Skip to main content
Who Owns the MID? The Compliance Question That Divides Outsourced eCommercePCI DSS Compliance
4 min readFor PCI DSS Compliance Teams

Who Owns the MID? The Compliance Question That Divides Outsourced eCommerce

The question at hand

Your company outsources its entire eCommerce operation to a third party. Are you still in scope for PCI DSS compliance?

The answer hinges on a detail most merchants overlook: who owns the Merchant Identification Number (MID). That seven-to-fifteen-digit identifier determines whether you're responsible for an annual Report on Compliance or whether you can step out of scope entirely.

This isn't a technicality. It's a structural decision that reshapes your compliance obligations, audit costs, and liability exposure. Yet compliance teams often discover the implications only after they've signed the contract.

The case for merchant-owned MIDs

Keeping your own MID gives you control over the payment relationship. You maintain direct visibility into authorization rates, interchange fees, and chargeback patterns. Your treasury team can reconcile transactions in real time rather than waiting for batch Electronic Funds Transfers from a third party.

From a compliance standpoint, owning the MID means you know exactly where cardholder data flows. You control the relationship with your acquiring bank and dictate which Payment Service Providers touch your transactions. If you're already maintaining a Cardholder Data Environment (CDE) for your retail operations, adding eCommerce under the same MID can simplify your scope rather than fragment it across multiple assessments.

For larger merchants with mature compliance programs, this approach makes sense. You've already built the controls and hired the Qualified Security Assessor (QSA). Adding another channel under your existing scope doesn't double your effort.

The merchant-owned MID also preserves your brand relationship with customers. The descriptor on the cardholder's statement shows your company name, not a third-party processor. That matters for customer recognition and dispute resolution.

The case for third-party MIDs

If the third party uses their own MID and performs Electronic Funds Transfers back to your bank account, you step out of PCI scope entirely. The third party becomes the merchant of record. They handle authorization, settlement, and cardholder data storage. You receive a net deposit with no exposure to Primary Account Numbers.

This model is common for small merchants operating through platforms like eBay, Etsy, and Zazzle. The platform owns the MID, processes the transaction, and transfers funds to the seller's account. The seller never touches cardholder data. Their PCI compliance obligation is zero.

For home-based businesses or small operations with no IT infrastructure, this arrangement eliminates a compliance burden they couldn't realistically manage. A sole proprietor selling handmade goods doesn't need to implement network segmentation or maintain firewall rule sets. They need to ship products and receive payment.

Even mid-sized merchants sometimes choose this route. If you're launching a new eCommerce channel and don't have an existing compliance program, outsourcing under the third party's MID can defer the compliance investment until you've proven the channel's viability. You can always bring the MID in-house later if the revenue justifies the compliance overhead.

The tradeoff is visibility. You don't see individual transactions or control the customer payment experience. You rely on the third party's reporting for reconciliation. If a dispute arises, you're working through their process, not yours.

Where practitioners actually land

Most compliance teams make this decision based on transaction volume and existing infrastructure, not compliance philosophy.

If you're processing fewer than six million transactions annually and don't already operate a CDE, the third-party MID model is hard to beat. The cost of building and maintaining PCI compliance from scratch exceeds the margin you'll earn on those transactions.

If you're already PCI-compliant for other channels, adding eCommerce under your own MID usually makes sense. The incremental compliance cost is lower than the operational friction of working through a third party's settlement process.

The middle ground is trickier. You're processing enough volume to justify investment, but you haven't built the controls yet. Here's where you need to model both paths. Calculate the cost of a Self-Assessment Questionnaire A-EP if the third party hosts your payment pages but you own the MID. Compare that to the cost of full outsourcing under their MID. Factor in the value of transaction-level data and customer relationship control.

One detail that often tips the decision: if you're already subject to an annual Report on Compliance for any reason, adding eCommerce under your MID doesn't trigger a new assessment. You're already paying for the QSA. Expanding scope is cheaper than maintaining two separate compliance programs.

Our take

The MID ownership decision should drive your outsourcing contract, not follow from it.

If you're going to use the third party's MID, confirm it in writing before you sign. Require a service provider Attestation of Compliance and a Responsibility Matrix that explicitly documents their scope and your exclusion. Without those documents, you can't prove to an acquiring bank or QSA that you're out of scope. The AOC isn't technically required if you don't own the MID, but you'll want it when someone questions your compliance status three years from now.

If you're keeping your own MID, scope the compliance requirements before you commit to the technology. Don't assume the third party's hosted payment page automatically qualifies you for SAQ A-EP. If your domain serves the checkout page or if you redirect customers through your infrastructure, you may still be in scope for portions of the CDE. Validate the architecture with your QSA during contract review, not during your annual assessment.

The "magic" of the MID isn't that it makes compliance disappear. It's that it defines where responsibility starts and ends. Get that definition right at contract time, and you'll avoid the uncomfortable conversation where your QSA tells you that your outsourced environment still puts you in scope for Requirements 1 through 12.

You Might Also Like