Skip to main content

SUMMER SAVINGS 90% OFF QuickBooks for 3 months* Ends 8/27

Buy now
Switch to QuickBooks and 70% off for 3 Months
New Member
September 3, 2026
Question

Documentation needed from QuickBooks for PCI Compliance

  • September 3, 2026
  • 5 replies
  • 108 views

Quickbooks handles all credit card payments from our customers.  I am trying to complete the Self-Assessment Questionnaire A.  As the TPSP, Quickbooks needs to provide written information so we meet the Questionnaire’s requirements.  I need a link to the document(s) needed or contact information for someone who can help.  QB’s "help/ contact us" folks don't seem to know anything about credit card processing or PCI compliance. The Merchant Payment Terms of Service, QB’s Attestation of Compliance, and QB’s Attestation of Validation do not meet the requirements.

12.8.2 requires a written agreement from QB, stating they are “responsible for the security of the account data it may store, process, or transmit on behalf of the customer or to the extent the TPSP may impact the security of a customer’s cardholder data and/or sensitive authentication data.”

12.10.1 requires an incident response plan, which requires a way to contact QB immediately if there is an issue.

5 replies

QuickBooks Team
September 3, 2026

For PCI DSS compliance documentation, the right team to contact is SecurityMetrics. They can provide the formal written TPSP responsibility agreement (12.8.2) and the security incident response contact information (12.10.1) that your SAQ-A requires.

 

They are Intuit's dedicated PCI compliance partner and are specifically equipped to help QuickBooks Payments merchants navigate SAQ-A requirements, including what documentation Intuit can provide to satisfy requirements 12.8.2 and 12.10.1. You can visit this link: www.securitymetrics.com/pcidss/intuit.

 

You should also keep a record of all correspondence, as your PCI auditor may want to see the communication trail alongside the documentation provided.

 

For more information and SecurityMetrics' contact number, refer to this article: Learn about QuickBooks PCI DSS Compliance Services.

 

Let us know if you have any other concerns.

user2026Author
New Member
September 4, 2026

Intuit/ Quickbooks is the TPSP, not SecurityMetrics.  SecurityMetrics is a separate company and they charge additional fees.  When we signed up for Quickbooks’ credit card processing we were specifically told we were not required to pay additional fees for PCI compliance. 

I don’t need help navigating the SAQ-A requirements.  I need help getting the documentation my TPSP (Quickbooks) is required to provide.  I also need a way to contact QB immediately if there is a credit card security concern.

QuickBooks Team
September 4, 2026

You are correct. Intuit QuickBooks is the TPSP, not SecurityMetrics.  However, QuickBooks Payments partners with SecurityMetrics, a PCI compliance vendor, to assist customers in achieving PCI compliance.

 

For the documents you need, you may reach out directly to SecurityMetrics for further assistance. SecurityMetrics provides guidance, assessments, and resources to help you complete the PCI compliance process.

 

If you prefer to obtain your own PCI compliance independently, you are welcome to do so.

 

Please let us know if you have any other concerns.

New Member
September 4, 2026

Hi user2026,

You are entirely correct to push back on this. SecurityMetrics is a third-party compliance vendor Intuit partners with, but you are not obligated to buy their paid portal packages to validate your self-assessment. PCI DSS is a self-assessment standard, and because your card processing is fully hosted by QuickBooks Payments, you can satisfy these exact requirements directly using official Intuit documentation:

1. Requirement 12.8.2 (Written TPSP Agreement)

Auditors and merchant banks accept the published Intuit Payments Merchant Agreement alongside Intuit's Attestation of Compliance (AoC) to meet this control:

  • In the standard Intuit Payments Merchant Agreement (under the Data Security and PCI Compliance sections), Intuit contractually binds itself as a Level 1 Service Provider and accepts responsibility for protecting cardholder data that it stores, processes, or transmits on your behalf.
  • You can pair this clause with Intuit's current Level 1 Service Provider Attestation of Compliance (AoC), which is freely downloadable from Intuit's Security Center.
  • In your SAQ documentation folder, cite that specific section of the Intuit Merchant Terms of Service as your written agreement, and attach the AoC as evidence.

2. Requirement 12.10.1 (Incident Response Strategy)

This requirement specifies that your internal Incident Response Plan (IRP) defines roles and communication paths if a breach occurs:

  • In your IRP documentation, list Intuit Merchant Services Security and Fraud Operations as your primary Third-Party Service Provider escalation point.
  • Note in your plan: "If an incident involves cardholder data processed through QuickBooks Payments, immediate notification will be submitted via the Intuit Security Center escalation form and Merchant Support, followed by notification to our acquiring bank."

Submitting Your SAQ A Once your SAQ A document and Attestation of Validation (AoV) are completed, you can submit them directly to your merchant acquiring bank or keep them on file for your annual compliance audit trail rather than paying a third-party vendor portal


 

Aakash Sinha | Accounting & Financial Data Workflows (Feel free to reach out via DM if you have questions)
user2026Author
New Member
September 4, 2026

Thank you so much!  I appreciate your time and willingness to provide actual information!

Can you tell me where to find the Intuit Security Center escalation form and how to submit it if needed?