Shopify PCI Compliance: What's Covered and What You Own

Flowchart showing PCI compliance splitting into perceived need and legal requirements
A profile picture of Steve Pogson, founder and strategist at First Pier Portland, Maine
Steve Pogson
Published
October 14, 2023
Last Updated
August 16, 2026

The short answer

Shopify holds its own PCI DSS certification as a service provider, and that covers Shopify's platform, its checkout, and Shopify Payments. It does not discharge your obligations as a merchant. Shopify's own Payments contract lists six PCI duties you carry personally, and your acquiring bank — not Shopify, not the PCI Council — decides what you have to validate and how.

So the honest version of "is Shopify PCI compliant?" is: Shopify is. You are mostly covered by that, and the gap is smaller than most security vendors want you to believe — but it is not zero, and it is worth twenty minutes of your time to know where it sits.

What Shopify's certification actually covers

Shopify publishes its service-provider Attestation of Compliance openly, with no NDA and no sales call. The current one is worth knowing in detail, because "Shopify is Level 1 PCI compliant" is a marketing sentence and the AoC is the document that actually proves something.

  • Assessed against PCI DSS v4.0.1, the version in force today.
  • Assessor: Coalfire Systems, a Qualified Security Assessor.
  • Assessment period 23 February to 26 May 2026; report dated 26 June 2026; valid through 26 June 2027.
  • Status: compliant, with nothing listed as out of scope.

The services named in scope are Shopify Payments, Shopify eCommerce Stores, the Shopify Subscriptions Vaulting Service, Shop Pay Wallet, and External Marketplace Integration. If you sell on Shopify and take payment through Shopify, the thing handling the card number is inside that boundary.

One detail that matters if you are answering a security questionnaire: the words "Level 1" do not appear anywhere in the attestation. Service-provider levels are a card-brand construct, not a field on the PCI Council's AoC template. Shopify's "Level 1" language is accurate shorthand, but if a buyer's security team asks for evidence, send the AoC rather than a link to a marketing page.

The AoC also describes how card entry works, in Shopify's own words: hosted fields implemented as "an iFrame served by Shopify for secure payment card information input from customers during the Shopify checkout process." Your theme does not touch the card number. Shopify's iframe does, and Shopify's assessor signed off on it.

Where to get Shopify's compliance documents

These are the documents most merchants are actually looking for when they search for this, and all three are public downloads on Shopify's compliance reports page:

  • PCI DSS Attestation of Compliance (AoC) — the service-provider attestation described above. This is the document to send when a partner, enterprise client, or auditor asks for proof.
  • ASV scan Attestation of Scan Compliance (AoSC) — Shopify runs quarterly external vulnerability scans through an Approved Scanning Vendor and posts each attestation. The most recent was dated 17 June 2026.
  • SOC 3 report — publicly downloadable, currently covering 1 April 2025 to 31 March 2026.

SOC 2 Type 2 and SOC 1 Type 2 reports exist but are not on the public download page; you request those through Shopify.

On ISO 27001: Shopify does not publish an ISO 27001 certification. It is not on Shopify's security page, not on the compliance reports page, and not in the help centre documentation. If a procurement form asks you for Shopify's ISO 27001 certificate, the correct answer is that Shopify attests to PCI DSS, SOC 2 and SOC 3 instead — not that the certificate exists somewhere you haven't looked.

On a shared responsibility matrix: Shopify does not publish one for PCI. Several security vendors describe "Shopify's shared responsibility model" as though it were a document you could download. It isn't. The closest thing to an authoritative split is the Shopify Payments contract, which is the next section.

What you still own

Shopify's marketing says stores on the platform are "automatically PCI compliant by default." Shopify's contract says something more specific. Section A14 of the Shopify Payments Terms of Service reads:

"Where you store, process or transmit Account Data, you agree that at all times you shall be compliant, as applicable, with PCI-DSS."

It then enumerates what that means for you. Paraphrased, with the operative words kept:

  • Implement industry standard access controls and authentication for your business systems and your Shopify Payments account.
  • Never store account data in any system you control.
  • Use only PCI-DSS compliant service providers where card data is stored or transmitted, and verify their compliance annually.
  • Never store CVV2 data, at any time.
  • Maintain an ongoing security program with incident response procedures, and notify Shopify immediately of any security incident involving account data.
  • If you use POS hardware, keep a device inventory and protect the devices against tampering and substitution.

The section closes with a line worth reading twice: "You agree to promptly provide Shopify with documentation evidencing your compliance with PCI-DSS."

Where the marketing page and the contract disagree, the contract is the one you signed. That is the real answer to "does Shopify make me PCI compliant" — Shopify covers the part that handles the card, and holds you to six named duties covering everything else.

Your merchant level, and who decides it

Merchant levels are set by the card brands, not by the PCI Council, and each brand defines its own. They are broadly aligned and not identical.

