SnowBe Online PCI DSS Audit
This collaborative PCI DSS assessment determines that SnowBe Online is a Level 2 merchant that must complete SAQ D, because it stores cardholder data in an AWS-hosted WordPress storefront. It works through merchant level, validation requirements, why each other SAQ does not fit, and the ongoing obligations that follow.
By Sean Richard · Project date May 2026
At a glance
- Scenario
- SnowBe Online: about 1.2 million card transactions a year (90% of sales), with cardholder data stored in an AWS-hosted WordPress storefront.
- Determinations
- PCI DSS Level 2 merchant, SAQ D v3 Merchant, an annual SAQ and AOC, and quarterly ASV scans.
- Scope
- AWS environment, WordPress shopping cart, databases, servers, endpoints, VPN, and network devices, unless segmented and verified out of scope.
- Team
- Completed as a collaborative team project.
Which PCI merchant level applies, and why
SnowBe Online is a PCI DSS Level 2 merchant. Credit and debit card purchases account for 90 percent of sales, approximately 1,200,000 transactions per year. Level 2 generally applies to merchants that process between 1 million and 6 million payment card transactions annually. SnowBe does not meet the Level 1 threshold of more than 6 million, and it exceeds the limits for Levels 3 and 4.
The level matters because it sets the validation requirements. PCI DSS applies to organizations that store, process, or transmit cardholder data, so the AWS environment, WordPress shopping cart, databases, servers, access management systems, network devices, and connected systems are all part of the PCI DSS environment unless they are properly segmented and verified out of scope.
What Level 2 requires
- An annual Self-Assessment Questionnaire (SAQ), which evaluates whether the company follows PCI DSS security requirements.
- An Attestation of Compliance (AOC), which confirms the assessment was completed and responsibilities are understood.
- Quarterly vulnerability scans by an Approved Scanning Vendor (ASV), to identify vulnerabilities that could put cardholder data at risk.
Security controls must also be maintained across every in-scope system, including employee laptops, office desktops, and VPN connections: firewalls, regular updates, antivirus, secure passwords, restricted access to sensitive information, and monitoring for suspicious activity. Because SnowBe stores customer payment information on its own systems, it carries a larger PCI DSS scope and greater responsibility.
Which SAQ applies, and why the others do not
SAQ D v3 Merchant is the appropriate questionnaire because SnowBe stores and processes payment card information through its AWS-hosted website. Customer information and purchase history are also kept indefinitely. Working through the alternatives shows why none of the narrower questionnaires fit:
| SAQ | Why it does or does not fit SnowBe |
|---|---|
| SAQ A | Does not fit. SnowBe has not fully outsourced payment processing. |
| SAQ A-EP | Does not fit. The website and WordPress shopping cart are directly involved in the payment process. |
| SAQ B, B-IP, C-VT, P2PE | Do not apply because of how SnowBe handles payment processing and cardholder data. |
| SAQ C | Does not fit. It is intended for merchants with internet-connected payment applications that do not electronically store cardholder data, and SnowBe does store it. |
| SAQ D v3 Merchant | Selected. Covers the broader cardholder data environment: website, WordPress cart, stored cardholder data, and connected systems. |
There is no requirement to complete multiple SAQs. The physical storefronts use bank-provided terminals that are PCI DSS Level 1 certified and do not store customer information, and payments not processed through the website are cash or check.
Shared responsibility on AWS
AWS is PCI DSS Level 1 certified as a service provider, but that does not transfer the merchant's obligations. SnowBe remains responsible for securing its website, its WordPress shopping cart, its stored cardholder data, and its connected systems. Hosting on a compliant cloud provider covers the infrastructure the provider runs. It does not cover what the merchant builds and stores on top of it.
Ongoing obligations under SAQ D
Falling under SAQ D brings responsibilities beyond completing the questionnaire: regular vulnerability scans, system updates, access control reviews, strong password protections, monitoring for suspicious activity, employee security awareness training, and records showing that controls are being followed. SnowBe would maintain its AOC, complete quarterly ASV scans, and continuously validate PCI DSS controls because of the large number of systems in scope.
The assessment is direct about the remaining gaps. SnowBe had made improvements such as updating antivirus software and patching systems, but the case still showed shared login information and access control issues. Those would need regular monitoring and continuous improvement for SnowBe to remain compliant.
What this project demonstrates
- Determining PCI DSS merchant level from transaction volume.
- Scoping a cardholder data environment across cloud, web, and on-premise systems.
- Selecting the correct SAQ by ruling out each alternative with a stated reason.
- Explaining shared responsibility between a merchant and a PCI-certified cloud provider.
Read the full document
Portfolio edition of coursework completed for the B.S. in Cyber/Computer Forensics & Counterterrorism at Full Sail University. The organization and scenario are a course case study, and this page summarizes the full document.