Payment security, without vague promises

PCI DSS responsibilities.
Made clear.

DX3 provides a PCI DSS v4.0.1-aligned hosting service and the evidence behind it. Your store, payment integration and validation remain a shared-responsibility exercise—and this page shows where the lines sit.

CURRENT STANDARDPCI DSSv4.0.1
AOC available on requestScope and service details supplied for your assessor or acquiring bank.

Current guidance

The 2025 deadline has passed.
The controls now apply.

PCI DSS v4.0.1 is the current standard. The requirements previously described as “future dated” became effective on 31 March 2025 and must now be considered in an assessment where applicable.

6.4.3

Payment-page scripts

Scripts loaded in the consumer’s browser must be authorised, integrity-checked and inventoried when the requirement applies.

11.6.1

Change detection

Payment pages and security-impacting HTTP headers require a mechanism that detects unauthorised changes, at least weekly or at a risk-defined frequency.

12.5.2

Annual scope review

PCI DSS scope must be documented and confirmed at least annually—and again after a significant change.

12.8

Third-party oversight

Using a provider reduces what you operate; it does not remove your duty to document, monitor and understand the provider relationship.

Shared responsibility

Compliance is a chain.
Every link matters.

We secure and operate the parts of the hosting service within our agreed scope. You remain responsible for the ecommerce application, people, payment journey and your own validation.

DX3

Hosting platform

  • In-scope hosting infrastructure and network controls
  • Operating-system and managed service patching
  • Platform access controls, logging and monitoring
  • Hosting-side remediation relevant to our service scope
  • Service-provider evidence, including our AOC on request
SHARED

The boundary

  • Accurate scope and responsibility allocation
  • Secure administrative access and change processes
  • Incident coordination and evidence exchange
  • Vulnerability findings spanning platform and application
  • Keeping third-party responsibilities understood and current
CUSTOMER

Your store and organisation

  • Magento, WooCommerce, extensions and custom code
  • Staff accounts, passwords, MFA and least privilege
  • Your payment provider and correct integration method
  • Payment-page scripts, content and application changes
  • Your SAQ or assessment, policies, scans and annual validation

Your checkout changes the answer

How payment is embedded
defines the scope.

The right SAQ and control set depends on the real payment flow—not the name of a plugin. Confirm the route with your acquirer, payment brand or qualified assessor.

Never store card details on the hosting service.Talk to us before using any integration that could bring account data into your environment.
01

Redirected payment

The customer leaves your site for a validated provider’s hosted payment page. This commonly offers the smallest ecommerce scope, provided every eligibility condition is met.

02

Embedded provider form

Payment elements originate from the provider but appear in your page. SAQ A may still be possible, but the merchant must now confirm its site is not susceptible to script attacks affecting the ecommerce system.

03

Card data touches your site

If your server, application or browser-delivered code stores, processes or transmits account data, the scope is materially broader. Obtain specialist advice before deployment.

Contractual allocation

Matrix of Responsibility

This is the same matrix published in our Terms of Service. It identifies the stated allocation at control level; your actual applicability still depends on your environment and payment flow.