Visa counts Visa transactions over twelve months: Level 1 above six million across all channels, Level 2 from one to six million, Level 3 from 20,000 to one million ecommerce transactions, Level 4 below 20,000 ecommerce transactions plus all other merchants up to one million. Level 1 requires an annual Report on Compliance by a QSA; Levels 2 and 3 an annual self-assessment questionnaire; Level 4 an annual SAQ that Visa describes as recommended, with the actual requirement "set by acquirer."

Mastercard counts combined Mastercard and Maestro transactions and uses the same numeric thresholds, but its Level 4 is simply "all other merchants," who must comply with PCI DSS but are not required to validate to Mastercard unless mandated.

The practical consequence: your acquirer decides what you file. Visa's own guidance puts the duty on them — "acquirers must ensure that their merchants validate at the appropriate level and obtain the required compliance validation documentation from their merchants." If you have never been asked for an SAQ, that is a real answer about your obligations, not an oversight you need to correct unprompted. If you are about to sign an enterprise customer or a bank is onboarding you, ask them directly which SAQ they expect.

What changed in 2025, and whether it applies to you

Two dates matter. PCI DSS v4.0 was retired on 31 December 2024, leaving v4.0.1 as the only active version. Then on 31 March 2025, the future-dated v4.x requirements became mandatory and a revised SAQ A took effect.

The revision is the part that generated a great deal of alarming content. The PCI Council removed requirements 6.4.3 and 11.6.1 — script inventory, script integrity, and payment-page tamper detection — from SAQ A, and replaced them with a single eligibility criterion:

"The merchant has confirmed that their site is not susceptible to attacks from scripts that could affect the merchant's e-commerce system(s)."

The Council's FAQ 1588 then set out two ways to satisfy it: implement the techniques in 6.4.3 and 11.6.1 yourself or through a third party, or obtain written confirmation from your PCI-compliant processor that its solution already includes those protections.

And — this is the sentence most vendor articles leave out — the criterion only applies to merchants whose own webpages contain an embedded payment form such as an iframe. It expressly does not apply to merchants who redirect customers to a processor's page or who fully outsource payment functions.

Which bucket is a Shopify store in?

Straight answer: nobody has ruled on it cleanly, and anyone telling you otherwise is selling something.

Shopify's checkout is served from Shopify's backend through a Shopify-managed frontend runtime, but since 2017 it has rendered on your domain rather than checkout.shopify.com. Inside it, the card fields are an iframe served by Shopify and covered by Shopify's AoC. So the payment form is embedded in a page on your domain, but neither the page nor the form is yours.

No PCI Council document and no Shopify document addresses that specific arrangement. Read one way, your theme pages contain no payment form and the criterion never engages. Read the other, the checkout page is on your domain and it does. We have not found a Shopify-issued written confirmation of the kind FAQ 1588 contemplates, either.

If your acquirer asks, put the question to them in writing and keep the answer. It costs nothing and it settles the point for your file.

What actually affects your PCI risk on Shopify

Setting aside the standards argument, these are the things that genuinely change your exposure, ordered by how often we see them.

Card data stored somewhere it shouldn't be

This is the clearest and most common problem, and it breaches your contract directly. Card numbers pasted into order notes to process a phone order. A CVV written into a customer service ticket. A spreadsheet of card details for recurring manual charges. A CRM field. Shopify Payments' terms prohibit storing account data in any system you control and prohibit storing CVV2 at any time, without exception. If this is happening anywhere in your business, fix it before anything else on this page.

Apps and service providers that touch card data

Your contract requires you to use only PCI-compliant service providers where card data is stored or transmitted, and to verify their compliance annually. Most Shopify apps never touch card data and are irrelevant here. The ones that might — subscription billing, manual payment capture, custom gateways, some ERP and accounting connectors — are worth a short annual list with each vendor's compliance status against it.

Custom pixels and marketing tags

Shopify runs custom pixels in a sandbox, which it describes as "a Lax sandbox, designed for improved security and control over the data that you send to third parties." The strict sandbox blocks DOM scraping and DOM writes and disallows window.document entirely. Shopify doesn't frame this as a PCI control and neither will we, but it does mean a marketing tag installed the supported way cannot read your checkout. Tags installed by pasting raw script into a theme file are a different matter — which is a good reason to use the pixel system rather than route around it.

Checkout customisation

Checkout UI extensions and web pixels run in isolated JavaScript environments and communicate with the checkout page through a mediated bridge, so app code cannot read the payment fields directly. Standard checkout customisation is available from the Basic plan up; the advanced customisation features, including the Checkout Branding API and apps that modify the information, shipping and payment steps, are Shopify Plus only. Either way the sandboxing is Shopify's, not yours.

