PCI Compliance

What is PCI Compliance?

Payment Card Industry (PCI), is comprised of Visa, Mastercard, American Express, and other leading card brands. 

Collectively, they require financial service providers, banks, and merchants accepting cards to follow strict security guidelines.

These guidelines include: 

 – Building and maintaining a secure network

 – Protecting cardholder data

 – Maintaining a vulnerability management program

 – Implementing strong access control measures

 – Regular monitoring and testing of networks

 – Maintaining an information security policy

Does PCI compliance apply to my business?

PCI (Payment Card Industry) DSS (Data Security Standards) compliance standards apply to any organization or business who accepts, transmits, or stores card holder data.

If your business accepts credits cards as a form of payment for goods or services, your business needs to be PCI compliant.

What is Cardholder Data?

Cardholder Data is any and all information that can be linked to the identity of a cardholder.

Information like someones name, address, & card number can be used to identify the cardholder.

Any information associated with a cardholder that is stored, processed, or transmitted is considered cardholder data.

Cardholder data can be transmitted with each card transaction, find out more on the PCI SSC’s website here.