Earlier quoted context omitted.
A successful startup is one that has grown rapidly in recent years. No growth = not successful, and not recent = not a startup. Any tech company that grows quickly starts bumping up against any number of compliance issues, both legal (ie HIPAA) and private (ie PCI). Today's growth curves don't keep pace with many of these regulations. As you expand laterally into new markets you constantly run into new obligations. A…
Isn't that why many companies are using Stripe and similar payment processors now? https://support.stripe.com/questions/do-i-need-to-be-pci-com...
Services like these are part of the problem. They can verify that the service they provide is compliant, but nobody can determine remotely whether or not you are compliant with something like PCI. You cannot outsource compliance. It is something you have to actually do.
And fyi these "iframe" services that allows a merchant to opt for SAQ-EP rather than the longer SAQ-D, that might be going away in the next couple years. Merchants may have to go with a full redirect, not a frame, if they want to wash their hands of chd.