Theme and storefront scripts

Worth being precise here, because this is where vendor marketing overreaches most. Scripts in your theme run on product, cart and landing pages — not on Shopify's checkout, and checkout.liquid is being retired. A compromised storefront script is a real security and privacy problem and can absolutely be used to harvest data your customers type into your own forms. Whether it puts you in PCI scope for 6.4.3 and 11.6.1 is a determination only your acquirer or a QSA can make, and no primary source makes it for a standard Shopify store. Treat storefront script hygiene as security work, which it is, rather than as a compliance emergency.

Shopify Payments versus a third-party gateway

Which gateway you use changes where the card number is entered, which is the thing PCI actually cares about.

  • Shopify Payments — card fields render in Shopify's iframe inside Shopify's checkout, covered by Shopify's AoC.
  • An offsite gateway — the buyer is redirected to a page the provider hosts. The card number never reaches anything of yours, and this is the model the PCI Council's FAQ explicitly places outside the script criterion.
  • An on-site third-party gateway — the provider's card fields render inside Shopify's checkout. You are relying on two attestations rather than one, so keep the gateway's AoC alongside Shopify's.

Whether any of this changes the SAQ you file is set by your acquirer, not by Shopify and not by the gateway. Ask once, write it down. If you're still choosing, our guide to setting up payments on Shopify covers the practical trade-offs, and Shop Pay fees covers what the wallet actually costs.

A short checklist

  1. Download Shopify's current AoC and keep it with your compliance records. Diary the 26 June 2027 expiry.
  2. Ask your acquirer, in writing, which SAQ they expect from you and at what level. File the reply.
  3. Audit for stored card data — order notes, support tickets, spreadsheets, CRM fields, shared inboxes. Remove anything you find and change the process that created it.
  4. List the apps and providers that touch payment data, and check each one's compliance status. Repeat annually; your contract requires it.
  5. Move marketing tags into Shopify's pixel system rather than pasting scripts into theme files.
  6. Enforce two-factor authentication and least-privilege staff permissions on your Shopify admin. This is the access-control obligation in your contract, and it is also the control most likely to matter in practice.
  7. If you take phone orders, use draft orders and invoice links rather than typing card numbers into the admin.

Common questions

Is Shopify PCI compliant?

Yes. Shopify holds a current service-provider Attestation of Compliance against PCI DSS v4.0.1, assessed by Coalfire Systems and valid through 26 June 2027, covering Shopify Payments, Shopify ecommerce stores, the Subscriptions Vaulting Service, Shop Pay Wallet and External Marketplace Integration.

Does that make my store PCI compliant?

It covers the payment infrastructure. It does not cover your side of the Shopify Payments contract, which requires access controls, no stored card data, no stored CVV, annual verification of your service providers, an incident response process, and POS device inventory if you sell in person.

Where do I get Shopify's PCI certificate or AoC?

Download it directly from Shopify's compliance reports page. No request or NDA is required. The quarterly ASV scan attestation and the SOC 3 report are on the same page.

Do I need to complete an SAQ?

That is your acquirer's call, based on the level the card brands assign you by transaction volume. Most Shopify merchants are Level 4, where Visa describes an annual SAQ as recommended and defers the requirement to the acquirer, and Mastercard does not require validation unless mandated. Ask yours.

Is Shopify ISO 27001 certified?

Shopify does not publish an ISO 27001 certification on any of its compliance pages. It publishes PCI DSS attestations, quarterly ASV scan attestations, and SOC 3 publicly, with SOC 2 Type 2 available on request.

Do requirements 6.4.3 and 11.6.1 apply to me?

They were removed from SAQ A in the March 2025 revision and replaced with a script-security eligibility criterion, which the PCI Council says does not apply to merchants who redirect or fully outsource payment functions. Whether a Shopify store counts as outsourced is not settled by any published document. Confirm with your acquirer.

What version of PCI DSS is current?

v4.0.1. Version 4.0 was retired on 31 December 2024, and the future-dated v4.x requirements became mandatory on 31 March 2025. No v5.0 has been announced.

Where First Pier fits

Most of what is on this page you can do yourself in an afternoon, and you should. Where we get called in is the part that isn't a checklist: a security questionnaire from an enterprise buyer that asks for documents you didn't know existed, an app stack nobody has audited since the store was built, or a phone-order process that has quietly been storing card numbers in order notes for three years.

We build and run Shopify and Shopify Plus stores from Portland, Maine, and were the first digital agency in Maine accepted into Shopify's Experts programme, which Shopify retired in October 2023 and replaced with the Partner Directory. If you want a second pair of eyes on your setup before an audit or a big customer asks, get in touch and we will tell you honestly whether you have a problem.

Get More Ecommerce Insights:

Free: 3 quick wins for your store

Let's Do This!

Drop your Shopify store URL and we'll send back 3 quick wins — free, no pitch, and usually within 2 business days.

Prefer to talk? Book a call

Get your 3 quick wins

Got it. We’ll review your store and email your 3 quick wins within two business days — nothing else needed from you.

Oops! Something went wrong while submitting the form.

No sales call required. Usually back within 2 business days. Unsubscribe anytime.