What Is PCI DSS Compliance?
Payment Card Industry (PCI) Data Security Standard (DSS) is something that every merchant who accepts credit cards needs to know about. Failure to adhere to the standards can expose you to significant financial liability as well as have your merchant and gateway accounts shut done.
The PCI security standards are a blanket of regulations set in place to safeguard payment account data security. Essentially, they define the best practices for storing, transmitting, and handling of sensitive information over the internet. Compliance is mandated by the payment card brands (Visa, MC, Discover, etc) and not by the PCI Security Standards Council. The standard is set by the PCI Security Standards Council.
For most existing merchants, the deadlines for validating compliance with the PCI DSS have already passed. You should check with your acquirer and/or merchant bank to check if any specific deadlines apply to you, based on merchant transaction volume (level) as determined by the card payment brands. All entities that transmit, process or store payment card data must be compliant with PCI DSS. This includes your shopping cart system if using a 3rd party, hosting environment, and even your own business practices around the storing and archiving of customer payment information.
Most credit card processors will send you a questionaire that needs to be filled out about your online business and depending on the answer will determine the steps necessary to be compliant. The more exposure you provide (ie higher sales, type of payment capture, etc) typically the more stringent of processes needs to be in place. For smaller merchants a security scan may be required, quarterly, monthly or even daily. The final requirements will come from your payment processor and will differ from business to business. Be sure to ask your payment processor what steps are required to make sure you are in compliance.
For more information, you should visit The Payment Card Industry website, as well as contact your respective payment processor.






Leave a Comment