Skip to content
Coverwright
For online and retail stores

The security policy your payment processor already expects you to have

Every card you accept carries a self-assessment questionnaire your processor administers, and PCI DSS 4.0 — mandatory since March 2025 — now expects more than it used to. What that actually asks of a small store, and what it doesn’t.

Usually a cyber insurance renewal that suddenly asks detailed questions about payment-page security, a payment processor or acquiring bank risk review, or a marketplace or wholesale partner asking for a written security policy before they’ll list or supply you.

5
documents
82
clauses
5
gaps flagged

What the engine actually produced for one real business of this kind — including the gaps, which it states with a remediation clause rather than leaving out.

What tends to be true of firms like yours.

PCI DSS is fully in force, and it now expects more

Version 4.0 became mandatory in March 2025. It broadened multi-factor authentication to cover anyone with access to the systems that touch card data — not just remote access — and added a requirement to inventory and manage the scripts running on your payment page, aimed at the checkout-skimming attacks that hit small online stores hardest. Your payment provider still administers the actual self-assessment; your documents record the access controls PCI DSS is now asking every merchant to have written down.

Your platform and your apps answer to different people

Your e-commerce platform secures its own hosting and patches its own software. The apps and scripts you’ve added to it are yours to vet, and an abandoned or compromised one is one of the most common ways a storefront actually gets skimmed. The vendor responsibility matrix draws that line explicitly — platform on one side, your admin accounts and app choices on the other.

A processor narrows the questionnaire; it doesn’t remove it

Accepting card payments carries an annual self-assessment questionnaire matched to how you accept cards, administered through your payment provider or acquiring bank. Using a payment provider narrows which questionnaire applies — it does not cover a checkout page you host yourself, which stays your responsibility even when the payment itself is processed elsewhere.

Insurers already price retail differently

More customer records, more payment exposure, more third-party app risk — cyber insurers increasingly underwrite retail and e-commerce more tightly than a comparable services business, which shows up as sharper questions and higher limits at renewal. A written policy and an honest list of what’s still a gap is exactly what that underwriting conversation is trying to get out of an applicant.

Where this stops

Coverwright does not complete your PCI self-assessment questionnaire or determine your compliance level — that stays a separate step with your payment provider, and your documents name it as an owner action rather than a box already ticked. Producing these documents does not guarantee insurance acceptance or claim outcomes either; those determinations stay with your carrier and, where the details matter, your own counsel.

Worth reading first

Before you decide anything.

See your own set before you pay.

Answer 21 plain-English questions — about ten minutes — and read the first section of your real generated program before deciding. From $199, one time, renewed for $99 a year.

No account needed to see your documents · no sales call, ever