I am a web developer with a large number of existing clients that have e-commerce sites hosted on third-party shared virtual hosting accounts (Linux.) None of them store credit cards and all simply connect securely to the transaction gateway (we write our own gateway interfaces, no packaged carts.) However we are being asked to make many of them PCI compliant. Scans of their existing host have indicated problems with the server that the host is not correcting, and I need to move them to a host that can pass an audit. However I have received conflicting information on whether it is even possible for a shared virtual hosting account to be PCI compliant. It would be very costly to move them to VPS or dedicated accounts. I need accurate information on whether or not shared virtual hosting can be PCI compliant, and if it can how to locate hosts that are.
Start Free Trial