You seem to have received many conflicting answers. I work for a payment company and have been audited by a Level 1 service provider, and deal with traders and their PCI requirements every day, so I think I can help you figure it out.
The reality is that you need to be PCI compatible if you accept credit cards, even if you transfer all the functions of a cardholderβs data. The trick is that the standard you need to meet is much less restrictive than the standard that a payment gateway must comply with - but that does not mean that "PCI is not applied." You do not need to understand the really stringent requirements for network security, but there are aspects of PCI DSS that you must comply with and you need to conduct a self-assessment audit every year. `
For more information on which part of DSS you should deal with, go to https://www.pcisecuritystandards.org/saq/instructions_dss.shtml and click on the link for SAQ Validation Type 1 (Questionnaire A). This will tell you which parts of PCI DSS you should implement as a trader with all the cardholder functions outsourced.
Hope this helps you figure it out!
Mikeh
source share