Bargain service. Although a nighmare of a field to be in. The basics of pci compliance often arent made clear (hence it took me several days to dig through all the information a few months back when the pci compliance form was put on my desk) There are four levels and depending on where your company falls determines at what level you have to be 'pci compliant'
Level 1: Any merchent processing over 6,000,000 transactions a year, any merchant that has been subject to hacking. Or any merchant that visa says so.
Annual onsite security audit: Required
Quarterly system perimeter scan: Required
Annual compliance questionaire: Required
Level 2: Any merchent processing between 150,000 and 6,000,000 e-commerce transactions per year
Annual onsite security audit: Not Required
Quarterly system perimeter scan: Required
Annual compliance questionaire: Required
Level 3: Any merchent processing between 20,000 and 150,000 e-commerce transactions per year
Annual onsite security audit: Not Required
Quarterly system perimeter scan: Required
Annual compliance questionaire: Required
Level 4: Any merchent processing fewer than 20,000 e-commerce transactions per year and all merchents processing upto 6,000,000 transaction per year (offline)
Annual onsite security audit: Not Required
Quarterly system perimeter scan: Recommended
Annual compliance questionaire: Recommended
It also needs to be clear that pci compliance if for merchants ie you have a merchant number. This doesn not apply if you are using a third party payment system such as paypal, worldpay, etc etc because they are the mechant (they need to do it).


LinkBack URL
About LinkBacks


Reply With Quote