Skip to main content
PayPal logo

PayPal

PCI DSS evidence

paypal.comPaymentsLast verified 17 Sep 2026
PCI DSS mark, CertReports state Verified as of 17 Sep 2026Verified

PayPal and PCI DSS

PayPal is listed in the Visa Global Registry of Service Providers for PCI DSS (Listed on the Visa Global Registry as PCI DSS validated through 2026-10-31), dated 14 Apr 2005, assessed by K3DES, LLC. CertReports last verified this on 17 Sep 2026 from the registry.

Evidence

VerifiedListed on the Visa Global Registry as PCI DSS validated through 2026-10-31
as of 17 Sep 2026 · confidence 100%
Kind
attestation
Issued or listed
21 Nov 2012
Expires or valid through
31 Oct 2026
Auditor or assessor
K3DES, LLC
Scope
HIGH INTEGRITY RISK PAYMENT FACILITATOR, PAYMENT FACILITATOR, THIRD PARTY SERVICER
SourceCapturedQuoteLinks
Visa Global Registry of Service Providers
Official registry · HTTP 200
17 Sep 2026PayPal Pte.Ltd Tokyo Branch: PCI DSS, assessor K3DES, LLC, valid through 2026-10-31
Live pagesha256 8a626d012c
VerifiedListed on the Visa Global Registry as PCI DSS validated through 2026-10-31
as of 17 Sep 2026 · confidence 100%
Kind
attestation
Issued or listed
15 Oct 2015
Expires or valid through
31 Oct 2026
Auditor or assessor
K3DES, LLC
Scope
DYNAMIC CURRENCY CONVERSION, HIGH INTEGRITY RISK PAYMENT FACILITATOR, ISO - HIGH INTEGRITY RISK, MERCHANT SERVICER - VISA, PAYMENT FACILITATOR
SourceCapturedQuoteLinks
Visa Global Registry of Service Providers
Official registry · HTTP 200
17 Sep 2026PayPal Inc: PCI DSS, assessor K3DES, LLC, valid through 2026-10-31
Live pagesha256 8a626d012c
VerifiedListed on the Visa Global Registry as PCI DSS validated through 2026-10-31
as of 17 Sep 2026 · confidence 100%
Kind
attestation
Issued or listed
11 Dec 2006
Expires or valid through
31 Oct 2026
Auditor or assessor
K3DES, LLC
Scope
PAYMENT FACILITATOR, ISO - HIGH INTEGRITY RISK, DYNAMIC CURRENCY CONVERSION, HIGH INTEGRITY RISK PAYMENT FACILITATOR, MERCHANT SERVICER - VISA
SourceCapturedQuoteLinks
Visa Global Registry of Service Providers
Official registry · HTTP 200
17 Sep 2026Paypal Australia Pty Ltd: PCI DSS, assessor K3DES, LLC, valid through 2026-10-31
Live pagesha256 8a626d012c
VerifiedListed on the Visa Global Registry as PCI DSS validated through 2027-06-30
as of 17 Sep 2026 · confidence 100%
Kind
attestation
Issued or listed
2 Feb 2010
Expires or valid through
30 Jun 2027
Auditor or assessor
K3DES, LLC
Scope
THIRD PARTY SERVICER, PAYMENT FACILITATOR, MERCHANT SERVICER - VISA, HIGH INTEGRITY RISK PAYMENT FACILITATOR
SourceCapturedQuoteLinks
Visa Global Registry of Service Providers
Official registry · HTTP 200
17 Sep 2026PAYPAL (EUROPE) S.A.R.L. & CIE, S.C.A.: PCI DSS, assessor K3DES, LLC, valid through 2027-06-30
Live pagesha256 8a626d012c
VerifiedListed on the Visa Global Registry as PCI DSS validated through 2026-10-31
as of 17 Sep 2026 · confidence 100%
Kind
attestation
Issued or listed
14 Apr 2005
Expires or valid through
31 Oct 2026
Auditor or assessor
K3DES, LLC
Scope
DYNAMIC CURRENCY CONVERSION, HIGH INTEGRITY RISK PAYMENT FACILITATOR, ISO - HIGH INTEGRITY RISK, MERCHANT SERVICER - VISA, THIRD PARTY SERVICER, VISANET PROCESSOR, PAYMENT FACILITATOR
SourceCapturedQuoteLinks
Visa Global Registry of Service Providers
Official registry · HTTP 200
17 Sep 2026PayPal: PCI DSS, assessor K3DES, LLC, valid through 2026-10-31
Live pagesha256 8a626d012c

What is not public

  • The Visa registry lists the assessor and the date the validation runs through, not the services in scope of the attestation of compliance.
What PCI DSS means, and what it does not

Only a registry listing (Visa Global Registry, Mastercard SDP) or an AOC letter is strong evidence. In the Visa registry only rows validated as PCI DSS with a validation date count; Third Party Agent registrations are not PCI evidence.

Read the PCI DSS guide and browse all vendors with evidence

Questions buyers ask

Is PayPal PCI DSS compliant?

PayPal is listed as a PCI DSS validated service provider, assessed by K3DES, LLC, valid through 31 Oct 2026, as of 17 Sep 2026.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with PCI DSS evidence

Similar vendors (shared product tags or the Payments category) whose PCI DSS row is verified or vendor-stated, ranked by similarity.