Stripe

Finance & Payments United States Website Reviewed Sept. 2, 2026

Payments infrastructure: card acquiring, Checkout, Billing, Connect marketplaces, Radar fraud tooling and Stripe Tax.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
PCI DSS Level 1 Service Provider Qualified Security Assessor Stripe payment processing and cardholder data environment - the highest PCI service provider level Current
ISO/IEC 27001 Accredited third-party certification body Stripe production systems and supporting ISMS Current
SOC 1 Type II and SOC 2 Type II Independent third-party auditor Stripe payment services; reports available to customers under NDA Current

Compliance Frameworks

PCI DSS v4.0
Full
PCI DSS Level 1 service provider - reduces card data scope for merchants using Stripe-hosted fields
SOC 2 Type 2
Full
ISO/IEC 27001:2022
Full
GDPR 2016/679
Full
Stripe acts as controller for payment data and processor for other customer data; SCCs and UK IDTA available
DORA
Partial
Relevant where the customer is a UK or EU financial entity - review the Stripe ICT contractual terms

Assess Stripe in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.