Build vs. Buy>Trust, Legal & Compliance>Inherited PCI-DSS & SOC2 Compliance

Should You Rely on Plus's Inherited PCI-DSS and SOC2?

Written by Deploi EditorialReviewed by Martin Dejnicki, Director of SEO & AI SearchUpdated September 2026Pricing verified September 2026

Relying on inherited certification is the right call for a Functions or checkout-extension build. Shopify is certified Level 1 PCI DSS compliant, that compliance extends by default to every Shopify store, and your code never receives a card number (per Shopify, Sep 2026). Commission an independent audit only when a counterparty demands a SOC 2 in your name or a system you host holds card or regulated data. No app performs an audit.

Your profile — see how the verdict shifts

VerdictWAIT (inherited platform certification covers a Functions or checkout-extension build) · CUSTOMIZE a shared-responsibility pack and a pen test for apps you host · BUY an independent audit only when a counterparty demands a report in your name
Buy score
3.4
Build score
7.4
Confidence
HighRead on 2026-09-05: Shopify's PCI page states that Shopify is certified Level 1 PCI DSS compliant and that this compliance extends by default to all stores powered by Shopify, which makes the certification a platform fact rather than a Plus entitlement, even though the Plus plan page also states the plan is Level 1 PCI DSS and SOC2 certified with full compliance and data encryption. Shopify's compliance documents page lists a PCI Attestation of Compliance, a quarterly ASV scan attestation, SOC 3, SOC 2 Type 2 with a bridge letter and SOC 1 Type 2 as viewable to logged-in merchants. On the mechanism side, Shopify documents that network access for Functions needs to be enabled by Shopify and that checkout UI extensions declare capabilities such as network_access, which must be requested before publishing. On the market side, the Store management: Security category held 30 apps, all fraud and chargeback blockers, accessibility widgets, GDPR consent banners and terms checkboxes; the finances and operations categories held no audit tooling either. An independent PCI or SOC 2 audit is a professional-services engagement with a licensed assessor, and no App Store product substitutes for one.
Reference scenario
$20M–$100M GMV · Shopify Plus · building a Payment Customization Function and a checkout UI extension · a custom app on the merchant's own cloud holding order data · agency dev bench
As of
September 2026

Decision at a Glance

Your profileVerdictWhy
Functions and checkout UI extensions onlyWAITYour code runs inside Shopify's sandbox and never receives a card number, and Shopify's Level 1 PCI DSS covers the cardholder data environment for every store. Download the Attestation of Compliance, file it, and build.
A custom app on your own infrastructure holding order or customer dataCUSTOMIZECard data still never touches you, so no PCI audit, but your servers now hold personal data. Write the shared-responsibility pack, adopt the Plus partner bar (annual pen test, TLS 1.2 or higher, 24-hour incident notice), and budget a penetration test at $8,000–$25,000 (Deploi estimate, illustrative).
Enterprise or B2B buyers asking for a SOC 2 in your nameBUYShopify's SOC 2 Type 2 describes Shopify's controls, not yours, and no procurement team accepts it as yours. Commission the independent audit; a first SOC 2 Type 2 is quote-based and lands two to four quarters out.
A system you run stores or transmits card numbersBUYCall-center card capture, a non-Shopify gateway or a custom payment flow puts you inside PCI scope, and the platform's certification stops at your boundary. Engage a QSA, or redesign so card data never reaches you, which is the cheaper answer.

What Inherited PCI-DSS & SOC2 Compliance Actually Drives

OutcomeImpactHow it works
Operational efficiencyHighDrawing the boundary once ends the recurring request to get the extension PCI certified, and turns audit season into a re-download of Shopify's reports plus one pen test.
Revenue — indirectMediumA shared-responsibility pack, or a SOC 2 in your name when demanded, unblocks retail and B2B partners whose procurement questionnaires stall deals without one.
Data & insightLowThe data inventory the pack requires doubles as the system map for privacy requests and incident response.
Customer experienceLowCustomers never see compliance work, and they do see a breach; controls on what you host are what stands between the two.

Spend ceiling: Spend on the boundary, not the badge. A $4,000–$12,000 pack plus an $8,000–$25,000 penetration test (Deploi estimate, illustrative) covers a custom app on your own servers; a quote-based SOC 2 is justified only when a counterparty demands a report in your name.

What buying enables (top apps)

  • + A SOC 2 or PCI report in your company's name that procurement teams accept
  • + Independent testing of your controls, which no inherited report provides
  • + A documented control set that carries into future audits and insurers' questionnaires

What building additionally unlocks

  • + A boundary document showing exactly where inherited certification stops and your responsibility starts
  • + Shopify's AoC, ASV attestation and SOC reports filed as evidence at no cost
  • + Controls on your custom app pitched at the Plus partner bar (annual pen test, TLS 1.2 or higher, AES-128 minimum, 24-hour incident notice) without an audit cycle

Find Your Verdict in 3 Questions

  1. Does any system you run yourself store, process or transmit card numbers (call-center capture, a non-Shopify gateway, a custom payment flow)?

