The Payment Card Industry (PCI) Security Standards Council (SSC) introduced an updated compliance framework to support the payment card industry going into effect on March 31, 2024. We have published E-Focus articles with details on the overall changes and the SAQ changes.
We recommend any organization accepting credit cards take the time to verify compliance. Even organizations with fully “outsourced” credit card processing using a service provider, you still have some compliance requirements. For instance, a website sending the cardholder to a 3rd party (service provider) website to submit the payment, the organization still has to meet 29 controls (SAQ A) mainly addressing policies, inventories, and documentation.
If your organization accepts credit cards in any way, we recommend you:
The PCI requirements seem complicated and can be confusing. Breaking them down into the tasks above, with a focus on the required scope of compliance, you can simplify the process.
Documenting the information above helps justify the specific SAQ in use, provides management the assurance the organization is protecting credit card data, and documents the environment in case there is an issue or incident.
If you have any questions about this article or have questions about assessing your credit card compliance, please reach out to RubinBrown.
Published: 9/11/2023
Readers should not act upon information presented without individual professional consultation.
Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.