If you process credit cards, your organization must meet PCI compliance standards.
PCI compliance scanning is required for any company that deals with credit card information, even if that information is only used for processing transactions and never stored on site or in any kind of database. Data Security Standards were created by the Payment Card Industry to help protect consumers, businesses, and the credit card companies themselves against the threat of system intrusion and credit card fraud. Getting and maintaining PCI compliance is not a one time event, but a process that requires the help of a specialized partner like ServerScan to manage certain parts of that process.
New to PCI compliance? Start with our PCI Compliance 101 guide for a quick overview of what PCI DSS is and why it matters before diving into the steps below.
Step One - Do I Need To Be PCI Compliant?
It is a common misconception that businesses do not need to meet compliance standards if they do not store credit card data, or that only large companies need to worry about PCI standards. These oft-repeated ideas expose your customer's private data to breach and your company to legal liability.
If you accept any of these cards, you must be PCI compliant:
Some US states and other jurisdictions impose additional legal requirements and penalties related to compliance with the data security standards (DSS).
Step Two - How Do I Become PCI Compliant?
Different credit card companies have different classifications for things like merchant levels, so you may find it easier to focus on what you need to do rather than what level you are. If you want to know your level anyway, here's a quick breakdown based on how many transactions you process annually:
- Quarterly Scans + Self-Assessment
Any credit card transactions (Visa, Mastercard, Discover, American Express, JCB). - Quarterly Scans + Self-Assessment + Validated Submission
20,000+ transactions (Visa, Mastercard, Discover). 50,000+ transactions (American Express). - Quarterly Scans + Accredited Self-Assessment + Validated Submission
1 million+ transactions (Visa, Mastercard, Discover). - Quarterly Scans + On-Site Assessment + Validated Submission
6 million+ transactions (Visa, Mastercard, Discover). 2.5 million+ transactions (American Express). 1 million+ transactions (JCB).
Credit card processors may increase security requirements for businesses that they deem to be high risk, especially if those businesses have been compromised in the past.
Step Three - Set Up Quarterly Scans
Your website needs ASV (Approved Scanning Vendor) scans at least quarterly to meet DSS requirements. PCI scanning tests for known exploits or vulnerabilities. If any are found, your scan will let you know where your security is weak and what needs to be done to fix any issues. Quarterly scans are required, but you can use ServerScan to scan your website more frequently (as much as every day). There is no extra charge for scanning more frequently, and you may choose to scan more frequently than once per quarter depending on your organization's security needs.
Step Four - Complete Your Self Assessment
All merchants must complete a self-assessment questionnaire (SAQ). Depending on your classification, you will complete one of several SAQ versions: A, A-EP, B, B-IP, C, C-VT, P2PE, SPoC, D-Merchant, or D-Service Provider. See our Which SAQ Form Should I Use? guide for details on which applies to you.
Form A - Merchants who accept only card-not-present (E-commerce, mail, or telephone) transactions, and exclusively use outsourced service providers to collect, handle, and process credit card data functions. If your servers ever receive or send credit card information, then this form is NOT for you. This form is intended for organizations that have fully outsourced all cardholder data processing to PCI DSS validated third parties and retain no electronic storage, processing, or transmission of cardholder data on their own systems.
Form B - Card transactions from a dial-out terminal or via credit card imprint machine. No electronic card data storage. This form is generally for brick-and-mortar or mail/telephone businesses. This form is not for any business that has payment systems connected to the internet. Form C - Payment application systems connected to the internet. No electronic card data storage.
Form C-VT - Web-based virtual terminal transactions only. No electronic card data storage. This form is for merchants who only manually enter a single transaction at a time into a web-based virtual terminal which is hosted by a 3rd-party service provider. The computer accessing the virtual terminal must be on a dedicated private network, isolated from your other computers. Cardholder data is not otherwise received or transmitted electronically. Merchants who use this payment configuration are generally brick-and-mortar or mail/telephone businesses with relatively low transaction volumes.
Form D - Any other merchant or service provider. If you store cardholder data electronically (not recommended unless absolutely necessary) this is the form you should use.
Inside your ServerScan account, you will find links to all of the most recent PCI SAQ forms for your convenience.
Ready to get started?