PCI-DSS and Credit Card Security
If you offer credit cards as a payment option to your customers, you must comply with additional security rules from the credit card companies.
These rules are laid down in the Payment Card Industry – Data Security Standard (PCI-DSS) and are intended to prevent customer or card data from being stolen or misused. If card data falls into the hands of third parties, it can be resold and subsequently used to make purchases on legitimate websites.
PCI Compliance Levels
Based on their annual transaction volume, merchants are classified into different PCI compliance levels:
- Level 1: More than 6 million card transactions per year
- Level 2: 1 to 6 million card transactions per year
- Level 3: 20.000 to 1 million e-commerce transactions per year
- Level 4: Less than 20.000 e-commerce transactions per year
PCI-DSS Validation Requirements
| Level | Requirements |
|---|---|
| Level 1 | Annual Report on Compliance (ROC) by a Qualified Security Assessor (QSA) or internal auditor; Attestation of Compliance (AOC); Quarterly scans by an Approved Scanning Vendor (ASV) |
| Level 2 | Annual Self-Assessment Questionnaire (SAQ); Attestation of Compliance (AOC); Quarterly scans by ASV |
| Level 3 | Annual SAQ; Attestation of Compliance (AOC); Quarterly scans by ASV |
| Level 4 | Annual SAQ; Quarterly scans by ASV |
Use of the PAY Payment Screen
If you use the standard PAY payment screen, you must also comply with the PCI-DSS rules of the credit card companies. Insufficiently secured techniques can lead to theft of card data, for example if customers are directed to a page belonging to a third party instead of to PAY.
Using the PAY payment screen significantly reduces the effort required compared to processing card data yourself on your own platform.
Important: Merchants who use the PAY payment screen must annually complete a SAQ-A. A sample pre-filled SAQ-A is available and applies to most e-commerce merchants who use the PAY payment screen. All questions must be answered carefully.
Non-compliance
If you cannot demonstrably comply with the rules of the credit card companies (non-compliant), they can hold you accountable and impose fines. This also applies to violations of the PCI-DSS standards.
- Investigations usually start after reports, but random checks can also take place.
- If card data is misused and can be traced back to your business, you must be able to provide evidence that you comply with PCI-DSS.
- If this cannot be demonstrated, fines may be imposed.