Skip to main content
Blog
Blog

Braintree PCI DSS Compliance: What PayPal Merchants Still Need to Do

Braintree holds PCI Level 1 certification as a PayPal service. Merchants remain responsible for payment page script monitoring under §6.4.3 and §11.6.1 regardless of integration type.

Mar 21, 2025 Updated Aug 09, 2026 5 min read
PayPal Braintree PCI DSS compliance illustration
Table of Contents

TL;DR: Braintree PCI DSS compliance

  • PayPal Braintree handles PCI DSS Level 1 compliance for the card processing, similar to Stripe. Merchants using Braintree Hosted Fields or Drop-in UI reduce their scope significantly.
  • Merchants still own PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 on their own page even when Braintree processes the card. Both requirements apply as long as your domain loads any script on the payment page.
  • SAQ-A merchants using Braintree still need script inventory and payment-page tamper detection. cside's free tier meets both requirements at zero cost for eligible merchants.

Short on time? See cside PCI Shield. It covers everything below in one deployment.

Yes, PayPal (and Braintree) is PCI DSS compliant as a Level 1 Service Provider but depending on your integration, you are still required to complete an annual SAQ to be PCI compliant yourself. It depends on how you integrate PayPal into your business. Here's how:

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to protect card information during and after a financial transaction. Compliance involves adhering to 12 requirements, ranging from installing and maintaining a secure network to having an inventory of third party scripts running on your web pages (PCI 6.4.3 and 11.6.1).

How to be compliant using PayPal

According to PayPal's official guidelines, your PCI DSS compliance requirements depend on how your business handles payment data. If you redirect users to PayPal's hosted checkout, your PCI scope is minimal (SAQ A). However, if you process raw card data, you must complete SAQ D and follow stricter security controls.

There are three main ways businesses use PayPal:

Integration Type PCI Scope SAQ Required
PayPal Standard, Express Checkout, or Smart Button (redirect to PayPal) Minimal - No cardholder data on your servers SAQ A
PayPal advanced Braintree drop-in UI* Minimal - Hosted fields, no cardholder data on your servers* SAQ A*
Direct API integration (PayPal Pro, Braintree, API or storing card data) High - Cardholder data passes through your server SAQ D

*You now need to monitor dependencies on payment pages, more below.

  • If you redirect users to PayPal's hosted checkout, you qualify for SAQ A.
  • If you use hosted fields (e.g., Braintree Drop-in UI), you qualify for SAQ A.
  • If you collect and store cardholder data, you must complete SAQ D and implement full PCI controls.

If your business processes or stores cardholder data (SAQ D), you must:

  • Implement strong encryption for payment data.
  • Set up firewall and access control policies.
  • Conduct quarterly network scans with an Approved Scanning Vendor (ASV).
  • Complete a full PCI DSS audit if you're a Level 1 merchant (6M+ transactions/year).

Braintree is owned by PayPal and operates as its subsidiary. This relationship has a direct impact on PCI compliance, depending on which PayPal or Braintree product you use. Braintree provides more direct payment processing options, which means you might need SAQ D if card data interacts with your servers.

*Monitoring dependencies for SAQ A compliance

As per the January 2025 update, the PCI Security Standards Council emphasized the importance of monitoring dependencies. This includes both first-party and third-party scripts on websites. This update requires merchants to ensure their sites are not susceptible to attacks originating from these scripts.

See PayPal's documentation on PCI DSS here.

Related reading: our PCI DSS 6.4.3 and 11.6.1 compliance guide · Stripe's PCI DSS shared responsibilities

Determine your PCI compliance level

Level Criteria Validation Requirement
Level 1 Over 6 million transactions annually Full onsite audit by a QSA + SAQ D
Level 2 1 to 6 million transactions annually SAQ A, SAQ A-EP, or SAQ D + Attestation of Compliance (AOC)
Level 3 20,000 to 1 million online transactions annually SAQ A, SAQ A-EP, or SAQ D + Attestation of Compliance (AOC)
Level 4 Less than 20,000 online transaction OR up to 1 million total transactions SAQ A, SAQ A-EP, or SAQ D + Attestation of Compliance (AOC)
  • Level 1 = Must do a ROC (Full PCI DSS Assessment with Full Report on Compliance by QSA)
  • Level 2 = Must do at least an SAQ with third party QSA or ISA attestation
  • Level 3 = Must do SAQ
  • Level 4 = Optional

Submit PCI compliance certification

For SAQ A merchants:

  • Complete SAQ A via PayPal's PCI compliance portal.
  • Ensure no scripts interfere with PayPal's hosted fields.
  • Keep documentation for annual reviews.

For SAQ D merchants:

  • Conduct quarterly network scans via an Approved Scanning Vendor (ASV).
  • Implement PCI security controls (firewall, encryption, access control).
  • Undergo an onsite QSA audit if required.

Once you've identified the correct SAQ based on your integration method, complete it thoroughly. PayPal's compliance portal walks merchants through the SAQ submission process for each integration type.

Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

FAQ

Frequently Asked Questions

It reduces but does not remove your obligations. Even when the cardholder data fields are hosted by PayPal or Braintree, you still control the payment page, which means PCI DSS 4.0.1 sections 6.4.3 and 11.6.1 (script management and integrity monitoring) still apply.

SAQ A applies when all cardholder data functions are fully outsourced to a PCI-compliant third party, such as redirecting to PayPal's hosted checkout or using Braintree's Drop-in UI. SAQ D applies when card data touches your own servers, such as with direct API integration or if you store card numbers. SAQ A has far fewer controls, but the January 2025 PCI DSS update replaced §6.4.3 and §11.6.1 with a self-attestation requirement: merchants must confirm their site is not susceptible to attacks from scripts. In practice, making that attestation honestly requires the same script inventory and page integrity monitoring those requirements describe.

No. Requirements 6.4.3 and 11.6.1 of PCI DSS 4.0.1 are merchant obligations tied to your payment page, not to your payment processor. Braintree certifies the card processing environment; it has no visibility into the scripts your domain loads alongside its hosted fields. You are responsible for inventorying every script on your payment page and monitoring the page for unauthorized changes.

You need to inventory and authorize every script on the payment page, monitor the HTTP headers and page content for unauthorized changes, and keep an audit trail. cside automates this for PayPal and Braintree integrations.

cside's PCI Shield monitors every script on your payment page in real visitor sessions, maintains a verified inventory, and detects unauthorized changes to satisfy §6.4.3 and §11.6.1 of PCI DSS 4.0.1. It deploys as a single JavaScript snippet with no DNS changes, and a free tier is available for eligible SAQ A merchants.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

Book a personalized demo to see:

How to achieve PCI DSS requirement 6.4.3 & 11.6.1 compliance in 1 day
Why third-party scripts are a security risk for you and your visitors
Monitoring privacy and consent leakage (GDPR, CCPA) across every third party
Stopping signup abuse, account sharing, and chargeback fraud with device intelligence
Detecting and controlling AI agents and bots hitting your site in real time

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead