Shopify Ecom

Do you need a written PCI agreement with Shopify?

Updated ·
At a glance
Short answer
Yes, but nothing new to sign: the acknowledgment 12.8.2 asks for sits in the Shopify Payments terms; another gateway is a separate agreement.
Where the acknowledgment lives
Shopify Payments Terms of Service, Part I, §A12 — part of the terms, nothing you sign separately
What it does not cover
Its scope is the Payments Services, not a third-party gateway; §A12 sits inside the Shopify Payments terms
The trap in the standard
An Attestation of Compliance is evidence of compliance, not the written acknowledgment 12.8.2 asks you to hold
The yearly duty
Requirement 12.8.4 wants a program that checks your provider's compliance status at least annually; Shopify's: the Compliance Reports page
PCI Responsibility Matrix
In the terms that phrase introduces a link; it opens Shopify's Compliance Reports page, not a separate document

What Requirement 12.8.2 asks you to hold

When an acquirer or a corporate buyer's security team asks for your written agreement with your payment provider, they are quoting an obligation of yours, not Shopify's. The mirror requirement, 12.9.1, applies only when the entity being assessed is a service provider.

PCI DSS v4.0.1 (June 2024) asks you to maintain written agreements with all third-party service providers with which account data is shared or that could affect the security of the cardholder data environment, and to have those agreements carry the provider's acknowledgment that it is responsible for the security of that data.

Outsourcing every card touch does not remove that. The PCI SSC FAQ for merchants who outsource all payment processing names two of the responsibilities that stay with the merchant: maintaining written agreements with the provider that include acknowledgment of their responsibilities (Requirement 12.8.2), and monitoring the provider's compliance status at least annually (Requirement 12.8.4). Shopify puts it in its own words: even if you outsource your payment processing, you're still responsible for complying with PCI DSS.

Read every requirement number with the version of the document it came from. The self-assessment questionnaire that carries the same requirement for v4.0.1 is SAQ A, Revision 1 (January 2025), and it answers what merchants ask next — whether a provider's published proof of compliance stands in for the agreement:

For example, a PCI DSS Attestation of Compliance (AOC), a declaration on a company's website, a policy statement, a responsibility matrix, or other evidence not included in a written agreement is not a written acknowledgment.
PCI Security Standards Council — PCI DSS v4.0.1 SAQ A, Revision 1 (January 2025), Requirement 12.8.2 Applicability Notes ·

Where the Shopify acknowledgment already sits

The document is not one you ask for. Part I, §A12 "Data Security" of the Shopify Payments Terms of Service states the acknowledgment, and the condition it depends on stands inside the same sentence:

Where the Payments Services involve Shopify storing, processing or transmitting "Account Data", as defined under Payment Card Industry Data Security Standards ("PCI DSS"), on your behalf, Shopify acknowledges that it is responsible for securing such Account Data in accordance with the applicable PCI DSS requirements.
Shopify — Shopify Payments Terms of Service, Part I §A12, read September 23, 2026 ·

The same clause turns around and lists what stays yours: your PCI-DSS compliance obligations include, but are not limited to, access controls and a ban on storing CVV2. The terms carry the rest, and no acknowledgment from Shopify covers it.

Merchants search for a PCI Responsibility Matrix because §A12 uses the phrase. In the terms the phrase introduces a link, and that link opens Shopify's Compliance Reports page rather than a document of its own: across the Shopify Payments terms, the Compliance Reports page and the Help Center's compliance-reports page, read on September 23, 2026, we found no separate file published under that name.

Nor does the standard attach a requirement to that name. In v4.0.1 the phrase does two different jobs in the passages we read: the note to Requirement 12.8.2 says a responsibility matrix not included in a written agreement is not a written acknowledgment, and the Good Practice note to Requirement 12.8.5 says a document mapping each requirement to the entity, the provider or both is "often referred to as a responsibility matrix".

What if you do not use Shopify Payments?

§A12 sits inside the Shopify Payments Terms of Service, and its acknowledgment is scoped to the Payments Services — to the case where those services involve Shopify storing, processing or transmitting Account Data on your behalf.

Requirement 12.8.2 of v4.0.1 asks for a written agreement with every third-party service provider with which account data is shared or that could affect the security of the cardholder data environment.

Where the cards run through another gateway, the written agreement under that requirement is one between you and that provider, so the acknowledgment you file is the one that provider gives you. Which providers your own card route puts in that description is worked through in our guide to Shopify PCI compliance.

What you keep, and what you check every year

The yearly duty is a routine rather than a document. Requirement 12.8.4 of v4.0.1 asks for a program that monitors your providers' PCI DSS compliance status at least once every 12 months, and the PCI SSC FAQ above states the same duty as monitoring that status at least annually.

For Shopify Payments that check has a public address. The Compliance Reports page links to Shopify's service provider PCI DSS AoC, states that Shopify completes ASV scans quarterly, and publishes a SOC 3 report it describes as publicly accessible. The Help Center page for compliance reports describes further reports, among them SOC 2 Type 2, a SOC 2 bridge letter and SOC 1 Type 2, and says you'll need to log on to your Shopify account to view the PCI AoC — though on September 23, 2026 the Compliance Reports page linked that attestation as a PDF that opened without one.

File the attestation and the agreement apart. An Attestation of Compliance is evidence that a provider is meeting PCI DSS requirements — the status 12.8.4 asks you to monitor; the written acknowledgment 12.8.2 asks for is the clause already in your terms, which is why SAQ A rules that evidence out as a substitute for it.


About This Article

This article was written entirely by AI under human editorial direction. The editor sets the topic and structure, runs multi-stage validation on facts, links, and interactive elements, and verifies the output is useful from a business perspective. All claims are checked against official Shopify sources. Details may change — always confirm critical data at shopify.com.

Editorial Policy

Related questions

Taxes & duties
Does each Shopify store get its own 1099-K?

Shopify combines volume across US Shopify Payments accounts under one TIN; if the total clears that year's threshold, each account gets a 1099-K.

August 18, 2026

Taxes & duties
Does Shopify send you a 1099-K?

Yes — Shopify Payments issues one to US sellers past $20,000 in more than 200 transactions; some states set it lower.

Updated September 12, 2026

Admin, staff & security
Does Shopify require two-step authentication?

Not by default — the choice is yours, unless you use Shopify Payments or an admin sets a secure sign-in method as required for you.

Updated September 12, 2026

Stay updated

Get notified about new articles

Subscribe to receive updates when we publish new Shopify guides and insights.