Stripe
Payments infrastructure: card acquiring, Checkout, Billing, Connect marketplaces, Radar fraud tooling and Stripe Tax.
Certifications & Accreditations
| Certification | Certifying Body | Scope | Achieved | Expiry | Status |
|---|---|---|---|---|---|
| PCI DSS Level 1 Service Provider | Qualified Security Assessor | Stripe payment processing and cardholder data environment - the highest PCI service provider level | — | — | Current |
| ISO/IEC 27001 | Accredited third-party certification body | Stripe production systems and supporting ISMS | — | — | Current |
| SOC 1 Type II and SOC 2 Type II | Independent third-party auditor | Stripe payment services; reports available to customers under NDA | — | — | Current |
Compliance Frameworks
PCI DSS v4.0
Full
PCI DSS Level 1 service provider - reduces card data scope for merchants using Stripe-hosted fields
SOC 2 Type 2
Full
ISO/IEC 27001:2022
Full
GDPR 2016/679
Full
Stripe acts as controller for payment data and processor for other customer data; SCCs and UK IDTA available
DORA
Partial
Relevant where the customer is a UK or EU financial entity - review the Stripe ICT contractual terms
Copyright © 2026 SnapGRC