You seem to imply that it is not impossible for a shared virtual account to meet PCI compliance just by the fact of it being a shared virtual setup; is that correct? I can involve the host and/or move a few hundred sites to a host that has a PCI compliant setup for shared virtual accounts if there is such a thing, but I need to know if I am on a wild goose chase looking for something that can't exist. I have not found any by Google. I have been told by one host that offers PCI compliance and who runs dedicated, VPS, and shared virtual that only a dedicated machine can be compliant. I have been told by others that they can make their shared virtual accounts compliant although they are not now. I have been told by the present host that the reason the audits find problems are just 'false positives.' I have been told that a requirement of 'only a single use' for a compliant machine precludes anything but a dedicated machine, and I have been told by others that that is not what that requirement means. Is there a known example of a PCI compliant shared virtual host that has passed an audit?
Main Topics
Browse All Topics





by: jason1178Posted on 2008-07-08 at 20:58:39ID: 21960492
Hi erniekent,
I would lean towards moving folks to VPS in order to deal with PCI compliance and maintain budgets. There are good, relatively inexpensive options
As far as regular shared hosting goes, it depends on the host and how willing they are to change things if the site can be made PCI compliant or not. Generally, you will not run a PCI compliant secure e-commerce site on a shared server without the host getting involved.
You can google for "PCI compliant hosting" to get a good range of options.