the Maxio Trust Center.
Do you need to comply with PCI standards?
Everyone who accepts credit cards must be compliant with PCI data security standards. But the process of validating your company’s compliance varies widely, depending on the type and size of your business.
The PCI-DSS standard
PCI defines a number of security standards. The one that’s relevant for Maxio and our merchants is called “PCI-DSS,” which stands for “PCI Data Security Standard.”
PCI-DSS covers various things about your business, like:
- Handling of data by your computer systems.
- Separation of program execution and data storage.
- Guarding against employee theft of data.
- Guarding against internet-based intrusions.
- Proper disposal of hard drives.
- Tracking of human access to hardware.
- Ensuring that software developers cannot directly change production systems without management oversight.
If you’re a small or medium-sized business that uses Advanced Billing for all functions where credit card data is involved, you only need to do a self-assessment.
PCI Level 1
PCI divides merchants into four Levels, based mainly on annual transaction volume. Advanced Billing itself is a PCI Level 1 merchant; for more information on its security compliance, view our security validations.
A merchant is Level 1 if any of the following is true:
- More than 6,000,000 Visa or MasterCard transactions per year.
- More than 2,500,000 American Express transactions per year.
- Any merchant that Visa or MasterCard determines should meet the Level 1 merchant requirements to minimize risk to the system.
- Any MasterCard merchant who had account data compromised in the previous year.
- Any entity that handles credit card data and/or provides card processing services on behalf of other merchants.
PCI Level 2
A merchant is Level 2 if either of the following is true:
- 1,000,000 to 6,000,000 Visa or MasterCard transactions per year.
- 50,000 to 2,500,000 American Express transactions per year.
PCI Level 3
A merchant is Level 3 if either of the following is true:
- 20,000 to 1,000,000 Visa or MasterCard transactions per year.
- 50,000 American Express transactions per year.
PCI Level 4
A merchant is Level 4 if the following is true:
- Fewer than 20,000 Visa or MasterCard transactions per year.
- Note: American Express does not use level 4.
What does my PCI level mean for me?
Look at the requirements above and see which PCI Level is right for your business.
- If you’re Level 1 or 2, then you need to hire an auditor to verify your compliance with the PCI-DSS Standard.
- If you’re Level 3 or 4, then you can do your own self-assessment of compliance.
If you’re a small/medium business and you rely on Advanced Billing for all of your credit card data-handling operations, Advanced Billing handles the heavy lifting of PCI-related concerns. You, as a merchant, can self-assess your PCI level, if you are level 3 or 4.
Self-assessment for PCI Level 3 and 4 merchants
PCI has developed a set of Self-Assessment Questionnaires (SAQs) that can be used by Level 3 and Level 4 merchants. These questionnaires are referred to as “SAQs”. They help you figure out if you’re compliant with the PCI-DSS standards.
SAQ A
Advanced Billing merchants that use Public Signup Pages or Maxio.js (formerly Chargify.js) qualify for SAQ-A.
Applies if: All cardholder data functions are outsourced to someone like Advanced Billing. You have no electronic storage, no processing, no transmission of cardholder data, no web pages hosted by you that even “kind of” touch credit card data (see below for what “kind of” means).
- This is the proper questionnaire for merchants who use Advanced Billing-hosted pages for all collection and updating of consumer’s card data. You can use our consumer signup pages, card update pages, and consumer self-service Portal.
- The questionnaire asks you to confirm that Advanced Billing is PCI compliant, which you can do by checking our Certificate of Compliance.
- This is not the proper questionnaire if you collect card data on your own SSL-secure web page and then transmit the data to Advanced Billing via our API. Avoid doing this unless you are prepared for annual PCI audits.
- This is not the proper questionnaire if you host the payment form on your own page and rely on a “transparent redirect” or a payment gateway’s JavaScript “drop-in” library, where the form is yours but the card data passes directly from consumers to Advanced Billing or the gateway. These methods are what we call “kind of” touching credit card data. See SAQ A-EP, below.
SAQ A-EP
Applies if: You are a merchant that partially outsources everything credit card-related to a company like Advanced Billing. Regarding the meaning of “partially”, here’s a summary from the SAQ A-EP document itself, “This SAQ has been created to address requirements applicable to e-commerce merchants with a website(s) that does not itself receive cardholder data but which does affect the security of the payment transaction and/or the integrity of the page that accepts the consumer’s cardholder data.”
This is the proper questionnaire for merchants whose own web pages “kind of” touch credit card data: those who use a “transparent redirect,” and those who use a payment gateway’s JavaScript “drop-in” library. In both cases you host the consumer-facing form, but the card data passes directly from consumers to Advanced Billing or the gateway rather than through your servers.
The questionnaire asks you to confirm that Advanced Billing is PCI compliant, which you can do by checking our Certificate of Compliance.
SAQ B
Applies if: Merchant only uses physical card imprint machines or stand-alone dial-out terminals. No electronic cardholder data storage.
- No internet connection with regard to card data, which pretty much eliminates all Advanced Billing merchants.
SAQ C
Applies if: Payment application connected to the internet. No electronic cardholder data storage.
- This is the proper questionnaire if you collect card data on your own SSL-secure web page and then transmit the data to Advanced Billing via our API.
SAQ D
Applies if: All other merchants not covered above, and service providers.
- This questionnaire applies to oddball merchants, and to companies like Advanced Billing, that provide services to others.
Where do you get the SAQ forms?
Download the SAQ forms directly from the PCI site.
More PCI information and links
Each card brand publishes its own Level criteria, which is where to confirm exactly which Level applies to you:
- For details regarding the Visa PCI Level criteria and validation requirements, see Visa's PCI compliance page.
- For details regarding the MasterCard PCI Level criteria and validation requirements, see MasterCard's PCI compliance page.
- For details regarding the American Express PCI Level criteria and validation requirements, see American Express's PCI compliance page.
Related information
PCI is not the only compliance regime that affects how you configure Maxio. For handling personal data of people in the EU and UK, see Understand GDPR Compliance.
To see how Maxio handles personal data of people in the EU and UK, see Understand GDPR Compliance.
For the list of subprocessors Maxio uses and what each one processes, see Understand GDPR Data Processing.
To keep cardholder data off your own servers and stay within SAQ A, see Understand Public Pages.
Still need help?
Reach out and our support team will take it from here.
