07-Security-Testing / 07.07.Payment-Compliance-Requirements

07.07.Payment Compliance Requirements

07.07. Payment Compliance Requirements

1. Zero-Card-Data Policy

The CPT application and all its components (API, WUI, Redis, GCS) must never touch or store raw cardholder data (CHD).

1.1 Specification: Stripe Integration

1.2 Specification: PayPal Integration


2. PII Protection in Payment State

Any PII (customer email, name) stored during the payment flow must be protected.

2.1 Specification: Encryption at Rest


3. Auditing & Reconcilliation

Maintain a log of all payment events for audit purposes.

3.1 Specification: Log Integrity


4. Compliance Reporting (SAQ-A)

Maintain documents required for PCI SAQ-A.

4.1 Specification: Annual Review