|
Hello,
Just received the latest editing of Practical Ecommerce. PE is a good little magazine focused on small to medium sized online stores and is published bi-monthly. We happen to have a full page ad in this months edition as a test.
According to John Munsell in his article 'Merchants And Vendors Will Be Held Responsible', Visa alone levied nearly $5,000,000.00 dollars in fines in 2006. So this is a serious subject unless you want to be on the receiving end of a fine ranging from 5 to 25k.
In addition to selecting a shopping cart which complies with PCI/PABA standards, your web host also must meet certain requirements. Such as having a firewall and maintaining a strict access protocol to the server room.
An easy way get your online store PCI certified is by using a service such as ScanAlert. ScanAlert's full-service PCI certification program is $149 per year. Upon completion you are issued a Certification of Compliance accepted by all credit card companies and all banks worldwide.
Everyone is required to follow the rules, however smaller vendors are not required to report their certification if they are doing under 20,000 transactions per year.
Some general background about PCI from http://www.pcicomplianceguide.org/businesscompliance.html
What is Payment Card Industry (PCI) Compliance?
Payment Card Industry (PCI) Compliance is a set of security standards that were created by the major credit card companies (American Express, Discover Financial Services, JCB, MasterCard Worldwide, and Visa International) to protect their customers from increasing identity theft and security breaches.
What are my requirements for PCI Compliance?
The requirements for becoming Payment Card Industry (PCI) Compliant are dependent upon the merchant level that a company falls under. Merchants are divided into four different levels based on the number of transactions they process throughout a year.
Level 1 Criteria Merchants with over 6 million transactions a year Merchants whose data has been compromised
Level 1 Requirements Annual Onsite Security Audit and quarterly network security scan
Level 2 Criteria Merchants with 150,000 to 6 million transactions a year
Level 2 Requirements Annual Self Assessment Questionnaire Quarterly Scan by an Approved PCI Scanning Vendor
Level 3 Criteria Merchants with 20,000 to 150,000 transactions a year
Level 3 Requirements Quarterly Scan by an Approved PCI Scanning Vendor Annual Self Assessment Questionnaire
Level 4 Criteria Merchants with less than 20,000 transactions
Level 4 Requirements No need to report compliance but must maintain compliance.
Kind Regards, Mike Randolph AbleCommerce.com, CEO
|