Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 631415
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 13, 20262026-05-13T19:57:45+00:00 2026-05-13T19:57:45+00:00

If i have a web application and i receive credit card data transmitted via

  • 0

If i have a web application and i receive credit card data transmitted via a POST request by a web browser over HTTPS and instantly open a socket (SSL) to a remote PCI compilant card processor to forward the data and wait for a response, am i allowed to do that? or is this receiving the data with my application and forwarding it already subject of “processing credit card data”?

if i create an iframe that is displayed in a client browser to enter cc data and this iframe posts the data via HTTPS to remote card processor (directly!) is this already a case of processing credit card data? even if my application code ‘doesnt touch’ the entered data with any event handlers?

i’m interested in the definition “credit card data processing”. when does it start to be a cc data processing application? can somebody maybe point me to that section in PCI-DSS standard that clearly defines when you start to ‘be a processing application’?

Thanks,

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-13T19:57:45+00:00Added an answer on May 13, 2026 at 7:57 pm

    Its a good question, and I’d love to hear some authoritative answers – either from someone directly representing the PCI-DSS or at least a QSA with access to PCI members.

    My unauthoritative answer would be that the webserver that hosts the iframe would be in scope for PCI, and you’d be classed as a service provider. This is based on my interpretation of the PCI standard, where the glossary states:

    Service Provider Business entity that is not a payment card brand
    member or a merchant directly
    involved in the processing, storage,
    transmission, and switching or
    transaction data and cardholder
    information or both (*1). This also
    includes companies that provide
    services to merchants, services
    providers or members that control or
    could impact the security of
    cardholder data (*2). Examples include
    managed service providers that
    provide managed firewalls, IDS and
    other services as well as hosting
    providers and other entities.
    Entities such as telecommunications
    companies that only provide
    communication links without access to
    the application layer of the
    communication link are excluded (*3)

    *1. You’re clearly not a payment card brand (such as Visa), neither are you a merchant (to whom you’re providing this service)
    *2. This is pretty clearly your role, as providing a service
    *3. Unfortunately, I dont think you meet this exclusion, as you have access to application layer data.

    The good news is that the approach you’ve taken is probably the best you can do to minimise your headaches.

    Ideally then you’d segment this server so that access to a wider (internal) network is very restricted. Ensure that the only ‘application’ the webserver provides is this iframe (ie, dont run any other webpages from the server). Ensure that the logging that the server/iframe/etc generate doesnt contain any card related data

    Unfortunately I belive it does mean that a QSA needs to be involved, as you are processing web transactions.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have developed a web application that processes credit card payments and when a
I have web application of which major part is javascript. I request images from
I have a web-based application that notifies users of activity on the site via
I have a Wicket Web Application running in Tomcat. The application uses Spring (via
Currently I have an application that receives an uploaded file from my web application.
I have web application written in java using Eclipse. It has just one servlet
I have web application which we deployed in a production . We have separate
I have web application and I do not really care about IE6 users. However
I have web application Project having RPC call. one RPC async is working fine.
I have a web application with an iframe that needs to communicate with its

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.