Open the full PCI DSS responsibility matrixDX3 · Client · Shared · Notes
Requirement V4.0 Control Dx3webs Client Shared Notes
1 1.1 Client
1 1.1.1 Client
1 1.1.2 Client
1 1.2
1 1.2.1 Client
1 1.2.2 Client
1 1.2.3 Client
1 1.2.4 Client
1 1.2.5 Client
1 1.2.6 Client
1 1.2.7 Client
1 1.2.8 Client
1 1.3
1 1.3.1 Client
1 1.3.2 Client
1 1.3.3 Client
1 1.4
1 1.4.1 Client
1 1.4.2 Client
1 1.4.3 Client
1 1.4.4 Client
1 1.4.5 Client
1 1.5
1 1.5.1 Client
2 2.1
2 2.1.1 Client
2 2.1.2 Client
2 2.2
2 2.2.1 Client
2 2.2.2 Dx3webs
2 2.2.3 Client
2 2.2.4 Client
2 2.2.5 Client
2 2.2.6 Client
2 2.2.7 Client
2 2.3
2 2.3.1 Client
2 2.3.2 Client
3 3.1
3 3.1.1 Client
3 3.1.2 Client
3 3.2
3 3.2.1 Client
3 3.3
3 3.3.1 Client
3 3.3.1.1 Client
3 3.3.1.2 Client
3 3.3.1.3 Client
3 3.3.2 Client
3 3.3.3 Client
3 3.4
3 3.4.1 Client
3 3.4.2 Client
3 3.5
3 3.5.1 Client
3 3.5.1.1 Client
3 3.5.1.2 Client
3 3.5.1.3 Client
3 3.6
3 3.6.1 Client
3 3.6.1.1 Client
3 3.6.1.2 Client
3 3.6.1.3 Client
3 3.6.1.4 Client
3 3.7
3 3.7.1 Client
3 3.7.2 Client
3 3.7.3 Client
3 3.7.4 Client
3 3.7.5 Client
3 3.7.6 Client
3 3.7.7 Client
3 3.7.8 Client
3 3.7.9 Client
4 4.1
4 4.1.1 Client
4 4.1.2 Client
4 4.2
4 4.2.1 Client
4 4.2.1.1 Client
4 4.2.1.2 Client
4 4.2.2 Client
5 5.1
5 5.1.1 Client
5 5.1.2 Client
5 5.2
5 5.2.1 Client
5 5.2.2 Client
5 5.2.3 Client
5 5.2.3.1 Client
5 5.3
5 5.3.1 Client
5 5.3.2 Client
5 5.3.2.1 Client
5 5.3.3 Client
5 5.3.4 Client
5 5.3.5 Client
5 5.4 Client
5 5.4.1 Dx3webs Client
6 6.1 Client
6 6.1.1 Dx3webs Client
6 6.1.2 Dx3webs Client
6 6.2
6 6.2.1 Client This depends on your own development practice
6 6.2.2 Client This depends on your own development practice
6 6.2.3 Client This depends on your own development practice
6 6.2.3.1 Client This depends on your own development practice
6 6.2.4 Client This depends on your own development practice
6 6.3
6 6.3.1 Shared Dx3webs is responsible for patching the operating system and services. You are responsible for patching any software you install, such as Magento or Node.
6 6.3.2 Shared Dx3webs is responsible for patching the operating system and services. You are responsible for patching any software you install, such as Magento or Node.
6 6.3.3 Shared Dx3webs is responsible for patching the operating system and services. You are responsible for patching any software you install, such as Magento or Node.
6 6.4
6 6.4.1 Client
6 6.4.2 Client
6 6.4.3 Client
6 6.5
6 6.5.1 Client
6 6.5.2 Client
6 6.5.3 Client
6 6.5.4 Client
6 6.5.5 Client
6 6.5.6 Client
7 7.1
7 7.1.1 Client
7 7.1.2 Client
7 7.2 Client
7 7.2.1 Client
7 7.2.2 Client
7 7.2.3 Client
7 7.2.4 Client
7 7.2.5 Client
7 7.2.5.1 Client
7 7.2.6 Client
7 7.3 Client
7 7.3.1 Client
7 7.3.2 Client
7 7.3.3 Client
8 8.1
8 8.1.1 Shared Dx3webs manages access to the hosting platform. Client manage access to your Magento store / other CMS platforms
8 8.1.2 Shared Dx3webs manages access to the hosting platform. Client manage access to your Magento store / other CMS platforms
8 8.2
8 8.2.1 Shared Dx3webs manages access to the hosting platform. Client manage access to your Magento store / other CMS platforms
8 8.2.2 Shared Dx3webs manages access to the hosting platform. Client manage access to your Magento store / other CMS platforms
8 8.2.3 Client
8 8.2.4 Client
8 8.2.5 Shared Dx3webs manages access to the hosting platform. Client manage access to your Magento store / other CMS platforms
8 8.2.6 Shared
8 8.2.7 Client
8 8.2.8 Client
8 8.3
8 8.3.1 Shared Dx3webs manages access to the hosting platform. Client manage access to your Magento store / other CMS platforms
8 8.3.2 Client Shared
8 8.3.3 Shared
8 8.3.4 Client
