3 ms·
I used to work as a low-level tech for one of the largest PCI compliance providers. For smaller merchants (I think less than 20k? transaction per year) there's
by airlocksoftware 15y ago
I used to work as a low-level tech for one of the largest PCI compliance providers. For smaller merchants (I think less than 20k? transaction per year) there's 4 levels of compliance: A, B, C, and D.
A is for merchants who redirect to another site or use an iframe (like paypal). B is for merchants who use a dial up terminal. C is for any merchant who accepts credit card information electronically (i.e. an internet connected terminal or a website with no redirect / iframe). D is for anyone who stores credit card information.
A & B just require you to fill out a self-assessment indicating you're aware of the rules and following them. C & D both require "scans", probably of your website or server (at least a couple hundred dollars, if not more).
- lsh123 15y agoI am not familiar with A/B/C/D levels but PCI spec clearly defines PCI 1-4 levels based on volume/number of payments: http://www.pcicomplianceguide.org/pcifaqs.php#5 http://www.pcicomplianceguide.org/pcifaqs.php#5
- airlocksoftware 15y agoAh, yes. What I'm talking about above applies to level 4 merchants, (less than 20k ecommerce transactions), who can get away with lower level compliance. The ABCD levels refer to the self assessment questionnaires (SAQ) these level 4 merchants are required to completed. https://www.pcisecuritystandards.org/security_standards/documents.php?category=saqs https://www.pcisecuritystandards.org/security_standards/docu...
- lsh123 15y agoI guess I never bothered to look at anything below level 1 :)