Everything you need to know about staying compliant and secure when processing credit cards
PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. Compliance is mandatory for all businesses that handle credit card data.
1. Install and maintain firewall configuration
2. Don't use vendor-supplied defaults for passwords
3. Protect stored cardholder data
4. Encrypt transmission of cardholder data
5. Protect systems against malware
6. Develop and maintain secure systems
7. Restrict access to cardholder data by business need
8. Identify and authenticate access to system components
9. Restrict physical access to cardholder data
10. Track and monitor access to network resources
11. Regularly test security systems and processes
12. Maintain a policy that addresses information security
Requires annual on-site security assessment by Qualified Security Assessor (QSA) and quarterly network scans by Approved Scanning Vendor (ASV).
Most stringent requirements and highest penalties for non-compliance
Requires annual Self-Assessment Questionnaire (SAQ) and quarterly network scans by ASV.
May require on-site assessment at card brand's discretion
Requires annual Self-Assessment Questionnaire (SAQ) and quarterly network scans by ASV.
Applies to e-commerce merchants only
Requires annual Self-Assessment Questionnaire (SAQ) and may require quarterly network scans.
Most small businesses fall into this category
Identify all systems that store, process, or transmit cardholder data
Choose the appropriate Self-Assessment Questionnaire based on your business model
Address any gaps in your security controls to meet PCI requirements
Fill out the Self-Assessment Questionnaire honestly and completely
Provide your completed SAQ and any required scan reports to your processor
$5,000 to $100,000 per month until compliance is achieved
Higher transaction fees until compliance is restored
Loss of ability to process credit cards
Responsibility for all costs associated with a security breach
Choose processors that handle PCI compliance for you
Avoid storing credit card information whenever possible
Chip readers provide better security than magnetic stripe
Ensure employees understand security procedures
Install security patches and updates promptly
At Due Diligence Advisors, we understand that PCI compliance can be overwhelming for small business owners. That's why we provide:
Let us help you achieve and maintain PCI compliance with secure, modern payment solutions
Or call us at (754) 441-4490