Compliance frameworks, security audits, and quality certifications this company maintains.
BigCommerce is PCI DSS Level 1 certified as a service provider, eliminating PCI compliance scope for merchants by handling payment card data security across its hosted checkout infrastructure — a key advantage over self-hosted Magento deployments.
BigCommerce maintains SOC 2 Type II certification for its e-commerce platform, demonstrating the security and availability controls required by enterprise retailers and their auditors when evaluating hosted commerce infrastructure.
BigCommerce holds ISO 27001 certification for its information security management system covering the cloud infrastructure that hosts 45,000+ merchant stores and processes billions in gross merchandise value annually.
BigCommerce is GDPR compliant, providing merchants in Europe with data processing agreements, EU data hosting options, cookie consent frameworks, and tools to support their obligations to shoppers' data rights under EU privacy law.
BigCommerce supports CCPA compliance for California merchants by providing data subject request tools, consent management features, and privacy policy templates that help retailers meet their obligations to California resident shoppers.
BigCommerce's default storefront themes and checkout experience conform to WCAG 2.1 AA accessibility standards, helping merchants comply with ADA requirements and serve shoppers with visual, motor, and cognitive disabilities.
Security
NIST Cybersecurity Framework
CompliantBigCommerce aligns its platform security operations with the NIST Cybersecurity Framework, covering identify, protect, detect, respond, and recover functions across its multi-tenant SaaS e-commerce infrastructure.
BigCommerce is ISO 27017 certified for cloud security controls, providing enterprise retail customers with assurance that its shared-responsibility security model meets internationally recognized standards for cloud service providers.
BigCommerce supports HIPAA-compliant storefronts for health and wellness merchants selling non-prescription products, providing data handling agreements that allow health-focused retailers to operate on the platform within HIPAA guidelines.
BigCommerce holds CSA STAR Level 2 certification validating that its cloud e-commerce infrastructure meets the Cloud Security Alliance's standards for security, transparency, and accountability in multi-tenant SaaS environments.