WorldPay PCI DSS Assessment Guide

WorldPay PCI DSS Assessment Guide


WorldPay Business Profile - PCI DSS Assessment

Assessment Method


Q: Choose an assessment method

A: Guide Me - Select this option to use our profiling tool to help you determine the scope of your PCI DSS compliance requirements and to complete your PCI DSS assessment.

Payment Channels    

Q: How do you accept payment cards?

A: Online payments (incl. e-Commerce website/shop, consumer mobile app, etc.)

Q: How do you accept online e-commerce customer card payments?

A: My customers make online payments to my business via a website accessed using a web browser; My customers make online payments to my business via a mobile app downloaded to their own device from an App Store.

Q: Mobile app payment processing

A: Mobile app supports native in-app payments and integrates my payment service provider's Mobile SDK for Android and Apple devices.

E-Commerce Hosting & Management

Q: Do you use a third party hosting company, e-Commerce platform provider, software as a service (SaaS) platform provider to host your e-Commerce website?

A: Yes

Q: Is your entire online payments e-Commerce website fully managed, operated and maintained by a third party?

A: Yes (Completely outsourced)

Q: Is your outsourced e-Commerce service provider PCI DSS compliant?

A: Yes

Q: Is ASV scanning performed by your ecommerce website provider?

A: Yes (Verified on at least a quarterly basis)

Service Providers


Q: Website Hosting Provider

A: Bottlecapps (PCI DSS Compliant: Yes)

Q: Website Shopping Cart

A: Bottlecapps

Q: Payment Service Provider

A: WorldPay US Inc. (PCI Compliant: Yes)

Q: Verified PSP does not pass card data back to application/website?

A: Yes

Data Handling & Security

Q: Send/receive full card numbers via email or instant messaging?

A: No

Q: Store, transmit or receive cardholder data electronically in any other way?

A: No

Q: Information Security Policy

A: I already have an Information Security Policy in place that covers ALL of the relevant clauses of the Payment Card Industry Data Security Standard (PCI DSS)

Business Environment

Q: Business premises type(s)

A: Retail liquor store

Q: How does your business store, process and/or transmit cardholder data?

A: We do not store process or transmit cardholder data

Q: Overall business environment description

A: We do not store process or transmit cardholder data