Skip to content
English
  • There are no suggestions because the search field is empty.

PCI-DSS and Credit Card Security

If you offer credit cards as a payment option to your customers, you must comply with additional security rules from the credit card companies.

These rules are laid down in the Payment Card Industry – Data Security Standard (PCI-DSS) and are intended to prevent customer or card data from being stolen or misused. If card data falls into the hands of third parties, it can be resold and subsequently used to make purchases on legitimate websites.


PCI Compliance Levels

Based on their annual transaction volume, merchants are classified into different PCI compliance levels:

  • Level 1: More than 6 million card transactions per year
  • Level 2: 1 to 6 million card transactions per year
  • Level 3: 20.000 to 1 million e-commerce transactions per year
  • Level 4: Less than 20.000 e-commerce transactions per year

PCI-DSS Validation Requirements

Level Requirements
Level 1 Annual Report on Compliance (ROC) by a Qualified Security Assessor (QSA) or internal auditor; Attestation of Compliance (AOC); Quarterly scans by an Approved Scanning Vendor (ASV)
Level 2 Annual Self-Assessment Questionnaire (SAQ); Attestation of Compliance (AOC); Quarterly scans by ASV
Level 3 Annual SAQ; Attestation of Compliance (AOC); Quarterly scans by ASV
Level 4 Annual SAQ; Quarterly scans by ASV

Use of the PAY Payment Screen

If you use the standard PAY payment screen, you must also comply with the PCI-DSS rules of the credit card companies. Insufficiently secured techniques can lead to theft of card data, for example if customers are directed to a page belonging to a third party instead of to PAY.

Using the PAY payment screen significantly reduces the effort required compared to processing card data yourself on your own platform.

Important: Merchants who use the PAY payment screen must annually complete a SAQ-A. A sample pre-filled SAQ-A is available and applies to most e-commerce merchants who use the PAY payment screen. All questions must be answered carefully.


Non-compliance

If you cannot demonstrably comply with the rules of the credit card companies (non-compliant), they can hold you accountable and impose fines. This also applies to violations of the PCI-DSS standards.

  • Investigations usually start after reports, but random checks can also take place.
  • If card data is misused and can be traced back to your business, you must be able to provide evidence that you comply with PCI-DSS.
  • If this cannot be demonstrated, fines may be imposed.