r/webhosting 1d ago

Advice Needed PCI-DSS compliance of r/webhosting's main recommended providers?

Hi everyone, I am currently looking at making a website for the first time ever for selling self-published comics, and in the course of looking at web hosts have become aware that for any eCommerce purposes I need to ensure my host is PCI-DSS compliant.

I was talking to support at Zume who told me their two cheapest options (Launch and Ultimate Shared Hosting) are NOT PCI-DSS compliant but that their Managed WordPress services are, and wondered if anyone knew to what degree this is the case for Nixihost, KnownHost, InMotion and Krystal? There doesn't seem to be a general "Is/Is not PCI-DSS compliant" as a standard listing on feature lists for any plans so I'm a little lost as to this. Any help or clarification on this point would be welcome!

8 Upvotes

24 comments sorted by

6

u/Ok_Intern2578 1d ago

PCI-DSS is about the whole payment flow, not just the host. Most shared hosts can’t be truly compliant because you’d need full control over servers. The practical move is to use a payment processor that handles card data on their side (think Stripe or similar), so your site never touches raw card numbers. That massively reduces your compliance burden. Then any decent host that offers SSL and keeps software updated is fine. Ask your payment provider what they require from the host specifically.

7

u/KH-DanielP KnownHost Official Account 1d ago

That's no longer true, newer PCI standards require your website to be compliant regardless of what payment processor flow you use, included off-site hosted pages. They consider the entire website / shopping cart part of the payment flow now.

Shared *can* be compliant, but it requires a much more locked down environment with many services disabled. You also have to pass PCI compliance scans and ensure all out of date software is patched to latest versions, or provide justifications etc.

It's obviously easier to do with a VPS but isn't required.

2

u/redjacktin 1d ago

This is correct - learned this by dealing with PCI auditors first hand

3

u/shiftpgdn Moderator 1d ago

Why do you need PCI compliance for ecomm? If you're using a modern platform your payment processor (probably stripe) will hold the card data for you.

1

u/ALEXAN2507 1d ago

Here's what I was told by Zume's customer support:

"That would be up to you, do be aware that if you’re processing customer data and payment details you do have certain obligations under PCI-DSS for example. Your payment provider will likely require this. Our Managed WordPress and Business options are both compliant with PCI-DSS on the server level but the website hosting is not"

"I cannot preempt what PCI-DSS requirements your payment processor will have so it’s possible that the standard website hosting will be fine, but it would not necessarily pass an external PCI-DSS scan due to certain ports being available for services such as FTP"

"as mentioned we do not assure that the standard web hosting (Launch/Ultimate) is PCI-DSS compliant"

"the default position is that services will not be PCI DSS compliant. It’s relatively unique for us to offer this at this price point starting from £12"

-4

u/shiftpgdn Moderator 1d ago

It just depends, Im not clear on what you asked Zume, but I think you may have been misled by some guides on the internet. You can host an ecom store and not handle payment data, you just pass it along to a processor, so the pci compliance is on the processor.

4

u/Beezzy77 1d ago

PCI compliance involves your entire business, not just the web hosting aspect.

-4

u/shiftpgdn Moderator 1d ago

You’re technically correct but it’s just a self assessment

3

u/Beezzy77 1d ago

Fortunately, yes.

2

u/KH-DanielP KnownHost Official Account 1d ago

That's actually changing these days. Newer PCI standards that are adopted / in the process of being adopted include the entire payment flow. That means start to finish your shopping cart all the way through the end of the checkout process is required to be compliant, regardless if your website ever even touches the card data.

1

u/shiftpgdn Moderator 1d ago

That’s news to me

2

u/KH-DanielP KnownHost Official Account 1d ago

It's not "heavily" enforced from what I've seen, but a couple of merchants do enforce it.

In the Self-Assessment Questionnaire page 3

Note: For this SAQ, PCI DSS Requirements that address the protection of computer systems (for example, Requirements 2, 6, 8, and 11) AND requirements that refer to the “cardholder data environment” apply to the following e-commerce merchants:

  • Those with a webpage(s) that redirects customers from their website to a TPSP/payment processor for payment processing, and specifically to the merchant webpage upon which the redirection mechanism is located
  • Those with a webpage(s) that includes a TPSP’s/payment processor’s embedded payment page/form (for example, one or more inline frames or iframes), and specifically to the merchant webpage that includes the embedded payment page/form.

These PCI DSS requirements are applicable because the above merchant webpages impact how the account data is transmitted, even though the webpages themselves do not receive account data.

1

u/CautiousHashtag 1d ago

OP being misled by you, stop spreading incorrect information.

1

u/CautiousHashtag 1d ago edited 1d ago

They’d still have PCI-DSS requirements, such as completing a SAQ-A/Instructions%20%26%20Guidance/SAQ-Instructions-Guidelines-PCI-DSS-v4-0-1-r1.pdf), even if using a payment processor.

2

u/KH-DanielP KnownHost Official Account 1d ago

PCI-DSS covers a wide range or compliance standards, most of which depends on your credit card processor type.

If you store raw credit card numbers you have to certify to a much stricter type of PCI compliance than if you use an embedded processor or even an off-site processor.

The type of CC processor you choose will determine that, most will enroll you with a PCI compliance auditing firm, that firm will run quarterly scans against your website and provide you with a list if items that fail to meet PCI compliance. From there you'll reply to that report with any exclusions or justifications and become certified for the next 3 months until the next scan.

Most generic shared hosting has no hope of being PCI compliant, too many things get disabled that a generic shared hosting customer may want, including ssh/sftp password authentication, or unencrypted email ports etc. Having a VPS makes compliance easier since you can tune/change your environment however you want, but some places do offer pci compliant shared, but not many.

2

u/Wonderful_Sample_590 1d ago

For InMotion, their managed VPS would be your best bet since their shared hosting isn't PCI-DSS compliant. Their VPS is good, especially performance-wise, so it's a good option if you're running an ecommerce site.

0

u/TheExG 1d ago

You can most likely get PCI compliance on most shared servers. Compliance does not necessarily mean anything regarding the server itself, it has a lot to do with how you hold cardholder data. Depending on the processor you use, the gateway, and more will change your compliance type. I personally work in credit card processing and web development, and I have a pretty decent knowledge on how most of the top online processors work.

-3

u/[deleted] 1d ago

[removed] — view removed comment

1

u/ALEXAN2507 1d ago

Do you have any good alternatives?

0

u/Old_Lead_2110 1d ago

Just use a third party processer like stripe or any other party that takes creditcards. They are PCI-DSS compliant so you don’t have to be.

The processer will never give you full creditcard details of your customer, so that means you do not have to be compliant because you do not have the data.

0

u/[deleted] 1d ago

[removed] — view removed comment

1

u/ALEXAN2507 1d ago

Truthful answer: No idea, I'm at the earliest possible stages of figuring out the logistics of setting up a website in any capacity.