Solutions Who We Serve Insights & Events About Contact
Published on August 31, 2026 7 min read

PCI Compliance: Optimize Your Payment Stack for Growth

PCI Compliance: Optimize Your Payment Stack for Growth

Summary: Your card acceptance architecture is a growth decision. The way card data moves through your systems shapes how quickly you can add processors, enter new markets, lift authorization rates, and carry clean data through a deal. Six collection methods each offer a different balance of compliance scope, flexibility, and data ownership. Map your card data early and you can choose the one that fits where your company is headed. 

Architectural decisions about payment flows carry long-term consequences that reach well beyond an initial assessment, and that is good news for teams who plan ahead. How card data moves through your systems shapes your ability to add processors, enter new markets, improve authorization rates, and carry clean data through a merger.  

For enterprise decision makers, portfolio company operators, and founders scaling high-growth platforms, the upside is the same whether you accept payments as a merchant or support card flows as a service provider. 

Start with a clear map of your card data

Teams sometimes assume the Payment Card Industry Data Security Standard (PCI DSS) applies only if they store card numbers in their own databases. In reality, understanding the full flow of payment data helps organizations make more informed compliance and architectural decisions.  

Under PCI DSS, your organization is in scope if you store, process, or transmit cardholder data. Connected systems, and systems that could influence that environment, come into scope as well. If infrastructure touches a Primary Account Number (PAN) for even a few milliseconds, it belongs in the conversation, as do manual channels such as a representative taking a card number by phone.  

All of this becomes manageable once you can see it. The most useful first step is a data flow diagram: where card data enters, the path it travels, every third-party service it touches, and where it rests. With that picture, you shape your compliance footprint on purpose rather than discovering it mid-assessment. At Aprio, we regularly work with clients to build out these diagrams, and they often surface quick wins. 

Know how you will attest

Your assessment level and reporting path depend on whether your acquiring bank or card network classifies you as a merchant or a service provider. Because the acquirer enforces the rules, confirming their read of your model early is time well spent.  

Merchants accept card payments for their own goods and services, across four levels set largely by annual transaction volume. A business using an outsourced payment iframe often qualifies for Self-Assessment Questionnaire A (SAQ-A), roughly 30 base level controls under PCI DSS v4. Past six million transactions a year on a single network, a Qualified Security Assessor (QSA) completes a Report on Compliance (ROC). Even then, descoping technologies like iframes let a QSA mark many controls out of scope, so early architecture work keeps paying off.  

Service providers handle cardholder data on behalf of others: payment gateways, orchestrators, fraud platforms, and a growing number of SaaS platforms and marketplaces. Thresholds are tighter: at 300,000 annual transactions on a single network, a service provider moves into the most rigorous level of review, and SAQ-D for Service Providers spans roughly 250 to 350 controls.  

Some companies are both: acting as a service provider for the core product and as a merchant when billing their own subscribers. Segmenting those environments into two scopes keeps each assessment proportionate. 

Six ways to collect card data

Six primary architectures dominate the landscape, each offering a different balance of compliance scope, business flexibility, and data ownership.  

  1. iframe: The merchant embeds a secure form from the payment service provider (PSP) into its own checkout page. Card data routes straight to the PSP, which returns a token. Fast to implement, low scope, and generally SAQ-A eligible. The tradeoff is that tokens work only inside that provider’s ecosystem, so routing flexibility stays with the PSP. A strong fit when speed to launch matters most.  
  1. Hosted redirect: The customer moves to a page hosted by the processor to finish paying. From a scope perspective, this is the leanest option, leaving a short list of obligations that starts with confirming the redirect points where it should. It does hand off part of the checkout experience, which matters more for conversion-sensitive brands.  
  1. Vault tokenization: An independent third-party vault holds card data and issues tokens that aren’t tied to one processor. That independence gives you room to route to any acquirer, gateway, or fraud tool, supporting a multiprocessor strategy and broader geographic coverage. You rely on an outside data steward and add a step to each authorization, so vendor terms and latency are worth a look.  
  1. Network tokens: Issued by the card brands and interoperable across processors. A network token is not treated as cardholder data, so holding one does not pull a system into scope. Lifecycle management is the standout benefit: when a card expires or is reissued, the token updates in the background, which helps subscription businesses hold onto revenue. Acquirer support still varies, and these tokens typically work alongside another capture method.  
  1. Vaultless tokenization or client-side encryption: Card data is encrypted in the customer’s browser using a public key, then stored in your own systems. Because you do not hold the private key, the encrypted string sits outside scope much as a token would. Decryption happens in the provider’s secure enclave at processing time, and a key escrow arrangement with an independent third party gives you a defined path if you change providers. Teams take on a learning curve around key management and gain ownership and lower latency.  
  1. In-house build: You manage your own cardholder data environment, cryptographic keys, and direct integrations with acquirers and networks. Control is total and you are vendor agnostic. The commitment is real: you become a Level 1 service provider with an ROC starting around 350 controls, plus ongoing penetration testing, monitoring, and dedicated compliance staffing. This fits when payment processing is core to how you monetize, as with a processor, a Payment Facilitator (PayFac), or a marketplace at scale. 

Data ownership as a growth asset

For early-stage companies and straightforward retail operations, routing everything through a single provider’s iframe can be a sound choice. Speed to market matters, and reduced compliance friction is real value.  

As volume grows, often around the $100 million mark in annual payment volume, the calculus shifts in an encouraging direction. Small improvements in payment performance start producing meaningful bottom line results, and routing across multiple providers by geography, cost, or authorization success becomes a genuine lever. For marketplaces, where payment volume can run an order of magnitude above net revenue, a few points land almost entirely on the bottom line.  

That agility comes from architecture, so teams who plan early, or commit to a focused modernization effort, keep their options open. For private equity operators and portfolio company CFOs, whether a target controls its own card data is a useful diligence signal about post-deal scalability. 

Final thoughts

Aprio is the 20th largest CPA firm in the U.S., and our Qualified Security Assessors work alongside technology and payments companies every day. We help clients map the cardholder data environment, rightsize PCI scope, confirm classification with the acquirer, and select an architecture that fits the next phase of growth. Because we also deliver SOC 2, ISO 27001, and penetration testing, one coordinated effort can cover several requirements.  

Wherever you are in the journey, the goal is the same: card acceptance that helps your business move faster, with data you control. That looks different at every stage. Early on, it means launching quickly without building a compliance footprint you will have to unwind later. As volume grows, it means routing by geography, cost, or authorization success because your tokens travel with you. At scale, it means walking into a diligence conversation with clean answers about where card data lives and who holds the keys. The teams who get there rarely did anything dramatic. They looked at the map early, weighed the six options side by side, and chose the one built for where they were headed. 

To go deeper on assessing card collection methods by scope, control, flexibility, and data ownership, download the free eBook from Aprio and Evervault. 

How we can help

Aprio’s Technology team works with software and payments companies on what comes next, from audit readiness to tax strategy to preparing for a raise or an exit. Connect With Us

PCI Compliance: Optimize Your Payment Stack for Growth