The RSI security weblog breaks down the measures in some detail, but the process in essence goes like this: The difference between the different types of SOC audits lies inside the scope and duration in the assessment: Stripe.js v2 SAQ A-EP Employing Stripe.js v2 to move card details entered inside