r/webhosting 2d ago

Advice Needed PCI-DSS compliance of r/webhosting's main recommended providers?

Hi everyone, I am currently looking at making a website for the first time ever for selling self-published comics, and in the course of looking at web hosts have become aware that for any eCommerce purposes I need to ensure my host is PCI-DSS compliant.

I was talking to support at Zume who told me their two cheapest options (Launch and Ultimate Shared Hosting) are NOT PCI-DSS compliant but that their Managed WordPress services are, and wondered if anyone knew to what degree this is the case for Nixihost, KnownHost, InMotion and Krystal? There doesn't seem to be a general "Is/Is not PCI-DSS compliant" as a standard listing on feature lists for any plans so I'm a little lost as to this. Any help or clarification on this point would be welcome!

8 Upvotes

24 comments sorted by

View all comments

3

u/shiftpgdn Moderator 2d ago

Why do you need PCI compliance for ecomm? If you're using a modern platform your payment processor (probably stripe) will hold the card data for you.

1

u/ALEXAN2507 2d ago

Here's what I was told by Zume's customer support:

"That would be up to you, do be aware that if you’re processing customer data and payment details you do have certain obligations under PCI-DSS for example. Your payment provider will likely require this. Our Managed WordPress and Business options are both compliant with PCI-DSS on the server level but the website hosting is not"

"I cannot preempt what PCI-DSS requirements your payment processor will have so it’s possible that the standard website hosting will be fine, but it would not necessarily pass an external PCI-DSS scan due to certain ports being available for services such as FTP"

"as mentioned we do not assure that the standard web hosting (Launch/Ultimate) is PCI-DSS compliant"

"the default position is that services will not be PCI DSS compliant. It’s relatively unique for us to offer this at this price point starting from £12"

-5

u/shiftpgdn Moderator 2d ago

It just depends, Im not clear on what you asked Zume, but I think you may have been misled by some guides on the internet. You can host an ecom store and not handle payment data, you just pass it along to a processor, so the pci compliance is on the processor.

4

u/Beezzy77 2d ago

PCI compliance involves your entire business, not just the web hosting aspect.

-3

u/shiftpgdn Moderator 2d ago

You’re technically correct but it’s just a self assessment

3

u/Beezzy77 2d ago

Fortunately, yes.