Merchants and Service Providers that store, process, or transmit cardholder data must comply with PCI DSS and the Payment Card Network Compliance Programs. The PCI DSS is enforced by the Payment Card Networks (Visa International, MasterCard Worldwide, American Express, Discover Financial Services, and JCB). Even though certification requirements vary by business and depend on your "Merchant Level" or "Service Provider Level", failure to comply with PCI DSS and the Payment Card Network Compliance Programs may result in a Merchant having to pay fines, fees and/or their processing services terminated.
First Data wants to ensure all its merchants are compliant. Below we are providing data security information and links to assist in assessing the actions your business should take to ensure that it remains compliant.
The PCI Security Standards Council (PCI SSC) is a global forum for the ongoing development, enhancement, storage, dissemination and implementation of security standards for account data protection. The PCI Security Standards Council (PCI SSC) is an independent body founded in September 2006 by the five major credit card networks: American Express, Discover Financial, JCB, MasterCard Worldwide, and Visa International.
The PCI SCC currently manages the following security standards:
The PCI SSC is also responsible for the training and qualification of security assessors and vendors that validate merchant and service provider compliance against these standards. The PCI SSC is not responsible for enforcing compliance to these standards. Enforcement of compliance is managed independently by the Payment Card Networks.
Visit www.pcisecuritystandards.org for more information.
The PCI DSS is a technical and broad-ranging set of security requirements created by the Payment Card Industry, laying out what Merchants need to do to protect customer information. The PCI Council requires that Merchants meet this set of security requirements if their business accepts, transmits or processes customer payment cards, such as credit cards or debit cards. Merchants that do not comply with these requirements can be penalized in a number of ways, up to and including having their card-processing privileges revoked, leaving them unable to accept customer payment cards.
Visit www.pcisecuritystandards.org for more information.
Compliance with the PCI DSS is mandatory. First Data wants to ensure all merchants adopt these standards and remain compliant. If a merchant is not compliant with PCI DSS, the Payment Card Networks could charge the merchant additional fees and fines, and the merchant may no longer be able to process credit card transactions.
Compliance means all requirements of the PCI DSS are met. To become certified, you must engage the services of Qualified Security Assessor "QSA" to validate your compliance to PCI DSS. The QSA will work on identifying areas of non-compliance. You must then remedy each area of non-compliance. Once all areas of non-compliance have been addressed, the QSA will re-evaluate and issue confirmation of compliance. If a merchant chooses to certify, the Certification to PCI DSS is at the merchant's expense.
PCI DSS includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures, intended to help organizations proactively protect customer account data.
Failure to meet the PCI DSS 12 requirements may result in fines or termination of credit card processing privileges. Below are the twelve principle requirements of PCI DSS.
You can find PCI DSS and supporting documentation at www.pcisecuritystandards.org.
All merchants must comply with the PCI DSS regardless of the volume of transactions processed or the method the transactions are processed. That being said, certification requirements vary by business and are contingent upon the "Merchant Level".
https://www.pcisecuritystandards.org/
https://www.visa.ca/en_CA/run-your-business/merchant-resources/merchant-security.html
https://www.mastercard.us/en-us/business/overview.html
https://www.pcisecuritystandards.org/document_library
https://www.pcisecuritystandards.org/assessors_and_solutions/give_assessor_feedback
https://www.pcisecuritystandards.org/assessors_and_solutions/qualified_security_assessors