Do you need a written PCI agreement with Shopify?

August 30, 2026·
At a glance
Short answer
Yes, but nothing new to sign: the acknowledgment 12.8.2 asks for sits in the Shopify Payments terms; another gateway is a separate agreement.
Where the acknowledgment lives
Shopify Payments Terms of Service, Part I, §A12 — part of the terms, nothing you sign separately
What it does not cover
Its scope is the Payments Services, not a third-party gateway; §A12 sits inside the Shopify Payments terms
The trap in the standard
An Attestation of Compliance is evidence of compliance, not the written agreement 12.8.2 asks you to hold
The yearly duty
Requirement 12.8.4 wants a program that checks your provider's compliance status at least annually; Shopify's: the Compliance Reports page
PCI Responsibility Matrix
In the terms that phrase introduces a link; it opens Shopify's Compliance Reports page, not a separate document

What Requirement 12.8.2 asks you to hold

When an acquirer or a corporate buyer's security team asks for your written agreement with your payment provider, they are quoting an obligation of yours, not Shopify's. The mirror requirement, 12.9.1, applies only when the entity being assessed is a service provider.

PCI DSS v4.0.1 (June 2024) asks you to maintain written agreements with all third-party service providers with which account data is shared or that could affect the security of the cardholder data environment, and to have those agreements carry the provider's acknowledgment that it is responsible for the security of that data.

Outsourcing every card touch does not remove that. The PCI SSC FAQ for merchants who outsource all payment processing names two of the responsibilities that stay with the merchant: maintaining written agreements with the provider that include acknowledgment of their responsibilities (Requirement 12.8.2), and monitoring the provider's compliance status at least annually (Requirement 12.8.4). Shopify puts it in its own words: even if you outsource your payment processing, you're still responsible for complying with PCI DSS.

Read every requirement number with the version of the document it came from. The self-assessment questionnaire that carries the same requirement is published as PCI DSS v4.0 SAQ A (April 2022), and it answers what merchants ask next — whether a provider's published proof of compliance stands in for the agreement:

Evidence that a TPSP is meeting PCI DSS requirements (for example, a PCI DSS Attestation of Compliance (AOC) or a declaration on a company's website) is not the same as a written agreement specified in this requirement.
PCI Security Standards Council — PCI DSS v4.0 SAQ A (April 2022), Requirement 12.8.2 ·

Where the Shopify acknowledgment already sits

The document is not one you ask for. Part I, §A12 "Data Security" of the Shopify Payments Terms of Service states the acknowledgment, and the condition it depends on stands inside the same sentence:

Where the Payments Services involve Shopify storing, processing or transmitting "Account Data", as defined under Payment Card Industry Data Security Standards ("PCI DSS"), on your behalf, Shopify acknowledges that it is responsible for securing such Account Data in accordance with the applicable PCI DSS requirements.
Shopify — Shopify Payments Terms of Service, Part I §A12, read August 29, 2026 ·

The same clause turns around and lists what stays yours: your PCI-DSS compliance obligations include, but are not limited to, access controls and a ban on storing CVV2. The terms carry the rest, and no acknowledgment from Shopify covers it.

Merchants search for a PCI Responsibility Matrix because §A12 uses the phrase. In the terms the phrase introduces a link, and that link opens Shopify's Compliance Reports page rather than a document of its own: across the Shopify Payments terms, the Compliance Reports page and the Help Center's compliance-reports page, read on August 29, 2026, we found no separate file published under that name.

Nor does the standard attach a requirement to that name. In v4.0.1 the phrase does two different jobs in the passages we read: the note to Requirement 12.8.2 says a responsibility matrix not included in a written agreement is not a written acknowledgment, and the Good Practice note to Requirement 12.8.5 says a document mapping each requirement to the entity, the provider or both is "often referred to as a responsibility matrix".

What if you do not use Shopify Payments?

§A12 sits inside the Shopify Payments Terms of Service, and its acknowledgment is scoped to the Payments Services — to the case where those services involve Shopify storing, processing or transmitting Account Data on your behalf.

Requirement 12.8.2 of v4.0.1 asks for a written agreement with every third-party service provider with which account data is shared or that could affect the security of the cardholder data environment.

Where the cards run through another gateway, the written agreement under that requirement is one between you and that provider, so the acknowledgment you file is the one that provider gives you. Which providers your own card route puts in that description is worked through in our guide to Shopify PCI compliance.

What you keep, and what you check every year

The yearly duty is a routine rather than a document. Requirement 12.8.4 of v4.0.1 asks for a program that monitors your providers' PCI DSS compliance status at least once every 12 months, and the PCI SSC FAQ above states the same duty as monitoring that status at least annually.

For Shopify Payments that check has a public address. The Compliance Reports page links to Shopify's service provider PCI DSS AoC, states that Shopify completes ASV scans quarterly, and publishes a SOC 3 report it describes as publicly accessible. The Help Center page for compliance reports describes further reports, among them SOC 2 Type 2, a SOC 2 bridge letter and SOC 1 Type 2, and says you'll need to log on to your Shopify account to view the PCI AoC — though on August 30, 2026 the Compliance Reports page linked that attestation as a PDF that opened without one.

File the attestation and the agreement apart. An Attestation of Compliance is evidence that a provider is meeting PCI DSS requirements — the status 12.8.4 asks you to monitor; the written agreement 12.8.2 asks for is the clause already in your terms, which is why SAQ A rules that evidence out as a substitute for it.


About This Article

This article was written entirely by AI under human editorial direction. The editor sets the topic and structure, runs multi-stage validation on facts, links, and interactive elements, and verifies the output is useful from a business perspective. All claims are checked against official Shopify sources. Details may change — always confirm critical data at shopify.com.

Editorial Policy

Related questions

Stay updated

Get notified about new articles

Subscribe to receive updates when we publish new Shopify guides and insights.