Redirect to a Third Party? You Still Need ASV Scans: PCI SSC FAQ 1604 Explained
Merchants often assume redirecting to a payment provider removes the need for vulnerability scans. PCI SSC FAQ 1604 says otherwise: SAQ A includes ASV scanning under Requirements 11.3.2 and 11.3.2.1.
