Demystifying PCI DSS: Choosing Your Sparados Integration Path
Updated: May 27
When integrating with Sparados, the most critical security question you must answer is: "Will my systems touch, process, or store unencrypted payment card data?"
The answer to this question determines your relationship with the Payment Card Industry Data Security Standard (PCI DSS). Depending on your business model - whether you are a Merchant (using cards for internal operations) or a Service Provider (offering card services to your own users) - your compliance path will diverge significantly based on the integration model you choose.
Table of Contents:

What Is PCI DSS Compliance?
PCI DSS compliance (Payment Card Industry Data Security Standard) is a mandatory set of security requirements designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. Established in 2004 by the major card brands — Visa, Mastercard, Discover, Amex, and JCB — the standard includes a framework of technical and operational controls that safeguard sensitive cardholder data against theft and fraud.
Compliance involves fulfilling strict practices like encrypting data in transit, maintaining robust firewalls, and conducting regular security audits. Ultimately, adhering to these rules is not just about avoiding steep fines from banks; it is about building trust with your customers by protecting their financial lifelines from cybercriminals.
Who Should Comply with PCI DSS?
If your business handles payment card data in any capacity, the short answer is: you do.
Specifically, any entity that stores, processes, or transmits cardholder data (CHD) or sensitive authentication data (SAD) must comply with PCI DSS. The size of your business or the volume of your transactions doesn't matter — if you touch card data, the rules apply.
Here is a breakdown of the specific types of companies that must comply:
Merchants: Any retail store, e-commerce website, restaurant, or service provider that accepts credit, debit, or prepaid cards as payment.
Service Providers: Companies that are directly involved in the processing, storage, or transmission of cardholder data on behalf of other businesses. This includes payment gateways, hosting providers, data centers, and third-party fraud prevention services.
Financial Institutions: Banks, credit unions, and any other organizations that issue credit cards or process merchant transactions (acquiring banks).
A Common Misconception: "We use Stripe/PayPal, so we're exempt."
Many small businesses believe that because they outsource their payment processing to a third party like Stripe, PayPal, or Shopify, they don't need to worry about PCI DSS.
While using these compliant gateways drastically reduces your scope and makes compliance much easier, it does not exempt you completely. You still have to ensure your website integration is secure and fill out a simplified self-assessment questionnaire (usually SAQ-A or SAQ-A-EP) annually to prove you are handling the integration correctly.
What Compliance Scope Is Required While Integrating with Sparados?
When integrating with Sparados, the most critical security question you must answer — one that serves as your north star for compliance architectural design — is:
"Will my systems touch, process, transmit, or store unencrypted payment card data?"
The answer to this question completely dictates your Cardholder Data Environment (CDE) scope. In the world of compliance, "scope" refers to any person, process, or piece of technology that interacts with or secures raw card data.
Depending on your foundational business model, your compliance path will diverge significantly based on the integration architecture you choose. Sparados offers two primary integration methodologies, each carrying vastly different operational scopes, financial liabilities, and development requirements.
Simple API Integration: Compliance by Proxy
The Simple API Integration is designed to keep your infrastructure entirely out of the PCI DSS scope for card data processing. In this model, the end-user interacts with sensitive data (like the full 16-digit PAN or CVV) exclusively through Sparados’ hosted web and mobile applications.
Because your servers never "see" or "touch" unencrypted card numbers, you avoid the heavy lifting of external audits.
Full API Integration: The "Embedded" Compliance Responsibility
Sparados operates as a technology provider for companies looking to open business accounts and cards. We also offer a solution for large companies (Full API Integration), which allows them to display corporate card data natively within their own applications.
Read the full API documentation:
However, this flexibility means that Sparados' clients are subject to direct and rigorous oversight under PCI DSS standards. In that case, your company is classified in the restrictive Service Provider category. Under this model, your exact compliance requirements are dictated entirely by your annual transaction volume:
Level 2 (Fewer than 300,000 Transactions Annually): At lower volumes, your pathway requires the completion of an annual Self-Assessment Questionnaire (typically SAQ D for Service Providers, which is the most comprehensive questionnaire) alongside mandatory quarterly external network vulnerability scans conducted by an Approved Scanning Vendor (ASV).
Level 1 (300,000 or More Transactions Annually): The moment your platform crosses the critical threshold of 300,000 transactions per year, your compliance obligations escalate dramatically. You can no longer self-assess. You must undergo a full, comprehensive annual external audit conducted by an independent Qualified Security Assessor (QSA).
Summary of Requirements for Full API Partners
If you opt for the Full API and have access to unencrypted PAN numbers, you must prepare for:
Attestation of Compliance: Signing the relevant SAQ provided by Sparados.
Quarterly ASV Scans: Regular network vulnerability scans (typically costing ~€1k/quarter).
The 300k Threshold: Once you exceed 300,000 transactions annually, you must either migrate to a non-sensitive data model or commit to a full annual audit by a certified PCI auditor (QSA).
(Data from Verestro: PCI DSS & other security requirements)
Strategic Verdict: Choosing the Right Path for Your Business
Deciding between these two API integration methodologies is ultimately a balancing act between user experience customization and regulatory risk appetite.
If you want to avoid the "hassle" of annual audits and high security overhead, the Simple API Integration is the recommended choice. If your business model demands Full API Integration, you will not have to walk it alone; Sparados, alongside our trusted technology provider Verestro, will actively collaborate with your technical leadership. We will guide your team through every security milestone, ensuring that as your transaction volume scales, your ecosystem remains robust, heavily defended, and fully compliant with global standards.



