{"id":194,"date":"2006-10-25T12:04:55","date_gmt":"2006-10-25T19:04:55","guid":{"rendered":"http:\/\/www.merchantaccountblog.com\/archives\/194"},"modified":"2009-01-06T11:51:40","modified_gmt":"2009-01-06T16:51:40","slug":"required-actions-for-pci-compliance","status":"publish","type":"post","link":"https:\/\/www.merchantequip.com\/merchant-account-blog\/194\/required-actions-for-pci-compliance","title":{"rendered":"Required Actions for PCI Compliance"},"content":{"rendered":"<p>If you accept credit card online, this chart is for you. This chart is a simple breakdown of the PCI data compliance levels and requirements. If you accept transactions online, you fall into one of these levels. This chart explains what the requirements are to be in a specific category, and what a merchant must do to remain compliant. <\/p>\n<p>The yearly cost for a level 2, 3 or 4 merchant is around $150, while the yearly cost for a level 1 merchant is more than $30,000. Because of this, it is extremely important not to ever have a data compromise. I personally recommend not storing any sensitive data online, at all, and if it is stored offline, access should be highly restricted and the data should be encrypted. Track data should never be stored anywhere, under any circumstance.<\/p>\n<p>If you have a data compromise and card holder data is stolen, you should expect upwards of $100,000 in fines, arbitration fees, and regulations in addition to the additional cost of level 1 PCI certification.<\/p>\n<table width=\"100%\" border=\"0\" cellspacing=\"0\" cellpadding=\"2\">\n<tr style=\"background:#f99;\">\n<td width=\"75px\" rowspan=\"3\"><b>Level 1<\/b><\/td>\n<td width=\"100px\"><b>Definition:<\/b><\/td>\n<td>\n<ul>\n<li>Over 6 million annual Visa or MasterCard Transactions<\/li>\n<li>Any merchant suffered a hack or attack that resulted in a data compromise<\/li>\n<li>Any merchant that card associations, at their discretion, determine should meet requirements<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"background:#f99;\">\n<td><b>Requirement:<\/b><\/td>\n<td>\n<ul>\n<li>On-site assessment by approved <a href=\"http:\/\/usa.visa.com\/download\/business\/accepting_visa\/ops_risk_management\/cisp_Qualified_Data_Security_Company_List.pdf\">QDSA on Visa&#8217;s website<\/a><\/li>\n<li>Quarterly vulnerability scan by approved scanning vendor<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"background:#f99;\">\n<td><b>Deadline:<\/b><\/td>\n<td>\n<ul>\n<li>September 30, 2004 (1 year for new Level 1 merchants)<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"3\">&nbsp;<\/td>\n<\/tr>\n<tr style=\"background:#fc9;\">\n<td rowspan=\"3\"><b>Level 2<\/b><\/td>\n<td><b>Definition:<\/b><\/td>\n<td>\n<ul>\n<li>Visa: 1M &#8211; 6M annual transactions<\/li>\n<li>MC: 150K &#8211;  6M annual transactions<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"background:#fc9;\">\n<td><b>Requirement:<\/b><\/td>\n<td>\n<ul>\n<li>Self assessment questionnaire and Quarterly vulnerability scan by approved scanning vendor<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"background:#fc9;\">\n<td><b>Deadline:<\/b><\/td>\n<td>\n<ul>\n<li>June 30, 2005 (Sep 30, 2007 for new Level 2 Visa merchants)<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"3\">&nbsp;<\/td>\n<\/tr>\n<tr style=\"background:#ffc;\">\n<td rowspan=\"3\"><b>Level 3<\/b><\/td>\n<td><b>Definition:<\/b><\/td>\n<td>\n<ul>\n<li>Visa: 20K &#8211; 1M annual transactions<\/li>\n<li>MC: 20K &#8211;  150K annual transactions<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"background:#ffc;\">\n<td><b>Requirement:<\/b><\/td>\n<td>\n<ul>\n<li>Self assessment questionnaire and Quarterly vulnerability scan by approved scanning vendor<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"background:#ffc;\">\n<td><b>Deadline:<\/b><\/td>\n<td>\n<ul>\n<li>June 30, 2005<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"3\">&nbsp;<\/td>\n<\/tr>\n<tr style=\"background:#cfc;\">\n<td rowspan=\"3\"><b>Level 4<\/b><\/td>\n<td><b>Definition:<\/b><\/td>\n<td>\n<ul>\n<li>Less than 20K ecommerce or 1M total Visa and MC transactions<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"background:#cfc;\">\n<td><b>Requirement:<\/b><\/td>\n<td>\n<ul>\n<li>Self assessment questionaire and Quarterly vulnerability scan by approved scanning vendor<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"background:#cfc;\">\n<td><b>Deadline:<\/b><\/td>\n<td>\n<ul>\n<li>Dates determined by merchant&#8217;s acquirer<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"3\">&nbsp;<\/td>\n<\/tr>\n<\/table>\n<p><strong>Related Posts:<\/strong><br \/>\n<a href=\"http:\/\/www.merchantequip.com\/merchant-account-blog\/archives\/114\">Scan Alert PCI \/ CISP<\/a><br \/>\n<a href=\"http:\/\/www.merchantequip.com\/merchant-account-blog\/archives\/96\">A Guide to Small Business Security, Free PDF Download\u00e2\u20ac\u00a6<\/a><br \/>\n<a href=\"http:\/\/www.merchantequip.com\/merchant-account-blog\/archives\/95\">CISP, SDP, PCI Compliance required for every business\u00e2\u20ac\u00a6<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you accept credit card online, this chart is for you. This chart is a simple breakdown of the PCI data compliance levels and requirements. If you accept transactions online, you fall into one of these levels. This chart explains what the requirements are to be in a specific category, and what a merchant must [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22,8,1],"tags":[],"class_list":["post-194","post","type-post","status-publish","format-standard","hentry","category-ecommerce","category-fraud","category-merchantaccounts"],"_links":{"self":[{"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/posts\/194","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/comments?post=194"}],"version-history":[{"count":1,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/posts\/194\/revisions"}],"predecessor-version":[{"id":503,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/posts\/194\/revisions\/503"}],"wp:attachment":[{"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/media?parent=194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/categories?post=194"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/tags?post=194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}