The Payment Card Industry developed the PCI Data Security Standard (PCI DSS) in 2004 with the objective of protecting cardholder data and securing the rising tide of credit card transactions.
To ensure this protection, merchants who accept payments by credit card are required to comply with the requirements of the Data Security Standard, which is enforced by the primary payment card brands and banks that process card transactions.
A good degree of flexibility has been built into the process of evaluating a merchant’s security posture in order to provide options for proving compliance with the PCI DSS, ranging from third-party assessments to merchant self-assessments.
The method recommended by the PCI Council for conducting a proper assessment is to employ the services of a Qualified Security Assessor (QSA). A QSA is a firm specializing in data security, cybersecurity, or security compliance that has been qualified by the PCI Council to perform onsite PCI Data Security Standard assessments. QSAs are required to be re-certified every year and are listed on the PCI website. 24By7Security is a Qualified Security Assessor that has assisted numerous merchants and service providers in achieving PCI DSS compliance.
The PCI Security Standards Council also offers multiple options for merchant self-assessment. This blog explores the self-assessment options available through eight Self-Assessment Questionnaires or SAQs.
A Pew Research Center survey in roughly the same timeframe indicated that cash as a payment vehicle is steadily being replaced by credit cards in Americans’ wallets and digital payment apps on their smartphones.
Individual names, credit card numbers, security codes, and other personal cardholder information are transmitted over networks in vast numbers after being scanned and transmitted by all kinds of devices with varying degrees of security.
Not only is merchant compliance with PCI DSS required by processing banks, but compliance is aligned with best security practices and a good idea in today’s hyperactive credit card environment. And there are a number of benefits to be enjoyed by merchants who comply with the PCI Data Security Standard as well.
Self-assessment may not be an option for every merchant who accepts credit card payments for purchases. This is why merchants should contact their processing banks or payment card brands to confirm what type of security assessment and proof of compliance is acceptable to, or required by, that entity.
Individual payment card brands (e.g., Visa, Amex, and others) have the authority to modify compliance requirements, and are also responsible for compliance enforcement, along with the merchant banks who process card transactions.
It’s best to know exactly what their requirements are before you get started. This important first step can prevent a merchant from making the wrong decision and a costly mistake.
For merchants who are eligible to evaluate and document their own compliance, Self-Assessment Questionnaires (SAQs) are tools provided by the PCI Security Standards Council to enable them to measure and assess their compliance with the PCI Data Security Standard, which consists of 12 security requirements.
Two terms are helpful for understanding in reviewing the SAQs. “Card-present” refers to merchants in brick-and-mortar sales environments or stores where a physical card is presented to be scanned or otherwise accepted. “Card-not-present” refers to e-commerce merchants who sell online through websites or merchants who sell or and take orders by mail or telephone, where a physical card is not able to be presented.
The appropriate SAQ for a merchant to use depends on several specifications, as described in the seven most common SAQs below.
The eighth Self-Assessment Questionnaire is known as SAQ D. There is an SAQ D for merchants, and an SAQ D for service providers.
While many merchants and service providers completing SAQ D will need to validate compliance with all 12 PCI DSS requirements, some with highly specific business models may find that certain requirements do not apply.
For example, a merchant who does not use wireless technology is not expected to validate compliance with PCI DSS requirements governing the use of wireless technology. The Self-Assessment Questionnaire Type D provides guidance about the exclusion of other specific requirements as well.
Now that you’ve verified your eligibility to self-assess compliance with the PCI Data Security Standard, and now that you’ve identified the specific Self-Assessment Questionnaire that applies to your payment card environment, what next?
This questionnaire includes a series of Yes/No questions for each PCI Data Security Standard requirement that applies to your business environment. In cases where your answer is No, you may be requested to specify a date by which you will comply with that requirement as well as a brief action plan for achieving compliance. Hence, it may not be necessary to be fully compliant at a given point in time—as long as you have a clear plan to remedy the shortfall.
Following are additional instructions, taken from SAQ A specifically to serve as an example.
Finally, you will submit the Self-Assessment Questionnaire and Attestation of Compliance, along with any other requested documentation, to your merchant bank or payment card brand as per their specific instructions.
Additional requested documentation could include, for example, external vulnerability scans or penetration testing performed by an approved scanning vendor who has the tools to verify compliance with PCI DSS external scanning requirements.
Learn more about the scoping and assessing activities required in Steps 1 and 2 in this PCI DSS blog.
Credit card data flies through the Internet every second of every day, captured and transmitted by credit card scanners, launched by smartphones, and collected by online payment forms. Securing data at every point in the process is not only good business but also a requirement.
Merchant compliance with the PCI Data Security Standard can be achieved through onsite assessments by Qualified Security Assessors, the PCI Council’s preferred method, or through a self-assessment process. Eight Self-Assessment Questionnaires (SAQs) are available to merchants who have confirmed with their processing banks or payment card brands that they are eligible to self-assess.
The PCI Security Standards Council maintains a website that provides a wide array of resources for industry members, including the eight SAQs outlined in this blog. The Council encourages members to effectively protect cardholder data by maintaining robust security programs that comply with the Data Security Standard.