If your business accepts credit cards then this affects you and it affects you right now!
If you accept credit or debit cards then your business MUST adhere to PCI Compliance standards. If you are not currently in compliance, or even worse, if you are reading about this for the first time, you are at the right place. Click the
free sign up button above and get PCI Compliance scanning from the world's leading security certification service provider
at no charge (
a $319 value).
PCI Compliance is a joint effort of the five major credit card companies; Visa, MasterCard, American Express, Discover Card and JCB International. This initiative is a cooperative effort to avoid governmental regulation by establishing self-regulation policies and procedures.
All this became especially important upon the recent disclosure that TJX Companies Inc did not follow all the PCI Compliance Standards. TJX revealed in March 2007 that hackers compromised at least 45.7 million credit and debit cards. From July 2005 until the discovery in December 2006, the bandits penetrated what was thought to be a secure network environment. The SEC filing also disclosed that another 455,000 customers, who had returned merchandise, had their driver's licenses stolen.
Don't be complacent! Hackers have all the incentive they need to compromise any size business that is vulernable. This is why these standards apply to every business that accepts credit or debit cards. Your potential liablity from hacker attacks will be exascerbated if you are not PCI Compliant. Payment card companies and aquiring banks will be actively monitoring these requiements for their protection and for your protection.
Compliance validation requirements are based on the total annual number of transactions, the potential risk and exposure introduced into the payment system by merchants and service providers.
|
Merchant Definition
|
Annual Transaction Level
|
Compliance Validation Reporting Requirements
|
|
Level 1
|
- Merchants with more than 6 million transactions a year
- Merchants whose data has been compromised
|
- Pass quarterly scan by an authorized scanning vendor
- Annual onsite audit by Qualified Data Security Company
|
|
Level 2
|
- Merchants with 150,000 to 6 million transactions a year
|
- Pass quarterly scan by an authorized scanning vendor
- Annual self-assessment questionnaire by merchant
|
|
Level 3
|
- Merchants with 20,000 to 150,000 transactions a year
|
- Pass quarterly scan by an authorized scanning vendor
- Annual self-assessment questionnaire by merchant
|
|
Level 4
|
- Merchants with less than 20,000 transactions a year
|
- Reporting of compliance to Acquiring Bank not required, however compliance is required.
|