    Yes: Your verdict: BUY — you're inside PCI scope and the platform's certification stops at your boundary; engage a QSA, or redesign so card data never reaches you.

    No: Go to question 2.

  2. Does a buyer, partner or insurer require a SOC 2 or PCI report in your company's name?

    Yes: Your verdict: BUY — commission the independent audit; Shopify's SOC 2 describes Shopify's controls and no counterparty accepts it as yours.

    No: Go to question 3.

  3. Does your custom build include an app on your own infrastructure holding order or customer data?

    Yes: Your verdict: CUSTOMIZE — inherit Shopify's attestations for the platform half and build the shared-responsibility pack plus an annual penetration test ($12,000–$37,000, Deploi estimate, illustrative) for yours.

    No: Your verdict: WAIT — Functions and checkout UI extensions never see a card; download Shopify's AoC and SOC reports, file them, and build.

The TCC Scorecard — 12 Dimensions

TCC — Total Cost of Capability: what it actually costs to have this capability over three years, whichever way you get it. Each dimension is scored 0–5 for both paths. How we score →

DimensionBuyBuildWhy
Cost
Acquisition & implementationAn independent SOC 2 or PCI assessment is a quote-based engagement measured in quarters; a shared-responsibility pack built on Shopify's attestations is 1–3 weeks (Deploi estimate, illustrative).
Recurring feesAudits recur annually with bridge letters in between; the pack needs a yearly refresh when Shopify posts new reports and a pen test only where you host customer data.
Maintenance & upgradesAuditors re-test controls every cycle; the in-house program re-downloads the AoC and SOC reports and updates the matrix.
Switching & exitAn audit report expires and is tied to its scope; a shared-responsibility matrix is a document you keep regardless of who audits you later.
Risk
Vendor riskAssessment firms are interchangeable; the inherited attestations depend on Shopify keeping them current, which it publishes annually and quarterly.
Security & compliance surfaceAn independent auditor tests your controls, which is the one thing inherited reports never do; the in-house pack relies on your own honesty about scope.
Platform-deprecation exposurePCI DSS versions and SOC frameworks move slowly, and neither path sits on a Shopify sunset.
Value
Fit to requirementFor a Functions or checkout-extension build, the audit tests systems that never see a card; the pack answers the actual question, which is where the boundary sits.
Time to marketDownload the Attestation of Compliance today; an audit's first report lands two to four quarters out.
Performance & scaleNeither path touches the storefront or the checkout's speed.
Data ownership & AI-readinessThe audit's evidence belongs to the engagement; your control inventory and data map are assets you reuse for privacy requests and incident response.
Focus & opportunity costAn audit consumes engineering and finance time for a quarter; the pack is a week or two of a technical lead.

The App Landscape

AppStatusPricingBest for
Shopify's platform certifications and compliance documentsNativeFirst-party Shopify. Shopify states it is certified Level 1 PCI DSS compliant and that this compliance extends by default to all stores powered by Shopify, not only Plus; the Plus plan page adds that the plan is Level 1 PCI DSS and SOC2 certified with full compliance and data encryption. Logged-in merchants can view Shopify's PCI Attestation of Compliance, quarterly ASV scan attestation, SOC 3, SOC 2 Type 2 with bridge letter, and SOC 1 Type 2 (per Shopify, Sep 2026). These reports describe Shopify's controls, not yours.Included with every Shopify store (verified Sep 2026)Evidence for the cardholder data environment and for the platform your Functions and checkout extensions run inside
Compliance and security appsCategoryThe category a search lands in, and it holds nothing for this decision. The Store Management security and operations categories were browsed in full and returned cookie-consent apps such as Consentmo and Pandectes, fraud and bot blockers, and accessibility widgets. None audits, scans or vets a merchant's own custom app. No product back-fills Shopify's review after the fact, which is why this market is empty rather than thin (verified Sep 2026).Nothing in the category prices this; the apps present solve other problemsConsent banners and fraud filters, which are real needs and not this one
Independent PCI DSS or SOC 2 assessmentLiveProfessional-services engagement with a licensed QSA or CPA audit firm; no App Store listing. A SOC 2 Type 2 observes your controls over a period of months, so the first report lands two to four quarters after you start, and readiness work often costs as much as the audit. Scope it to systems you host and cite Shopify's Attestation of Compliance for the platform half.Quote-based; scoped per engagement, no listed priceCounterparties who require a report in your name, or systems you run that hold card or regulated data
Shared-responsibility pack (in-house)Build laneA scoping document that maps each component of your custom build (Functions, checkout UI extensions, custom apps, data warehouse) to who controls it, cites Shopify's AoC and SOC reports for the platform half, inventories the customer data your own systems hold, and sets the controls you commit to. The bar Shopify sets for Plus-certified partners (annual independent penetration test, TLS 1.2 or higher, AES-128 minimum, incident notice within 24 hours) is a sensible floor.$4,000–$12,000 for the pack, plus $8,000–$25,000 for a third-party penetration test when your custom app hosts customer data (Deploi estimate, illustrative)Any Plus merchant with a custom app on its own infrastructure who wants a defensible answer before an auditor or a buyer asks

The Build Path

  • Draw the boundary: List every custom component and where it runs. Shopify Functions execute inside Shopify with no network access unless Shopify enables it; checkout UI extensions run in Shopify's checkout sandbox behind a capabilities allowlist, and network_access must be requested before publishing. Neither receives a card number, so neither sits in the cardholder data environment. Your own servers, if any, do hold personal data.
  • File the inherited evidence: Download Shopify's PCI Attestation of Compliance, the quarterly ASV scan attestation and the SOC 2 Type 2 with its bridge letter from the compliance documents page, and record their dates. The SOC 3 can be freely shared with counterparties; the others answer the platform question for your auditor, insurer and finance team.
  • Own the controls for what you host: For a custom app holding order or customer data, adopt the bar Shopify sets for Plus-certified partners: an annual independent penetration test, TLS 1.2 or higher, AES-128 minimum, and incident notification within 24 hours. Add data-subject-request handling within 30 days, which Shopify requires of App Store apps and never checks for custom apps.
Effort band
$4,000–$12,000 for the shared-responsibility pack and $8,000–$25,000 for a third-party penetration test — Deploi estimate (illustrative); the $10–25K contact-form band. An independent SOC 2 or PCI assessment is quote-based and sits outside these bands.
Typical timeline
1–3 weeks for the pack; 2–4 weeks for a penetration test; a first SOC 2 Type 2 runs two to four quarters (Deploi estimate, illustrative)
Maintenance, honestly
~15–20% of build cost per year (Deploi estimate): roughly $1,000–$3,000/yr (Deploi estimate, illustrative) to refresh the pack when Shopify posts new reports, plus the annual penetration test where your app hosts customer data.
What you own — and what you take on
You own: the boundary document, the data inventory and the controls on what you host. You take on: honesty about scope, because inherited certification stops exactly where your own infrastructure starts.

3-Year Total Cost of Capability

Buy (app path)Build (custom path)
Year 0 (setup)$40,000–$120,000 (quote-based engagement, illustrative)$12,000–$37,000 (pack plus penetration test)
Years 1–3 (recurring)$60,000–$180,000 (annual re-audit, illustrative)$27,000–$84,000 (yearly pen test and pack refresh)
3-year total≈$100,000–$300,000≈$39,000–$121,000
Illustrative cumulative cost over 36 months$0$48k$96k$144k$192kMo 0Mo 12Mo 24Mo 36break-even ≈ mo 0Buy (app path)Build (custom path)
Illustrative cumulative cost, and the expensive line buys a report about controls that never touch a card. For a Functions or checkout-extension build, the platform's Level 1 PCI DSS already covers the cardholder data environment; the pack plus a penetration test covers what you actually host. Commission the audit when a buyer demands a SOC 2 in your name, not before.
  • All figures illustrative samples for the reference scenario — not quotes, not verified pricing.
  • Buy column: an independent SOC 2 Type 2 or PCI assessment is quote-based; the band is an illustrative placeholder for a mid-market first engagement including readiness work, not a price.
  • Build column: shared-responsibility pack plus a yearly penetration test on a custom app hosting customer data; three-year horizon.

What the Sticker Price Hides

On the buy path

  • An audit scoped before the boundary is drawn tests Shopify-hosted components that never see a card, at your expense
  • A SOC 2 Type 2 observes controls over months, so the first report lands two to four quarters after you start
  • Readiness work (policies, evidence collection, tooling) often costs as much as the audit itself
  • Reports expire; bridge letters and re-audits become a permanent annual line

On the build path

  • Inherited certification stops at your infrastructure; a custom app database with customer data is yours to secure, monitor and disclose breaches from
  • Custom apps skip Shopify's app review, so nobody checks that you answer data-subject requests within 30 days unless you do
  • Functions network access, once Shopify enables it for you, moves data flows outside the sandbox and widens the boundary you drew
  • ~$1,000–$3,000/yr to refresh the pack, plus the annual penetration test (Deploi estimate, illustrative)

