Compliance
In addition to this year's requirement for your business to certify to its level (1-4) of Merchant compliance with the Payment Card Industry Data Security Standard (PCI-DSS), two new requirements have been added. They include:
The Payment Application - Data Security Standard (PA-DSS) requires that any software that stores, processes or transmits credit card data must be PA-DSS certified by July 1, 2010. Coupled with this, as a merchant, if you use a software product to store, process or transmit credit card data, then effective July 1, 2010, when asked by your Merchant Acquirer (credit card processor), you must validate that the software you are using is PA-DSS certified.
The Payment Card Industry - PIN Entry Device (PCI-PTS) requires all PIN terminal manufacturers to ensure their PIN Entry Devices are PCI-PTS compliant by July 1, 2010. Coupled with this, as a merchant, if you are using a PIN Entry Device to process debit card transactions, then effective July 1, 2010,, when asked by your Merchant Acquirer (credit card processor), you must validate that the terminal you are using is PCI-PTS compliant.
Merchant Acquirers (like Sage Payment Solutions) are required to ensure that these new requirements are validated this year, in addition to ensuring all merchants meet their annual PCI-DSS certification.
Please select a topic below to learn more: