As a PCI DSS Compliant Service Provider, B2C Commerce is responsible for ensuring that the base service provided to customers is PCI DSS compliant and allows customers to customize in a compliant way. Leveraging the B2C Commerce platform doesn't mean that a customer is inherently PCI Compliant. This document is intended to help address where we can assist our customers with their audits, what our responsibilities are, and what our customers’ responsibilities are.
PCI DSS Standard
The PCI DSS Standard was adopted by all the major card issuers to address data security issues. It is broken up into several sections that broadly address:
You can find a listing of B2C Commerce as a registered service provider at the following locations:
As proof of compliance B2C Commerce will provide a copy of our current PCI Attestation of Compliance (AOC). Please contact Commerce Support if you need a copy of our AOC.
B2C Commerce Responsibility
All Merchants have full responsibility for ensuring their own PCI DSS Merchant compliance. In regards to the B2C Commerce platform, the following lists the major items in-scope for B2C Commerce as a PCI DSS compliant Service Provider. These items cover customer data that is stored within our service. Where the customers' compliance comes in is primarily around integrations and any exchange of sensitive data with systems outside of the B2C Commerce Platform service (like an external OMS system). Specifically it addresses the 12 major PCI DSS requirements sections:
Customer Responsibility
As mentioned before, for any external integration or customization built on top of the B2C Commerce platform the customer is responsible for ensuring PCI-DSS compliance. Common examples include:
NOTE: This list is not comprehensive – you should consult with your PCI DSS assessor or consultant to determine all requirements and responsibilities you have to maintain your PCI DSS Merchant compliance.
How does B2C Commerce help with my audit?
Most auditors are very familiar with working with external PCI compliant partners. You can download any relevant documentation from the links above; this includes our listing as a service provider with the credit card companies. You may also log a ticket with Support to request a copy of the B2C Commerce AOC This should be sufficient for your auditor to use to start identifying where our responsibility as a service provider ends and where your responsibility begins. B2C Commerce does not assist in completing any portion of a customer PCI audit, this includes Self-Assessment Questionnaires (SAQ).
Scheduling Audits/Security Scans
Please see the information outlined in Security Assessments.
Who do I contact if I have questions?
If you are unable to find the answer to your question in this document, please post a question in the Trailblazer Community or reach out to Commerce Support.
000391196

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.