What Merchants Say

Finance and legal leads describe procurement questionnaires from retail and B2B partners asking for the merchant's own SOC 2, and the realization that Shopify's report describes Shopify, so the company has nothing in its own name.
community-reported (2026 research corpus)
Dev leads report being asked to get the checkout extension PCI certified before launch, a request that dissolves once someone draws where card data actually flows.
community-reported (2026 research corpus)

If You Change Your Mind Later

If you bought and outgrow it

An audit report is a dated artifact tied to its scope; leaving the assessment firm loses nothing but the next cycle, and the evidence collected stays yours. Keep the control inventory and data map in your own repository rather than the auditor's portal, so the next firm starts from your documents instead of from zero.

If you built and want out

The shared-responsibility pack, data inventory and penetration-test history are exactly what a future auditor asks for on day one, so nothing is wasted if a buyer later forces a SOC 2. Shopify's reports refresh annually and quarterly, and you re-download them rather than re-create anything.

When This Answer Changes

We're watching for:

  • Shopify changing the plan scope of its published compliance documents (today the PCI AoC, ASV attestation, SOC 1, SOC 2 and SOC 3 are viewable to logged-in merchants without a Plus gate, per Shopify, Sep 2026)
  • Shopify granting network access to Functions more broadly, which would move data flows outside the sandbox and widen the boundary you drew
  • A PCI DSS version change altering merchant self-assessment scope for stores on a hosted checkout

Verdict change log:

No changes since first publication (September 2026).

Common Questions

Does Shopify Plus's PCI DSS Level 1 certification cover my custom checkout code?

Shopify's Level 1 PCI DSS certification covers the platform, and your Functions and checkout UI extensions run inside it without receiving a card number. Shopify states the certification extends by default to all stores powered by Shopify, so it is not a Plus-only benefit (per Shopify, Sep 2026). The certification never covers infrastructure you run yourself: a custom app on your own servers holding customer data is yours to secure and to audit.

Can I get Shopify's SOC 2 report and give it to a customer?

Shopify's SOC 3 report can be freely shared. The SOC 2 Type 2, bridge letter, SOC 1 Type 2, PCI Attestation of Compliance and ASV scan attestation are viewable to logged-in merchants on the compliance documents page (per Shopify help, Sep 2026). All of those reports describe Shopify's controls, not yours. A partner asking for your SOC 2 wants an audit of your systems, which no Shopify document provides and no app performs.

When does a Shopify Plus merchant need its own compliance audit?

A Shopify Plus merchant needs its own audit in 3 cases. A counterparty requires a SOC 2 in your name; your custom stack stores regulated data such as health or financial records; or a system you run stores or transmits card numbers. A Functions or checkout-extension build triggers none of them. For everything in between, a shared-responsibility pack at $4,000–$12,000 plus a penetration test at $8,000–$25,000 (Deploi estimate, illustrative) is the proportionate answer.

Your Next Steps

If you're going with WAIT(matches your selected profile)

  1. Draw the data-flow diagram: where card numbers go (Shopify) and where personal data goes (Shopify plus anything you host)
  2. Download Shopify's PCI Attestation of Compliance, ASV scan attestation and SOC 2 Type 2 with bridge letter, and record their dates
  3. Write a one-page shared-responsibility statement for finance, legal and your insurer
  4. Confirm every custom Function and checkout extension runs without network access, or with access Shopify approved
  5. Re-check Shopify's compliance documents page each quarter for new reports

If you're going with BUY

  1. Scope the engagement to systems you host, and exclude Shopify-hosted components with the Attestation of Compliance as evidence
  2. Choose SOC 2 Type 2 for buyer questionnaires, and a QSA-led PCI assessment only if a system of yours truly holds card data
  3. Budget readiness work before the observation window opens: policies, evidence collection, access reviews
  4. Run a penetration test on your custom app first; it's the finding most auditors ask for anyway
  5. Put the annual re-audit and bridge letters into the compliance calendar

Official Docs & Sources

Official documentation linked for verification — our verdicts and estimates are our own.

Ready to know exactly where your compliance responsibility starts?

We map your Functions, extensions and custom apps against Shopify's certifications, file the inherited evidence, and scope a penetration test only where you actually host data.

Contact us today

Ecommerce development at Deploi

Verdict scored for the reference scenario above. Estimates are not quotes; app pricing carries its verification date and gets re-verified quarterly. Full scoring anchors: see the TCC methodology.

Read how we score these decisions (the TCC Framework). No affiliate links, no paid placement — no app vendor pays to appear here.

No affiliate links. No paid placement. We make money building and integrating solutions — not on referral fees.