Skip to Content
Shopify logo
  • By business model
    • B2C for enterprise
    • B2B for enterprise
    • Retail for enterprise
    By ways to build
    • Platform overview
    • Modular commerce
    • Shop Component
    By outcome
    • Growth solutions
    • Shopify
      Platform for entrepreneurs & SMBs
    • Plus
      A commerce solution for growing digital brands
    • Enterprise
      Solutions for the world’s largest brands
  • Customer Stories
    • Everlane
      Shop Pay speeds up checkout and boosts conversions
    • Brooklinen
      Scales their wholesale business
    • ButcherBox
      Goes Headless
    • Arhaus
      Journey from a complex custom build to Shopify
    • Ruggable
      Customizes Headless ecommerce to scale with Shopify
    • Carrier
      Launches ecommerce sites 90% faster at 10% of the cost on Shopify
    • Dollar Shave Club
      Migrates from a homegrown platform and cuts tech spend by 40%
    • Lull
      25% Savings Story
    • Allbirds
      Omnichannel conversion soars
    • Shopify
      Platform for entrepreneurs & SMBs
    • Plus
      A commerce solution for growing digital brands
    • Enterprise
      Solutions for the world’s largest brands
  • Why trust us
    • Leader in the 2024 Forrester Wave™: Commerce Solutions for B2B
    • 2024 Gartner Magic Quadrant for Digital Commerce
    • Leader in the 2024 IDC B2C Commerce MarketScape vendor evaluation
    What we care about
    • Shop Component Guide
    • Shopify TCO Calculator
    • Principals of a Modern Commerce OS
    • Mastering Global Trade: How Integrated Technology Drives Cross-Border Success
    How we support you
    • Premium Support
    • Help Documentation
    • Professional Services
    • Technology Partners
    • Partner Solutions
    • Shopify
      Platform for entrepreneurs & SMBs
    • Plus
      A commerce solution for growing digital brands
    • Enterprise
      Solutions for the world’s largest brands
  • Latest Innovations
    • Editions - June 2024
    Tools & Integrations
    • Integrations
    • Hydrogen
    Support & Resources
    • Shopify Developers
    • Documentation
    • Help Center
    • Changelog
    • Shopify
      Platform for entrepreneurs & SMBs
    • Plus
      A commerce solution for growing digital brands
    • Enterprise
      Solutions for the world’s largest brands
  • Get in touch
  • Get in touch
Shopify logo
  • Blog
  • Enterprise ecommerce
  • Total cost of ownership (TCO)
  • Migrations
  • B2B Ecommerce
    • Headless commerce
    • Announcements
    • Unified Commerce
    • See All topics
Search
Type something you're looking for
Log in
Get in touch

Powering commerce at scale

Speak with our team on how to bring Shopify into your tech stack

Get in touch
blog|Announcements

Simplifying PCI DSS Version 4 Compliance with Shopify’s Checkout

PCI DSS V4 goes into effect March 31, but merchants can rely on Shopify Extensions and its checkout architecture to make compliance with the new stringent payment card industry standards simple and easy.

by Stephanie Kelman
On this page
On this page
  • The ever-growing maze of regulations
  • Hassle-free compliance with Shopify’s Checkout 
  • Shopify Extensions: Unlocking customization without compromise

The platform built for future-proofing

Get in touch

In today’s rapidly evolving digital world, keeping up with the latest compliance regulations is challenging and confusing. The Payment Card Industry Data Security Standard (PCI DSS) Version 4 introduces a new set of anti-skimming requirements that protect buyers from payment data fraud. It’s an important and necessary step, but also one that introduces a new and complex compliance hurdle for many merchants.

The good news is that Shopify makes it easy for merchants to adhere to these requirements, enabling them to focus on expanding and scaling their businesses. Merchants can rest assured that Shopify’s architecture makes PCI DSS v4 compliance simple and easy.

The ever-growing maze of regulations

Regulations continue to expand covering everything from privacy and data access to web accessibility and marketing transparency. The PCI DSS v4 changes, which come into effect on March 31, 2025, introduce new security standards to combat digital skimming, which occurs when attackers steal credit card information from customers during checkout. This attack is carried through malicious code within a checkout that can steal payment data by, for example, intercepting or replacing secure input fields with an alternative that can steal user data.