8 8.3.5 Shared Dx3webs manages access to the hosting platform. Client manage access to your Magento store / other CMS platforms
8 8.3.6 Shared Dx3webs manages access to the hosting platform. Client manage access to your Magento store / other CMS platforms
8 8.3.7 Shared Dx3webs manages access to the hosting platform. Client manage access to your Magento store / other CMS platforms
8 8.3.8 Client
8 8.3.9 Client
8 8.3.10 Client
8 8.3.10.1 Client
8 8.3.11 Client
8 8.4 Client
8 8.4.1 Client
8 8.4.2 Client
8 8.4.3 Client
8 8.5 Client
8 8.5.1 Client
8 8.6 Client
8 8.6.1 Client
8 8.6.2 Client
8 8.6.3 Client
9 9.1 Client
9 9.1.1 Client
9 9.1.2 Client
9 9.2 Client
9 9.2.1 Client
9 9.2.1.1 Client
9 9.2.2 Client
9 9.2.3 Client
9 9.2.4 Client
9 9.3 Client
9 9.3.1 Client
9 9.3.1.1 Client
9 9.3.2 Client
9 9.3.3 Client
9 9.3.4 Client
9 9.4 Client
9 9.4.1 Client
9 9.4.1.1 Client
9 9.4.1.2 Client
9 9.4.2 Client
9 9.4.3 Client
9 9.4.4 Client
9 9.4.5 Client
9 9.4.5.1 Client
9 9.4.6 Client
9 9.4.7 Client
9 9.5 Client
9 9.5.1 Client
9 9.5.1.1 Client
9 9.5.1.2 Client
9 9.5.1.2.1 Client
9 9.5.1.3 Client
10 10.1 Client
10 10.1.1 Client
10 10.1.2 Client
10 10.2 Client
10 10.2.1 Client
10 10.2.1.1 Client
10 10.2.1.2 Client
10 10.2.1.3 Client
10 10.2.1.4 Client
10 10.2.1.5 Client
10 10.2.1.6 Client
10 10.2.1.7 Client
10 10.2.2 Client
10 10.3 Client
10 10.3.1 Client
10 10.3.2 Client
10 10.3.3 Client
10 10.3.4 Client
10 10.4 Client
10 10.4.1 Client
10 10.4.1.1 Client
10 10.4.2 Client
10 10.4.2.1 Client
10 10.4.3 Client
10 10.5 Client
10 10.5.1 Client
10 10.6 Client
10 10.6.1 Client
10 10.6.2 Client
10 10.6.3 Client
10 10.7 Client
10 10.7.1 Client
10 10.7.2 Client
10 10.7.3 Client
11 11.1
11 11.1.1 Client
11 11.1.2 Client
11 11.2
11 11.2.1 Client N/A
11 11.2.2 Client N / A
11 11.3
11 11.3.1 Client Dx3webs will resolve any issues flagged by AVS scans
11 11.3.1.1 Client Dx3webs will resolve any issues flagged by AVS scans
11 11.3.1.2 Client
11 11.3.1.3 Client
11 11.3.2 Client
11 11.3.2.1 Client
11 11.4 Client
11 11.4.1 Client
11 11.4.2 Client
11 11.4.3 Client
11 11.4.4 Client
11 11.4.5 Client
11 11.4.6 Client
11 11.4.7 Client N/A
11 11.5 Client
11 11.5.1 Client
11 11.5.1.1 Client
11 11.5.2 Client
11 11.6 Client
11 11.6.1 Client
12 12.1 Client
12 12.1.1 Client
12 12.1.2 Client
12 12.1.3 Client
12 12.1.4 Client
12 12.2 Client
12 12.2.1 Client
12 12.3 Client
12 12.3.1 Client
12 12.3.2 Client
12 12.3.3 Client
12 12.3.4 Client
12 12.4
12 12.4.1 Dx3webs
12 12.4.2 Dx3webs
12 12.4.2.1 Dx3webs
12 12.5
12 12.5.1 Shared
12 12.5.2 Shared
12 12.5.2.1 Dx3webs
12 12.5.3 Dx3webs
12 12.6
12 12.6.1 Client
12 12.6.2 Client
12 12.6.3 Client
12 12.6.3.1 Client
12 12.6.3.2 Client
12 12.7
12 12.7.1 Client
12 12.8
12 12.8.1 Shared
12 12.8.2 Shared
12 12.8.3 Shared
12 12.8.4 Shared
12 12.8.5 Shared
12 12.9
12 12.9.1 Dx3webs
12 12.9.2 Dx3webs
12 12.10.
12 12.10.1 Shared
12 12.10.2 Shared
12 12.10.3 Shared
12 12.10.4 Shared
12 12.10.4.1 Shared
12 12.10.5 Shared
12 12.10.6 Shared
12 12.10.7 Shared

Need a copy for your assessment? Ask us for the matrix and current AOC.

Evidence, not badges

Give your assessor
something useful.

We can provide our current Attestation of Compliance and responsibility information for the contracted hosting service. Tell us which service you use and who is requesting the evidence.

Request PCI evidence
Important: This page explains DX3’s hosting scope in plain English; it is not a compliance determination or a replacement for the PCI DSS, your contract, your acquirer’s instructions or qualified assessment advice.

Primary guidance: PCI SSC Document Library · January 2025 SAQ A update · Outsourcing and merchant responsibility

Ready to get started?

We are here to help your business grow
Let's talk.

Get in touch