Is a paid SecurityMetrics subscription required if I only use QuickBooks invoice payment links?
I use QuickBooks Online with QuickBooks Payments and I'm trying to clarify the PCI compliance requirements for my specific payment workflow.
I only send customers invoices/payment links through QuickBooks. Customers enter their own card information on Intuit's hosted payment page, including customers who choose AutoPay.
I do not:
- manually enter customer card numbers
- take card numbers by phone, email, chat, or message
- use a card reader or POS terminal
- collect card information through my website
- store cardholder information on my computer or other systems
Based on Intuit's PCI guidance, this appears to be an SAQ A payment environment.
I currently pay SecurityMetrics for PCI compliance, and I'm trying to determine whether the paid SecurityMetrics service itself is required by QuickBooks Payments, rather than whether PCI compliance is required.
Specifically:
- Does QuickBooks Payments require a merchant with this setup to maintain a paid SecurityMetrics subscription?
- Can I complete the official SAQ A myself annually at no cost?
- If I complete SAQ A myself, do I simply retain it in my business records, or does QuickBooks Payments require me to submit it through SecurityMetrics or another portal?
- If SecurityMetrics is used as the PCI validation portal, is there a free/self-service validation option rather than the paid service?
- Has anyone using only QuickBooks invoices/payment links canceled the paid SecurityMetrics service and continued to be recognized as PCI compliant by QuickBooks Payments?
I understand that PCI compliance itself is required. I'm specifically trying to determine whether paying SecurityMetrics is required to satisfy that obligation with QuickBooks Payments.