Skip to main content

Stripe PCI Validation

Understand PCI requirements for Stripe and how Donorfy’s payment tools help you stay compliant.

Cristina Gruita avatar
Written by Cristina Gruita
Updated over a month ago

From time to time, Stripe will request that you validate your PCI compliance. Although this may sound complex, the good news is that if you are using the newer Donorfy Web Widgets or standard Campaign Pages, the validation process is straightforward.


Why PCI Validation Is Needed

PCI DSS (Payment Card Industry Data Security Standard) requires organisations that handle card details to confirm they meet security standards.
The level of responsibility depends on how card details are processed.

Donorfy’s modern payment tools are designed so that:

  • You never store, process, or transmit card data on your servers.

  • Card information is entered in the donor’s browser and sent directly to Stripe, bypassing Donorfy entirely.

This dramatically reduces your PCI scope.


Post-September 2019 Donorfy Payment Tools

All new Donorfy Stripe Web Widgets and standard Campaign Donation Pages created after September 2019:

  • Are SCA compliant

  • Use Stripe’s secure payment elements

  • Never touch your systems or Donorfy’s servers

  • Fall under the simplest PCI category

Because of this, validating PCI compliance usually involves only completing Stripe’s recommended Self-Assessment Questionnaire (SAQ A).

Stripe’s documentation includes:

  • A Knowledge Base article on integration security

  • A link to the relevant SAQ form for your integration type.


Older Web Widgets (Pre-September 2019)

If you are still using the old-style Web Widgets (pre-2019), these:

  • Use Stripe.js v2

  • Require SAQ A-EP, a much more complex compliance level

  • May require support from security specialists to complete

Stripe states:

"If you continue to use Stripe.js v2, you’ll be required to upload your SAQ A-EP annually to prove your business is PCI compliant. As this is more complex, we recommend you work with SecurityMetrics if you require additional assistance in completing your SAQ A-EP. "


Recommendation: Upgrade Your Web Widgets

To simplify PCI compliance and improve security:

Migrating to the new widgets reduces compliance overhead and ensures safer, smoother donation processing.

Did this answer your question?