MerchantGuy.com
TwitterFacebookLinkedIn
  • Home
  • About Us
  • Solutions
    • Retail
    • Mobile Payments
    • E-Commerce
    • Gift Cards / Loyalty Cards
    • Terminal Replacement Program
    • PCI DSS Compliant
  • Education
    • FAQ
    • What is Interchange?
    • Common Terms
  • Contact Us
  • Merchant Login

What is PCI DSS Compliance?

The Payment Card Industry (PCI) Data Security Standard (DSS) is a set of requirements for enhancing payment account data security. These standards were developed by the PCI Security Standards Council, which was founded by American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa, Inc. to facilitate industry-wide adoption of consistent data security measures on a global basis. The standard aims to increase awareness and promote best practices in the handling of sensitive information as a means to minimizing identity theft and fraudulent transactions.

Is PCI DSS New?

No. The framework of the PCI data security standards has existed in different forms for some time now and continues to evolve. You may be more familiar with the payment brands’ programs that promote the adoption of PCI DSS.

Here are a few links to review about PCI Compliance.

MasterCard: Site Data Protection (SDP) program

Visa: Cardholder Information Security Program (CISP)

Discover Network: Discover Information Security & Compliance (DISC)

American Express: Data Security Operating Policy

I am a small business and only process a few hundred dollars a month. Does my merchant account still need to be PCI Compliant?

Yes, all merchants, whether small or large, are required to be PCI compliant. The payment brands have collectively mandated PCI DSS compliance for any and all organizations that process, store or transmit payment cardholder data. Inherent in having a merchant account is the ability to handle cardholder data.

I already use a “PCI Compliant” Terminal/Gateway. Does that mean I am PCI Compliant?

No. Use of PCI compliant payment application is one aspect of the many PCI DSS requirements, which cover handling of sensitive data. Currently, the PCI DSS lists twelve requirements. These requirements are organized around the following principles:

  • Build and maintain a secure network
  • Protect cardholder data
  • Maintain a vulnerability management program
  • Implement strong access control measures
  • Regularly monitor and test networks
  • Maintain an information security policy

Can I choose not to certify for PCI Compliance?

If you choose not to complete the Self-Assessment Questionnaire (and applicable network scans) you may overlook certain data security practices that minimize your risk of a security breach. In the event that your business is compromised, you may be subject to fines of up to $500,000 per payment brand. These fines would be in addition to the expenses and fraudulent transactions resulting from the breach.

In light of the importance that data security has to the payment processing industry and consumers at large, we, as your service provider, may also begin imposing a fee for each month that your account has not been validated as PCI compliant or in any given month your account is deemed non-compliant. Continued failure to validate compliance may result in termination of your merchant account.

How long is PCI Certification valid?

The PCI compliance certification is valid for one year from the date of issue. To maintain your compliance, you are required to complete the PSI DSS Self-Assessment Questionnaire annually and any applicable network scans on a quarterly basis.

How do I get PCI Certified?

Feel free to contact us if you have any questions at all. We can work with you and find out what specifically you will need for compliance. Contact us here with any questions you have.

Where can I find more information about PCI DSS Compliance?

Here is the website for the PCI Security Council if you have any additional questions.

MerchantGuy.com

Documents

API Document
Top 10 Business savings
What merchant account is right?

Info

Employment
Legal
Privacy Policy
News
Logo Center