Sign Up
    Log In

Security and Compliance at Sezzle

PCI DSS Compliance at Sezzle

Sezzle is a PCI DSS Level 1 certified Service Provider

Sezzle is certified as a Level 1 Service Provider under the Payment Card Industry Data Security Standard (PCI DSS), the highest level of PCI certification available to service providers. Level 1 certification means an independent Qualified Security Assessor (QSA) has fully assessed Sezzle's security controls, rather than Sezzle assessing itself.

PCI DSS is a comprehensive set of security requirements created by the PCI Security Standards Council to protect cardholder data and to ensure the safe handling and storage of sensitive payment card information. The current version of the standard is PCI DSS v4.0.1.

Sezzle's responsibilities are documented in our Report on Compliance (ROC) and Attestation of Compliance (AOC), independently audited and reported by our QSA. Our AOC is submitted to our acquiring banks and is available to merchants and partners on request through our Trust Center.

The roles Sezzle plays under PCI DSS

Sezzle participates in card transactions in more than one way, and PCI DSS treats each role differently:

  • As a service provider. When merchants offer Sezzle at checkout, Sezzle handles payment card data on their behalf. Our Level 1 Service Provider certification covers this role.
  • As a merchant. When shoppers pay Sezzle with their own debit or credit cards, Sezzle is itself a merchant accepting card payments, with its own PCI DSS obligations to its acquiring banks. Sezzle meets these obligations under the same independently audited security program.
  • As a card program participant. The Sezzle Anywhere virtual card is issued through Sezzle's bank partner. Card data Sezzle handles in connection with that program is covered by Sezzle's Level 1 assessment and reflected in our ROC and AOC.

What this means for merchants

Sezzle's certification is designed to take the PCI burden of Sezzle transactions off your plate. When you implement Sezzle according to our recommended configuration, sensitive payment card data collected in the Sezzle checkout is handled by Sezzle, not by you, and responsibility for protecting that data rests with Sezzle under the Sezzle Merchant Agreement.

Important: Sezzle's certification covers card data handled by Sezzle. It does not cover your other payment channels or systems. You remain solely responsible for your own PCI DSS obligations and compliance status, and we recommend consulting your own information security professionals or a Qualified Security Assessor regarding any cardholder data your business handles outside of Sezzle.

Two things are required on your side:

  • Implement Sezzle according to the recommended configuration. If your implementation deviates from the recommended configuration, the delegation described above may not apply, and you should consult a Qualified Security Assessor.
  • Stay on top of your own PCI obligations. Your business likely accepts payments through channels other than Sezzle.

What this means for shoppers

You do not need to do anything. When you pay with Sezzle, we protect your card details under the current PCI DSS standard for as long as we retain them. That protection is independently audited every year.

About PCI DSS certification levels

PCI DSS assigns compliance levels based on transaction volume. Service providers like Sezzle are certified under a two-level scheme:

  • Level 1: Stores, processes, or transmits more than 300,000 Visa transactions per year. Requires a full annual on-site assessment by an independent Qualified Security Assessor, resulting in a Report on Compliance, plus quarterly network scans by an Approved Scanning Vendor. (Sezzle is Level 1.)
  • Level 2: Fewer than 300,000 Visa transactions per year. May self-assess annually using a Self-Assessment Questionnaire, with the same quarterly scans.

Merchants are certified under a separate four-level scheme based on their own transaction volumes. More information is available on the PCI Security Standards Council website: www.pcisecuritystandards.org.

Verify our compliance

Sezzle’s Attestation of Compliance (AOC) is available on request through our Trust Center. Sezzle’s PCI DSS assessment is renewed annually.

For information about how Sezzle handles personal information more broadly, see Sezzle’s Privacy Policy.

Sezzle’s Attestation of Compliance (AOC) is available upon request in our Trust Center.

Trust Center
Sezzle’s Privacy Policy

1Pay later loans are originated by WebBank or Sezzle. Refer to your loan agreement for lender information. For example, for a $300 loan Pay in 4, you would make one $75 down payment today, then three $75 payments every two weeks for a 45.0% annual percentage rate (APR) and a total of payments of $307.49 which includes a $7.49 Service Fee (finance charge) charged at loan origination. Service fees vary and can range from $0 to $7.49 depending on the purchase price and Sezzle product. Actual fees are reflected in checkout.

2Sezzle First Party Data, 1H 2025. Lift 60 days prior to adding Sezzle widget vs 60 days after.