top of page

Demystifying PCI DSS: Choosing Your Sparados Integration Path

May 20
4 min read

Updated: May 27

When integrating with Sparados, the most critical security question you must answer is: "Will my systems touch, process, or store unencrypted payment card data?"


The answer to this question determines your relationship with the Payment Card Industry Data Security Standard (PCI DSS). Depending on your business model - whether you are a Merchant (using cards for internal operations) or a Service Provider (offering card services to your own users) - your compliance path will diverge significantly based on the integration model you choose.



Choosing the PCI DSS compliance scope

What Is PCI DSS Compliance?


PCI DSS compliance (Payment Card Industry Data Security Standard) is a mandatory set of security requirements designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. Established in 2004 by the major card brands — Visa, Mastercard, Discover, Amex, and JCB — the standard includes a framework of technical and operational controls that safeguard sensitive cardholder data against theft and fraud.


Compliance involves fulfilling strict practices like encrypting data in transit, maintaining robust firewalls, and conducting regular security audits. Ultimately, adhering to these rules is not just about avoiding steep fines from banks; it is about building trust with your customers by protecting their financial lifelines from cybercriminals.


Who Should Comply with PCI DSS?


If your business handles payment card data in any capacity, the short answer is: you do.


Specifically, any entity that stores, processes, or transmits cardholder data (CHD) or sensitive authentication data (SAD) must comply with PCI DSS. The size of your business or the volume of your transactions doesn't matter — if you touch card data, the rules apply.


Here is a breakdown of the specific types of companies that must comply:


  • Merchants: Any retail store, e-commerce website, restaurant, or service provider that accepts credit, debit, or prepaid cards as payment.

  • Service Providers: Companies that are directly involved in the processing, storage, or transmission of cardholder data on behalf of other businesses. This includes payment gateways, hosting providers, data centers, and third-party fraud prevention services.

  • Financial Institutions: Banks, credit unions, and any other organizations that issue credit cards or process merchant transactions (acquiring banks).

A Common Misconception: "We use Stripe/PayPal, so we're exempt."

Many small businesses believe that because they outsource their payment processing to a third party like Stripe, PayPal, or Shopify, they don't need to worry about PCI DSS.

While using these compliant gateways drastically reduces your scope and makes compliance much easier, it does not exempt you completely. You still have to ensure your website integration is secure and fill out a simplified self-assessment questionnaire (usually SAQ-A or SAQ-A-EP) annually to prove you are handling the integration correctly.


What Compliance Scope Is Required While Integrating with Sparados?


When integrating with Sparados, the most critical security question you must answer — one that serves as your north star for compliance architectural design — is:

"Will my systems touch, process, transmit, or store unencrypted payment card data?"

The answer to this question completely dictates your Cardholder Data Environment (CDE) scope. In the world of compliance, "scope" refers to any person, process, or piece of technology that interacts with or secures raw card data.


Depending on your foundational business model, your compliance path will diverge significantly based on the integration architecture you choose. Sparados offers two primary integration methodologies, each carrying vastly different operational scopes, financial liabilities, and development requirements.


Simple API Integration: Compliance by Proxy 


The Simple API Integration is designed to keep your infrastructure entirely out of the PCI DSS scope for card data processing. In this model, the end-user interacts with sensitive data (like the full 16-digit PAN or CVV) exclusively through Sparados’ hosted web and mobile applications.


Because your servers never "see" or "touch" unencrypted card numbers, you avoid the heavy lifting of external audits.


Full API Integration: The "Embedded" Compliance Responsibility


Sparados operates as a technology provider for companies looking to open business accounts and cards. We also offer a solution for large companies (Full API Integration), which allows them to display corporate card data natively within their own applications.


Read the full API documentation:



However, this flexibility means that Sparados' clients are subject to direct and rigorous oversight under PCI DSS standards. In that case, your company is classified in the restrictive Service Provider category. Under this model, your exact compliance requirements are dictated entirely by your annual transaction volume:


  • Level 2 (Fewer than 300,000 Transactions Annually): At lower volumes, your pathway requires the completion of an annual Self-Assessment Questionnaire (typically SAQ D for Service Providers, which is the most comprehensive questionnaire) alongside mandatory quarterly external network vulnerability scans conducted by an Approved Scanning Vendor (ASV).

  • Level 1 (300,000 or More Transactions Annually): The moment your platform crosses the critical threshold of 300,000 transactions per year, your compliance obligations escalate dramatically. You can no longer self-assess. You must undergo a full, comprehensive annual external audit conducted by an independent Qualified Security Assessor (QSA).


Summary of Requirements for Full API Partners


If you opt for the Full API and have access to unencrypted PAN numbers, you must prepare for:


  1. Attestation of Compliance: Signing the relevant SAQ provided by Sparados.

  2. Quarterly ASV Scans: Regular network vulnerability scans (typically costing ~€1k/quarter).

  3. The 300k Threshold: Once you exceed 300,000 transactions annually, you must either migrate to a non-sensitive data model or commit to a full annual audit by a certified PCI auditor (QSA).



Strategic Verdict: Choosing the Right Path for Your Business


Deciding between these two API integration methodologies is ultimately a balancing act between user experience customization and regulatory risk appetite.


If you want to avoid the "hassle" of annual audits and high security overhead, the Simple API Integration is the recommended choice. If your business model demands Full API Integration, you will not have to walk it alone; Sparados, alongside our trusted technology provider Verestro, will actively collaborate with your technical leadership. We will guide your team through every security milestone, ensuring that as your transaction volume scales, your ecosystem remains robust, heavily defended, and fully compliant with global standards.







Find out how we can help your business!

SPARADOS - THE OPTIMAL SOLUTION

Sparados S.A.

Sparados SA with headquarters in Lublin, at 17A Rusałka St., 20-103 Lublin, entered into the register of enterepreneurs of the National Court Register with the KRS No. (National Court Register No.): 0000985680, NIP (Tax ID No./VAT Reference No.): 9462719635 and REGON (Business ID No.): 522752701, with a fully paid share capital of PLN 333 370,00.

 

Data Protection Officer: Weronika Dawidzka

Email: [email protected]

Contact: +48 781 761 200

  • Instagram
  • Facebook
  • LinkedIn
  • YouTube

Sparados App

Download on the Apple Store
Download on the Apple Store
Get it on Google Play
Get it on Google Play

© 2026 Sparados. All right reserved

EFSG_en.png
NCBR_logo_ENG.png
RDF_en.png

Designed by

Sparados S.A. (Tax Identification Number/NIP: 9462719635), with its registered office in Lublin at ul. Rusałka 17A, 20-103 Lublin, is neither a payment service provider nor a payment institution within the meaning of the Act of 19 August 2011 on Payment Services. The Company does not hold an authorization from the Polish Financial Supervision Authority (KNF) to provide payment services, does not hold user funds, and provides solely a technological platform for expense management and integration with third-party payment service providers.

Payment services, including the maintenance of accounts, issuance of payment cards, and execution of transactions, are provided by appropriately licensed payment service providers operating within Europe, in accordance with applicable laws and under the supervision of relevant regulatory authorities.

The use of payment functionalities is subject to the acceptance of the terms and conditions of the respective payment service provider. The agreement for the provision of payment services is concluded directly between the user and said provider.

Sparados S.A. shall not be held liable for the execution of payment transactions or for their settlement between the user and the payment service provider. The Company acts exclusively as a technology solution provider enabling access to these services.

bottom of page