Security Audits Mandatory for Online Merchants

NEW YORK — In an effort to streamline the credit card industry’s regulations, adult and mainstream companies that accept credit and debit cards over the Internet must comply with a 12-step security audit starting June 30.

With the new standards, all merchants must be certified under the Payment Card Industry (PCI) Data Security Standards, which were developed by a consortium of major payment card companies.

The PCI standards, which specifically address wireless security, detail "lock down" procedures for data, including data housed by third parties and procedures on how a merchant's computer infrastructure should be configured, maintained and secured.

To receive certification under the standard, all merchants must meet the security requirements, which include:

— Installing and maintaining a firewall;

— Not using default passwords;

— Using strong protection for stored data; Implementing controls that restrict data access to a need-to-know basis;

— Assigning a unique identity authentication to each person accessing computer systems;

— Encrypting cardholder data transmitted over public networks;

— Not storing credit card verification codes;

— Installing and regularly updating anti-virus software;

— Developing and maintaining an information security policy;

— Restricting physical access to cardholder data;

— Monitoring and tracking network resources and cardholder data regularly; and,

— Testing security systems and processes frequently.

The rules affect adult and mainstream Internet companies that offer Visa International, JCB International Credit Card, Diners Club International, Discover, American Express and MasterCard International are part of the consortium. American Express, however, refuses to process online adult charges.

Companies that fail to comply will face fines and other penalties, which include, in some instances, being banned from processing transactions using payment cards.

With the new regulations, most online adult companies will be forced to buy automated compliance tester software. Qualys sells a package for under $500.

The new rules ramp up with large companies that process more than six million transactions a year. Those companies must conduct an annual on-site security audit, a quarterly network scan, and an annual self-assessment questionnaire.

Each card company has implemented its own program under the standard — Visa's is called Cardholder Information Security Program.

Most of the larger credit card companies’ data security programs have been in existence for several years, but it was optional. It became mandatory in 2003, but only for the largest merchants.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Playboy Partners With Creator Platform Tango

Playboy has partnered with creator platform Tango, introducing Playmates to the livestreaming service.

Anti-Porn Senator Introduces Federal Age Verification Bill

U.S. Senator Jim Banks of Indiana, who last month urged the Department of Justice to ramp up obscenity prosecutions, on Wednesday introduced a bill that would make age verification by adult websites federal law.

Orion Expands 'Your Strap-On' Collection From You2Toys Line

Orion Wholesale has added two new sets to the Your Strap-On collection from its You2Toys line.

AEBN Publishes Popular Searches by Country for April, May

AEBN has released the list of popular searches from its straight and gay theaters, by country, for April and May.

Honey Play Box Introduces 'Kai Pro' Stroker

Honey Play Box has debuted its new Kai Pro stroker.

Male Power Featured on 'Saturday Night Live'

Male Power was featured in the season finale of “Saturday Night Live.”

COTR Acquires 'Le Wand,' 'b-Vibe' and 'The Cowgirl' Trademarks

COTR, Inc. has acquired trademark ownership of its flagship brands, Le Wand, b-Vibe, and The Cowgirl.

Kheper Releases Flavored 'All Dicks,' 'All Chicks' Lollipops

Kheper Games has debuted its new All Dicks Penis Suckers and All Chicks Pussy Suckers.

Magic Silk Expands 'Love' Line

Magic Silk has introduced six new styles from its Love line of lingerie.

XBIZ Virtual Pleasure Products Trade Show Set for July 28-30

To facilitate global business between brands and buyers without the need for travel, XBIZ is pleased to reintroduce a virtual edition of its pleasure products events, set for July 28-30.

Show More