Validation on Demand
The PCI standards provides very clear guidelines for assessing compliance. All enterprises with cardholder agreements are required to comply. And to do so, they must ensure that their service providers, i.e. Payment Gateways and Processors, are also compliant.
Are You a Service Provider?
What is less clear, however, is the definition of a ‘service provider’. Certainly, any firm that stores, processes or transmits cardholder data (and is not a merchant) is a service provider. This definition includes Payment Gateways and Payment Processors. Increasingly, security-conscious enterprises are asking third parties that simply manage important controls to also pursue and validate compliance.
This new broader definition of a service provider is good for both the merchants and the service providers. The reason being, it draws important business partners into discussions on security and raises the bar on transparency and communication.
How to Get Validated
If you are a Level 1 service provider, you need an independent assessment and Attestation of Compliance (AOC) to get listed by the major card brands as a validated service provider. Panacea InfoSec is the top independent consultant for service providers. Our reports have always satisfied the requirements set forth by Visa and MasterCard.
If you are a Level 2 service provider (that is, you process fewer than 200,000 transactions annually), you are also required to be fully compliant with the Payment Industries standards, but you have options regarding validation.
The fastest and easiest way may be to complete a Self Assessment Questionnaire (SAQ). Now, you may accomplish this either on your own or with the help of an outside assessor. However, many service providers are now choosing to conduct external assessments so they can file an AOC and be listed by Visa and MasterCard.
Panacea InfoSec encourages you to pick the validation method that is most appropriate for your customers and is the best match for your in-house skill sets. Regardless of your choice, Panacea InfoSec can help.