3 ms·
"His company, Gravity Payments, which he set up in his teens"... I'd LOVE to see how a TEENAGER was able to go through the PCI-DSS certification process and PAS
by earwetr 7y ago
"His company, Gravity Payments, which he set up in his teens"... I'd LOVE to see how a TEENAGER was able to go through the PCI-DSS certification process and PASS the D-level.
- jschwartzi 7y agoIt’s possible PCI-DSS didn’t exist back then. DSS has only been around since 2004.
- C12H22O11 7y agoHere is v1.0 of PCI-DSS from December 2004, same year this company was founded. Doesn't seem very difficult to comply with, it is essentially 'Use a firewall and antivirus and don't use the default password' http://ftp.freenet.at/mar/PCI_data_security_standard.pdf http://ftp.freenet.at/mar/PCI_data_security_standard.pdf
- earwetr 7y agonow compare with https://www.pcisecuritystandards.org/documents/PCI-DSS-v3_2_1-SAQ-D_Merchant.pdf https://www.pcisecuritystandards.org/documents/PCI-DSS-v3_2_...
- earwetr 7y agomost likely true. these days you have to be a well funded company that has enough cash to jump through the hoops. the cost of entry these days is astronomical. hence very few players on the market.
- ska 7y agoregulatory capture?