Click here to talk with sales about Shopify plans for enterprises

Global cyberattacks involving digital skimming have been steadily increasing in recent years and compromise sensitive customer data. In 2019, the digital skimming attack known as Magecart was actively operating on 3,126 online stores. This attack followed two other attacks that same year targeting college campuses and hotel ecommerce platforms.

There are many important updates in PCI DSS v4, but merchants should pay close attention to section 6.4.3, which imposes requirements aimed at combatting digital skimming through the effective management of scripts that are loaded and executed on all payment pages where cardholder data can be entered.

To mitigate risk and adhere to new privacy standards, merchants must inventory and maintain an up-to-date list of all authorized scripts, verify their integrity, and implement reporting and enforcement infrastructure to identify violations. Such scripts can include identity verifications, digital wallets, marketing opt-ins, and more. Yet most merchants have limited visibility into these details, making it difficult to abide by these new regulations. 

If a merchant doesn’t use Shopify, they would need to use client-side protection platforms and security guard tools to manage and authorize their scripts, ensuring that only approved scripts are loaded and executed. These tools alone can cost hundreds of dollars a month or more and require significant time and training to manage. Often, these tools do not have a meaningful performance impact since they need to be loaded before any other content on the page and must intercept the browser-level work of loading and executing JavaScript. 

Hassle-free compliance with Shopify’s Checkout  

Shopify’s best-converting checkout is designed to be resilient against security threats with an airtight architecture. It is a managed and secure runtime engineered to help you handle compliance and ensure all aspects of data protection are in line with the latest standards. 

Shopify’s architecture helps ensure that only approved, trusted code runs during the checkout process, with all third-party scripts being securely isolated, or “sandboxed.” This prevents any unauthorized script from running, thereby protecting against data theft or other harmful activities that could compromise sensitive information. 

Find out how Shopify powers a high-performance, PCI DSS v4 compliant checkout with sandboxing from Distinguished Engineer, Ilya Grigorik.

For Shopify merchants, PCI DSS v4 requirements will be integrated seamlessly in checkout, with no additional work required. The platform will manage these new security standards, allowing merchants to focus on growing their business without worrying about compliance and data security issues. This proactive approach from Shopify provides merchants peace of mind, knowing that their checkout is reliable and protected.

Shopify Extensions: Unlocking customization without compromise

Despite rigid security requirements, Plus merchants can still create unique checkout experiences, and integrate necessary reporting and analytics, with Shopify Extensions throughout the entire purchasing journey. While traditional customization tools often introduce security vulnerabilities and performance issues, Shopify’s approach maintains:

Enterprise-grade security: With Shopify Extensions, all checkout customizations operate within a secure sandbox environment, ensuring PCI DSS Version 4 compliance remains uncompromised. 

Lighting-fast performance: Shopify’s checkout is optimized for speed, enabling up to 40,000 checkouts per shop, per minute.

Future-proof infrastructure: Shopify Checkout is a managed and secure runtime engineered to help you handle compliance and ensure cardholder data is protected. 

Upgrade-safe: Shopify’s architecture is adaptable, resilient and upgrade-safe—gain instant access to new features and never perform an upgrade again.

Tune in to our recent X space where we go deep on how merchant shops can extend checkout with apps that are performant, upgrade-safe, and compliant. As global regulations evolve, merchants can rely on Shopify’s architecture to make compliance simple and easy.

FAQs on PCI DSS V4

When does PCI DSS Version 4.0.1 go into effect?

All requirements in PCI DSS Version 4.0.1 will be mandatory as of March 31, 2025.

Do Shopify merchants need to implement additional security measures to Shopify’s checkout to be compliant with PCI DSS Version 4?

No, Shopify's checkout infrastructure ensures compliance with PCI DSS Version 4 requirements with no additional merchant work required.

Can merchants still customize their checkout while maintaining compliance with PCI DSS Version 4?

Yes, Shopify Extensions in Checkout allow for customization while maintaining full compliance with PCI DSS Version 4.

What are the costs associated with achieving PCI DSS Version 4 compliance on Shopify?

There are no additional costs for PCI DSS Version 4 compliance on Shopify as it's built into the platform's infrastructure.

by Stephanie Kelman
Published on Feb 13, 2025
Share article
  • Facebook
  • Twitter
  • LinkedIn
by Stephanie Kelman
Published on Feb 13, 2025

The latest in commerce

Get news, trends, and strategies for unlocking new growth.

