Frequently Asked Questions about PCI Compliance
What is PCI DSS?
The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements developed by the major credit card companies to enhance credit card data security. All organisations that process, store, or transmit payment card data must be PCI DSS compliant or risk losing their ability to process credit card payments.
From October 2008, any organisation that requires a new merchant ID from the credit card companies must be PCI DSS compliant or use PA DSS compliant applications. By July 1, 2010, all organisations must be PCI DSS compliant to process credit cards.
You may also hear the term, PA DSS. This refers to Payment Application Data Security Standard. The goal of PA-DSS is to help software vendors and others develop secure payment applications that do not store prohibited data, such as full magnetic stripe, other sensitive authentication data or PIN data, and ensure their payment applications support compliance with the PCI DSS. PA-DSS requirements apply to payment applications that are sold, distributed or licensed to third parties.
How do PCI-DSS and PA-DSS affect my organisation?
Each organisation is responsible for its own PCI DSS compliance initiative.
PCI DSS encompasses more than the payment applications used by an organisation. More information about how to become PCI DSS compliant can be found at www.pcisecuritystandards.org.
What do I have to do?
If you currently have a merchant ID, you may not have to do anything until 1st October 2009. However, to be sure, you should call your bank or whoever you use to process credit cards just to be sure. Keep in mind, after 1st October 2009, everyone who processes credit cards will have to be PCI compliant and/or use PA DSS validated products.
What’s a merchant ID?
A Merchant ID (sometimes referred to as an Internet Merchant Account) is provided through a customer’s existing merchant service provider (i.e. acquiring bank, payment vendor, etc.).
What if I don’t have a merchant ID?
If you don’t have a merchant ID, contact your bank or whoever your office plans to use to process credit cards, and apply for a merchant ID.
Keep in mind the new PCI standards go into effect on 1st October 2008. After this date you will have to be PCI compliant to receive a merchant ID.
What if I need major internal system changes that cannot be completed by 1st October 2009?
You need to communicate your concerns with your credit card processor or bank. They may have alternatives that will allow you to process credit cards after 1st October 2009.