What is PCI DSS Compliance?

PCI DSS compliance is a requirement for anyone taking or processing payments made by credit or debit card. In this short blog (and video – below) we overview what it’s all about…

What does PCI compliance mean?

To achieve PCI compliance means to meet the standards of the Payment Card Industry Data Security Standard (PCI DSS). This standard contains a set of requirements designed to increase data security and protect merchants and customers when taking and making payments by debit or credit card.

Although the current standard is PCI DSS 3.2.1, the next evolution of the standard is now available: PCI DSS v4.0.

All UK merchants and service providers that process, transmit or store payment card data must be PCI DSS compliant.

For merchants: if you accept payment by debit or credit card for goods or services, you must be PCI DSS compliant, even if you use a third-party organisation or platform to process the payment.

For service providers: if you are involved in processing, storing or transmitting cardholder data on behalf of another party, you must be PCI DSS compliant.

What if you use a payment service provider?

If you use a payment service provider, PCI compliance becomes a shared responsibility between yourself as the merchant and the payment provider.

Using service providers such as Opayo, Stripe, Elavon Sage etc, can help demonstrate you’re PCI compliant, but does not make you fully exempt.

Using a payment service provider will normally mean you, as the merchant, have no need to see or have any access to the card holder’s information. This makes it much easier to meet your PCI compliance requirements, but it does not remove all of the requirements.

What are the consequences of not achieving PCI compliance?

The main consequence of not being PCI compliant is that you may not be protecting cardholder data. This means you could be responsible for a breach and that could be enormously costly for your business and your customers.

A data breach could result in both financial and identity theft from your customers. This will need to be reported to the Information Commissioner (and your customers) and you could be liable to financial penalties that could be significant under the GDPR (General Data Protection Regulation), as well as the card brands.

Even in the absence of a breach, failure to be PCI DSS compliant means you are likely to be liable for fines and additional transaction charges from your bank. They may also withdraw the facility to take payment by credit and debit card if you continue to be non-compliant.

How do I go about becoming compliant?

Securious is a PCI QSA (Qualified Security Assessor) Company. This means we are independent security organisation that has been qualified by the PCI Security Standards Council to validate an organisation’s compliance with PCI DSS and can advise you on what you will need to do.

For more information from one of our Exeter-based PCI specialists, just fill in the contact form below, email pci@securious.co.uk or call 01392 247 110 to find out more.

 

More information:

  1. Read our ‘Ultimate Guide to PCI Compliance’
  2. Learn more about our services as a PCI QSA company