PCI compliance is a set of security standards that protect credit and debit card information. Any organization that accepts card payments is expected to meet them — churches included, and nonprofit status does not exempt you. The standards are set by the PCI Security Standards Council, the body created by the major card brands.
Meeting these standards keeps your donors' payment details safe and protects your church from the cost and disruption of a data breach. The good news: because One Church handles the card processing for you, your part is short.
How One Church keeps you covered
One Church Giving, and by extension One Church Software, is a PCI-compliant service provider. Card processing is handled by our payment processor, Usio, on validated and compliant systems. Card and bank details entered into your giving forms are encrypted and never stored by your church.
Because all cardholder data functions are outsourced to us, your church qualifies for the simplest form of validation available.
What your church needs to do
Once a year, your church confirms its own compliance by completing a Self-Assessment Questionnaire A (SAQ A) through VikingCloud, our PCI compliance partner. SAQ A is the shortest questionnaire — it is built for merchants who never store, process, or transmit cardholder data themselves.
Most of it is a series of yes/no questions confirming you do not handle card data directly. If your name is on the compliance and you feel unqualified to answer, the questions are more straightforward than they look, and they double as a helpful checklist of good payment-security habits.
Two answers to know as you start:
Third-party service provider - answer yes, and enter USIO.
Environment and processing method - choose Shopping Cart for your environment and Ecommerce for the processing method, since donations are only accepted online.
Tip: If a question asks about storing card data, backing up media, password policies, or anything else that does not match how your church operates, reach out to our support team before guessing. We answer these questions every week and can tell you exactly what applies to your setup.
Watch for the VikingCloud email
After your online giving is set up, VikingCloud sends an email with instructions and your login details. It generally arrives by the start of the following month and comes from notifications@complywithpci.com.
This email is legitimate, not spam or phishing. You will also receive reminders each year when your annual renewal comes due, sometimes labeled "Action Required." Please do not ignore them — unresolved compliance can lead to fees from the card networks.
You may see the names Sysnet or ControlScan in older correspondence. That is the same program under previous names.
If the email never arrives
Check your spam and junk folders.
Confirm which address it went to. VikingCloud emails the primary contact on your merchant account, which is often a different staff member, such as a treasurer or a general office address.
Verify that online giving is actually enabled on your public giving page. The email is not triggered until it is.
If it is still missing, contact our support team and we will have it re-sent.
If you cannot log in
The portal at complywithpci.com signs you in with your Merchant ID (MID) and username. Use the Forgot Username link with your MID and the primary contact email on the merchant account, then reset your password if needed.
You can find your Merchant ID in One Church under Contributions > Settings > Merchant Accounts, in the Merchant ID (MID) column.
About vulnerability scans
Under PCI DSS v4.0.1, some SAQ A merchants are asked to run quarterly external vulnerability scans. If you see a scan requirement in your portal, check your business profile first — most One Church churches do not belong in that category.
Because One Church and Usio handle every part of payment processing, and donors never enter card details on a domain your church owns, your church's internet presence is fully outsourced. To set this:
In the VikingCloud portal, find Your business profile and select Manage.
Choose Re-profile.
Select Entire internet presence is outsourced.
This places your church in SAQ A without the scan requirement. Portal wording shifts from time to time, so if you cannot find these options, contact our support team and we will walk you through it.
Tip: If you do end up running a scan, point it at your church's own public website domain — not your onechurchsoftware.com address. Any findings will relate to your own website host, and your web provider can help you resolve them.
Never collect card details by hand
Warning: Never write down, type, or store a donor's card number yourself — not on paper, in an email, or in a spreadsheet. Every card gift should go through One Church's secure giving forms. Collecting card numbers manually increases your compliance obligations well beyond SAQ A and puts both your church and your donors at risk.
If a donor wants to give by card, direct them to your online giving page or enter the gift with them through the secure form.
Other things churches ask about
Changing who receives PCI emails - submit Usio's merchant information update form. You will need your church's legal name and your Merchant ID.
Your questionnaire asks for proof that One Church is compliant - contact our support team and we will send you our current certificate of validation.
You use another giving platform as well - let us know. Additional processors can change which questions apply to you, and we will help you sort out the right answers.
Someone called claiming to be a PCI company - be cautious. Legitimate contact about your compliance comes by email from notifications@complywithpci.com. If you are unsure, check with us before sharing any information.
Next Steps
