Choosing a payment provider involves more than comparing features and pricing. It's also about trusting that your customers' payment information is being handled securely. Every August, Segpay is recertified as a Level 1 PCI-compliant service provider, a milestone the company has achieved for the past 20 years. Having helped write Segpay's original PCI policy documents more than two decades ago, I've seen firsthand how PCI compliance has evolved.
This month, we'll explore how PCI compliance has changed over the years, what merchants should expect today and why it matters.
Don't assume your payment processor is PCI compliant simply because it processes payments. A PCI-compliant processor should have the appropriate policies and controls in place to protect cardholder data. It should also be able to demonstrate compliance through independent assessments and regular audits.
What Is PCI Compliance and How Has it Evolved?
In 2004, the major card brands came together to establish a unified framework to protect cardholder data and reduce payment fraud. Before PCI DSS, each card brand maintained its own security requirements, creating unnecessary complexity and inconsistency. Today, the unified framework provides a standardized set of security requirements and a common language for acquiring banks, payment processors, payment facilitators and technology providers.
The original PCI 1.0 standard focused on secure networks, protecting stored cardholder data, encryption in transit, secure systems, access restrictions, monitoring, testing and written security policies. Fraudsters never quit, which means security procedures must continually evolve.
There have been several generations of PCI. We're currently using PCI DSS 4.0, which is designed for today's complex environments, including cloud infrastructure, mobile applications, software-as-a-service platforms and remote workforces. This latest version emphasizes strong authentication and access management, security awareness and training, secure development practices, protection of cloud and virtualized environments, ongoing validation of security controls and heightened awareness of payment page threats. Maintaining all of this can sometimes feel like preparing for a PCI audit every day.
Is My Payment Processor PCI Compliant?
Don't assume your payment processor is PCI compliant simply because it processes payments. A PCI-compliant processor should have the appropriate policies and controls in place to protect cardholder data. It should also be able to demonstrate compliance through independent assessments and regular audits.
PCI compliance isn't handled solely by your payment processor. Service providers also have significant PCI responsibilities, and many acquiring banks require merchants to complete the PCI DSS SAQ A (Self-Assessment Questionnaire).
What Happens Between Annual Audits?
While the PCI assessment takes place annually, preparation begins the day the audit ends. Organizations must demonstrate every day that their security controls are working as intended. PCI DSS 4.0 focuses on continuous validation rather than simply preparing for an annual assessment. The goal is to keep pace with fraudsters, who are constantly adapting as payment systems become more secure.
How Does PCI Protect My Business?
Working with a PCI-compliant service provider offers several benefits. Consumers are more likely to trust businesses that invest in strong payment security. PCI DSS helps safeguard card information, expiration dates and other sensitive personal data, such as email and mailing addresses. Following PCI requirements also reduces opportunities for criminals to steal payment information and commit fraud.
While no security standard can eliminate every cyber risk, PCI DSS requires organizations to maintain security controls that help detect, contain and respond to attacks more quickly, reducing the impact of a potential breach. It also helps build confidence that businesses are following recognized security practices and treating customers' payment information responsibly.
Organizations with stronger security practices are generally better prepared to prevent or recover from cyberattacks, resulting in fewer service disruptions. Working with a PCI-compliant provider can also provide peace of mind for both businesses and consumers. Even though most customers never see what happens behind the scenes, PCI compliance helps make everyday card transactions more secure.
What Should My Payment Processor Be Doing?
Behind the scenes, your payment processor should be continuously monitoring its systems, validating security controls, applying updates, testing for vulnerabilities and documenting compliance. As mentioned earlier, PCI DSS 4.0 places greater emphasis on ongoing security than simply passing an annual audit. Today, PCI compliance is part of an overall security strategy rather than a once-a-year certification.
What is My Responsibility as a Merchant?
Merchants play an important role in PCI compliance, too. Complete the PCI DSS SAQ A when required, use strong passwords, keep your software up to date and train employees on security best practices. Don't be afraid to ask questions, either. When was your payment processor's last PCI assessment? How is cardholder data protected? What happens if a vulnerability is discovered?
Organizations that properly implement PCI controls are better equipped to prevent common attacks and minimize the impact if one does occur. For consumers, that means a lower risk of payment card theft and fraud, and less inconvenience from replacing compromised cards or disputing unauthorized charges.
If you're unsure whether your payment provider is PCI compliant, you can verify it through Visa's Global Registry of Service Providers.
Cathy Beardsley is president and CEO of Segpay, a merchant services provider offering a wide range of custom financial solutions, including payment facilitation, direct merchant accounts and secure gateway services. Under her direction, Segpay has become one of four companies approved by Visa to operate as a high-risk internet payment services provider. For questions or help, contact sales@segpay.com or compliance@segpay.com.