
VerifiedBlackbaud and PCI DSS
Blackbaud is listed in the Visa Global Registry of Service Providers for PCI DSS (Listed on the Visa Global Registry as PCI DSS validated through 2027-06-30), dated 16 Oct 2006, assessed by Schellman Compliance, LLC.. CertReports last verified this on 17 Sep 2026 from the registry.
Evidence
- Kind
- attestation
- Issued or listed
- 16 Oct 2006
- Expires or valid through
- 30 Jun 2027
- Auditor or assessor
- Schellman Compliance, LLC.
- Scope
- PAYMENT FACILITATOR, MERCHANT SERVICER - VISA
| Source | Captured | Quote | Links |
|---|---|---|---|
Visa Global Registry of Service Providers Official registry · HTTP 200 | 17 Sep 2026 | Blackbaud Payment Services: PCI DSS, assessor Schellman Compliance, LLC., valid through 2027-06-30 | Live pagesha256 ae8e2967e1 |
- Kind
- attestation
- Issued or listed
- 16 Oct 2006
- Expires or valid through
- 31 Jul 2027
- Auditor or assessor
- Schellman Compliance, LLC.
- Scope
- PAYMENT FACILITATOR, MERCHANT SERVICER - VISA
| Source | Captured | Quote | Links |
|---|---|---|---|
Visa Global Registry of Service Providers Official registry · HTTP 200 | 17 Sep 2026 | Blackbaud Hosted Portfolio: PCI DSS, assessor Schellman Compliance, LLC., valid through 2027-07-31 | Live pagesha256 ae8e2967e1 |
What is not public
- The Visa registry lists the assessor and the date the validation runs through, not the services in scope of the attestation of compliance.
What PCI DSS means, and what it does not
Only a registry listing (Visa Global Registry, Mastercard SDP) or an AOC letter is strong evidence. In the Visa registry only rows validated as PCI DSS with a validation date count; Third Party Agent registrations are not PCI evidence.
Read the PCI DSS guide and browse all vendors with evidenceQuestions buyers ask
Is Blackbaud PCI DSS compliant?
Blackbaud is listed as a PCI DSS validated service provider, assessed by Schellman Compliance, LLC., valid through 30 Jun 2027, as of 17 Sep 2026.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with PCI DSS evidence
Similar vendors (shared product tags or the Nonprofit and fundraising category) whose PCI DSS row is verified or vendor-stated, ranked by similarity.
Frontstream
Nonprofit and fundraising
Givelify
Nonprofit and fundraising
Anedot
Nonprofit and fundraising
Church Community Builder
Nonprofit and fundraising
DonorDrive
Nonprofit and fundraising
Paciolan
E-commerce
Active Network
Nonprofit and fundraising
Subsplash
Nonprofit and fundraising