You need PCI DSS if your business stores, processes, or transmits cardholder data, full stop. If you route payments entirely through a compliant third party like Stripe or Shopify Payments and never touch card numbers directly, you likely only need a short Self-Assessment Questionnaire (SAQ), not the full standard. The confusion isn't about whether PCI DSS applies. It's about how much of it applies to you, and a lot of Canadian SaaS and e-commerce companies are buying far more compliance than their card-data footprint requires.
What PCI DSS Actually Regulates
PCI DSS (Payment Card Industry Data Security Standard) is a contractual requirement from the card brands (Visa, Mastercard, Amex, Discover) enforced through your acquiring bank or payment processor, not a government law. It applies the moment your systems store, process, or transmit primary account numbers (PANs), regardless of company size or country. There's no small-business exemption and no PIPEDA-style threshold. If a card number touches your infrastructure, PCI DSS is in scope.
That said, "in scope" and "full Level 1 assessment" are very different things. The standard has four merchant levels based on annual transaction volume, and most Canadian startups and mid-market SaaS companies land in Level 3 or Level 4, which qualify for self-assessment rather than a formal audit by a Qualified Security Assessor (QSA).
Who Genuinely Needs Full PCI DSS Compliance
Full-scope PCI DSS work is warranted when you:
- Build your own checkout or payment page that captures raw card numbers before sending them anywhere
- Store cardholder data in your own database, even temporarily, for retries or reconciliation
- Operate as a payment facilitator, gateway, or processor for other merchants
- Process over 6 million transactions a year (Level 1, mandatory QSA audit)
- Have had a prior card-data breach (the brands can force you into Level 1 regardless of volume)
Fintech companies, payment platforms, and marketplaces that hold funds or route card data on behalf of third parties fall squarely here. If that's your business model, treat PCI DSS as a real engineering and governance program, not paperwork.
Who Is Over-Buying PCI DSS Compliance
We regularly see Canadian SaaS founders quoted for a full PCI DSS program when their actual card-data exposure is close to zero. The pattern is almost always the same: they use Stripe Checkout, Stripe Billing, or a similar hosted payment page, meaning card numbers never hit their servers. In that setup, the correct scope is usually SAQ A, the shortest self-assessment questionnaire, covering roughly 20 to 25 controls rather than the 300-plus requirements in a full Report on Compliance.
Vendors selling generic compliance platforms often push clients toward broader scope than necessary because it's easier to sell one tier than to correctly scope each customer. This is where an outside opinion earns its cost. Our approach on PCI DSS compliance for SaaS companies starts with a scoping exercise before anything else, because the fastest, cheapest, most defensible path to compliance is architectural: reduce what touches card data, then certify what's left.
Scope Reduction Comes Before Any Assessment
The single biggest lever in PCI DSS is scope reduction, and it's the step most vendors skip because it shrinks the engagement. Before writing a single policy document, we look at:
- Whether card capture can move entirely to a hosted payment page or iframe (Stripe Elements, Braintree Hosted Fields) so raw PANs never enter your environment
- Whether tokenization can replace any internal storage of card numbers for recurring billing
- Network segmentation, so the cardholder data environment (CDE) is isolated from the rest of your infrastructure and doesn't drag your entire AWS account into scope
- Whether third-party logging, analytics, or support tools are inadvertently capturing card data through session replay or form logging
Get scope reduction right and a company that thought it needed a full QSA audit often ends up eligible for SAQ A or SAQ A-EP, a fraction of the effort and cost. This is the same discipline we bring to broader compliance advisory work at traztech: fix the underlying architecture first, then let the paperwork reflect a smaller, truer scope.
PCI DSS Readiness Versus the Required Penetration Test
Once scope is confirmed, readiness work covers the control gaps: firewall configuration, encryption of cardholder data at rest and in transit, access control and least privilege, vulnerability management, logging and monitoring, and vendor management for any third party that touches the CDE. For companies above SAQ A, or anyone with a web-facing CDE, PCI DSS Requirement 11.3 mandates an annual penetration test performed by a qualified tester, plus retesting after significant infrastructure changes. This isn't optional and it isn't the same as a vulnerability scan. Skipping it, or treating an automated scan as a substitute, is one of the most common reasons companies fail their assessment or get flagged by their acquiring bank.
The Canadian Context: PIPEDA, Quebec Law 25, and PCI DSS
PCI DSS is card-brand contractual law, but it doesn't operate in isolation for Canadian companies. Cardholder data is personal information under both PIPEDA and Quebec's Law 25, so a card-data breach triggers separate privacy-law breach notification obligations on top of whatever the card brands require. Companies building toward the emerging Canadian Protocol for Cybersecurity and Cyber Resilience (CPCSC) baseline should treat PCI DSS scoping and privacy-law scoping as one exercise, not two separate binders, since they largely touch the same systems and the same access controls.
We work with SaaS and e-commerce teams across Toronto, Waterloo, Ottawa, Vancouver, Calgary, and Montreal on exactly this overlap, because Canadian fintech and payments companies in particular need PCI DSS, PIPEDA, and often SOC 2 to line up rather than duplicate each other's control work.
How to Tell Which Category You're In
Ask three questions before signing any PCI DSS engagement. Does your platform ever receive a raw card number, even in transit, before it reaches a payment processor? Do you store card data anywhere, including backups or logs? What's your actual annual transaction volume against the card brand thresholds? Honest answers to those three questions usually settle the scope question in under an hour, and they should come before any vendor quotes you a fixed-fee "PCI DSS package" without asking them first.
Get an Honest Scoping Assessment
If you're not sure whether you need SAQ A or a full assessment, that uncertainty is normal and it's worth resolving before you spend money. Traztech is a boutique Canadian security and compliance consultancy led by a published security researcher, and we scope PCI DSS work honestly, including telling clients when they need less than they think. If your company handles payments and you want a straight answer on what PCI DSS actually requires of you, contact traztech for a scoping conversation.