PCI Compliance for Fintech Startups: A Practical Roadmap
Most of PCI DSS never has to apply to you. Architect so card data never touches your servers, and a 329-question audit collapses into a 22-question form.
Build so card data never touches your infrastructure and PCI shrinks from a 329-question audit to a 22-question self-assessment you can finish in an afternoon.
PCI DSS has a reputation for being a swamp, and most of that reputation is earned by teams who walked into it without a plan. The trick early on is not to comply with all twelve requirements. It is to architect so that most of them never apply to you. If card data never touches your servers, you fill out a 22-question form instead of a 329-question one. That single decision is worth more than any compliance hire you could make in your first two years.
Your transaction volume sets the level
PCI splits merchants into four levels by annual transaction count. Level 4 is under 20,000 e-commerce transactions or under 1 million total card transactions a year. Level 3 runs 20K to 1M e-commerce. Level 2 is 1M to 6M on any channel. Level 1 is anything above 6M. Almost every startup we work with sits at Level 4, and Level 4 is the comfortable spot: you self-certify with a Self-Assessment Questionnaire plus a quarterly external scan. No QSA, no on-site audit, no five-figure assessment. You inherit the audit burden only once you cross 6M transactions, and by then you can afford it.
The catch is that the level only tells you whether someone audits you. Which SAQ you fill out is decided entirely by your architecture, and the gap between the easy one and the hard one is enormous.
Aim for SAQ A and never look back
There are nine SAQs. SAQ A is 22 questions. SAQ D is 329. They cover the same idea, but one of them will eat a quarter of an engineer's year and the other is an afternoon. You qualify for SAQ A when every piece of card handling is outsourced to a PCI-compliant provider, card data never lands on your servers (not even for a millisecond), you collect cards through a hosted iframe or redirect, and you store nothing, not even encrypted.
In practice this means rendering the card field inside a provider-hosted iframe, like Stripe Elements. The input lives in their frame, not your DOM. The number never enters your JavaScript, never hits an endpoint you own, never shows up in your logs. You get back a token. That token is the only thing your backend ever sees. Build it this way once and you stay in SAQ A territory permanently.
If you must do more, do it in this order
Sometimes SAQ A is off the table, usually because a B2B flow forces card data through your servers. Then you owe more of the twelve requirements, and the mistake is treating all twelve as equally urgent. They are not. We sequence them by blast radius.
Three things ship in week one. First, never store prohibited data: no CVV, no full magnetic stripe, no PIN, ever, encrypted or not. If you are keeping CVV "for convenience," delete it today. There is no legal way to store it. Second, TLS 1.2 or higher on everything, no plain HTTP endpoints, no self-signed certs in production. Third, least-privilege access. Developers do not get standing production database access. Role-based from the first commit.
The next tier lands within three months: unique credentials per person (kill the shared "dev" account), AES-256 with real key management if you are forced to store PANs, and audit logging on who touched what and when. That last one pays for itself the first time you debug a production incident, long before any auditor asks for it.
Everything else scales with you: cloud IAM hygiene in place of physical access controls, quarterly automated scans now and manual pentests after your Series A, a security policy that starts as a README rather than a 100-page binder, dependency patching, restore and incident drills, and one named owner for security even if it is half of someone's job.
Pick the architecture, and the paperwork follows
Your architecture is your compliance burden. There are really three shapes.
And it almost always can be met another way. Recurring billing runs on tokens. Card-on-file runs on tokens. The number of teams that actually need to store a real PAN is close to zero, and most of the ones who think they do are wrong.
Compliance is a habit, not a certificate
Two clocks run continuously. Every 90 days you need an external scan from an Approved Scanning Vendor against your public IPs and domains. Pass means no high or critical findings. Budget $100 to $500 per scan; Qualys, Tenable, Rapid7, and SecurityMetrics all do it. You pass by patching before the scan, not after: keep OpenSSL current, close unused ports, drop SSL and TLS 1.0/1.1 entirely.
Once a year you complete your SAQ. For SAQ A that means confirming you still qualify, answering 22 yes/no questions, having an exec sign the attestation, and handing it to your acquirer if they ask. The part people skip is evidence. Keep a compliance folder from day one: access lists, change logs, training records, incident procedures, vendor assessments, and every quarterly scan report. Automate the collection. Recreating a year of evidence the week before renewal is misery; capturing it as it happens is nearly free.
The failures we see over and over
We have audited dozens of fintech startups, and the same handful of mistakes show up almost every time. The fixes are cheap once you know to look.
What we actually tell teams to buy
On processors, Stripe is the default for most startups on developer experience alone, at 2.9% plus $0.30. Adyen wins on global and enterprise coverage with volume pricing. Checkout.com is competitive in the EU at 2.5% plus $0.25. Braintree makes sense if you want PayPal in the box at 2.9% plus $0.30. Any of them gets you SAQ A eligibility, which is the whole point.
For quarterly scans, SecurityMetrics runs about $500/year and is aimed at smaller shops; Qualys (~$2,500/year), Tenable.io (~$3,000/year), and Intruder (~$100/month) cover the heavier end. Compliance automation platforms like Vanta, Drata, and Secureframe start around $5,000/year.
Our standard early-stage recommendation is short. Take payments through Stripe for SAQ A eligibility. Use SecurityMetrics for the quarterly scan at $500/year. Skip the compliance automation platforms entirely until you raise a Series A, because manual evidence collection is genuinely fine at small scale. Then bring in Vanta or Drata the moment SOC 2 starts blocking enterprise deals. Spend the money where it removes a real constraint, not before.
We help teams design and ship production-grade software in eLearning, fintech, and AI. Let's talk about your project.
Book a call