By entering your email, you agree to receive marketing emails from Shopify.

popular posts

Enterprise commerceHow to Choose an Enterprise Ecommerce Platform for Your Scaling StoreTCOHow to Calculate Total Cost of Ownership for Enterprise SoftwareMigrationsEcommerce Replatforming: A Step-by-Step Guide To MigrationB2B EcommerceWhat Is B2B Ecommerce? Types + Examples
start-free-trial

Unified commerce for the world's most ambitious brands

Learn More

popular posts

Direct to consumer (DTC)The Complete Guide to Direct-to-Consumer (DTC) Marketing (2025)Tips and strategiesEcommerce Personalization: Benefits, Examples, and 7 Tactics for 2025Unified commerceHow To Sell on Multiple Channels Without the Logistical Headache (2025)Enterprise ecommerceComposable Commerce: What It Means and Is It Right for You?

popular posts

Enterprise commerce
How to Choose an Enterprise Ecommerce Platform for Your Scaling Store

TCO
How to Calculate Total Cost of Ownership for Enterprise Software

Migrations
Ecommerce Replatforming: A Step-by-Step Guide To Migration

B2B Ecommerce
What Is B2B Ecommerce? Types + Examples

Direct to consumer (DTC)
The Complete Guide to Direct-to-Consumer (DTC) Marketing (2025)

Tips and strategies
Ecommerce Personalization: Benefits, Examples, and 7 Tactics for 2025

Unified commerce
How To Sell on Multiple Channels Without the Logistical Headache (2025)

Enterprise ecommerce
Composable Commerce: What It Means and Is It Right for You?

subscription banner
The latest in commerce

Get news, trends, and strategies for unlocking unprecedented growth.

Unsubscribe anytime. By entering your email, you agree to receive marketing emails from Shopify.

Popular

Headless commerce
What Is Headless Commerce: A Complete Guide for 2025

Aug 29, 2023

Growth strategies
How To Increase Conversion Rate: 14 Tactics for 2025

Oct 5, 2023

Growth strategies
7 Effective Discount Pricing Strategies to Increase Sales (2025)

Ecommerce Operations Logistics
What Is a 3PL? How To Choose a Provider in 2025

Ecommerce Operations Logistics
Ecommerce Returns: Average Return Rate and How to Reduce It

Industry Insights and Trends
Global Ecommerce Statistics: Trends to Guide Your Store in 2025

Customer Experience
Fashion Brand Storytelling Examples to Inspire You

Mar 24, 2023

Growth strategies
SEO Product Descriptions: 7 Tips To Optimize Your Product Pages

Powering commerce at scale

Speak with our team on how to bring Shopify into your tech stack.

Get in touch
Shopify logo

Shopify

  • About
  • Careers
  • Investors
  • Press and Media
  • Partners
  • Affiliates
  • Legal
  • Service status

Support

  • Merchant Support
  • Shopify Help Center
  • Hire a Partner
  • Shopify Academy
  • Shopify Community

Developers

  • Shopify.dev
  • API Documentation
  • Dev Degree

Products

  • Shop
  • Shop Pay
  • Shopify Plus
  • Shopify Fulfillment Network
  • Linkpop
  • Shopify for Enterprise

Global Impact

  • Sustainability
  • Build Black
  • Research

Solutions

  • Online Store Builder
  • Website Builder
  • Ecommerce Website
  • Australia
    English
  • Canada
    English
  • Hong Kong SAR
    English
  • Indonesia
    English
  • Ireland
    English
  • Malaysia
    English
  • New Zealand
    English
  • Nigeria
    English
  • Philippines
    English
  • Singapore
    English
  • South Africa
    English
  • UK
    English

Choose a region & language

  • Australia
    English
  • Canada
    English
  • Hong Kong SAR
    English
  • Indonesia
    English
  • Ireland
    English
  • Malaysia
    English
  • New Zealand
    English
  • Nigeria
    English
  • Philippines
    English
  • Singapore
    English
  • South Africa
    English
  • UK
    English
  • Terms of service
  • Privacy policy
  • Sitemap
  • Privacy Choices