If you alter the source code, does it nullify the pci pa-dss compliance and then require a re-assessment?
If you alter the source code, does it nullify the pci pa-dss compliance and then require a re-assessment?
Technically, yes.
Realistically - unless you touch any security or gateway related code, you're probably not messing with anything that'll affect PA-DSS compliance. While technically you're required to have the customizations reviewed by a QSA, it won't be an issue until/unless your site is audited.
If you decide not to have the review done, and you have some kind of a breach and get audited....ouch.That's not a cheap settlement.