The security documentation your payment processor and insurer both want
Card payments bring PCI DSS obligations most small retailers have never seen written down, on top of what a cyber insurance renewal now asks for. What each actually requires, and how to produce the paperwork without a security team.
Usually a payment processor’s annual self-assessment questionnaire (SAQ), a cyber insurance renewal, or a chargeback dispute that asks how card data is protected.
What the engine actually produced for one real business of this kind — including the gaps, which it states with a remediation clause rather than leaving out.
What tends to be true of firms like yours.
PCI DSS applies the moment you take a card
Accepting card payments carries obligations from the card brands, administered through your payment provider or acquiring bank — an annual self-assessment questionnaire matched to how you accept cards, and in some cases a quarterly external scan. Using a payment provider narrows which questionnaire applies; it does not remove the obligation.
A hosted checkout doesn’t cover everything
Routing payment through a processor keeps card numbers off your own servers, but the checkout page itself — and everything around it — stays your responsibility even when the payment is processed elsewhere. Your documents state what is outsourced and what you still own, so a reviewer can see the actual boundary.
Admin access is the highest-value target here
For an online store, the storefront and payment-dashboard logins are worth more to an attacker than any single card number. Multi-factor authentication and a password manager on those accounts are the two controls worth getting right first — your documents record honestly which ones are and aren’t in place.
Reusable across your processor and your insurer
The same written program answers your processor’s SAQ questions and your cyber insurance renewal — re-answer what changed a year later and regenerate, rather than filling out each form from a blank page.
Whether your PCI DSS obligations call for a particular self-assessment questionnaire, or something beyond it, depends on transaction volume and your processor’s own determination — that call sits with your processor and your counsel. Coverwright produces the written policies a merchant is asked to hold; holding them is not the same as PCI DSS compliance or certification, and your documents say so.