Security Audits Mandatory for Online Merchants

NEW YORK — In an effort to streamline the credit card industry’s regulations, adult and mainstream companies that accept credit and debit cards over the Internet must comply with a 12-step security audit starting June 30.

With the new standards, all merchants must be certified under the Payment Card Industry (PCI) Data Security Standards, which were developed by a consortium of major payment card companies.

The PCI standards, which specifically address wireless security, detail "lock down" procedures for data, including data housed by third parties and procedures on how a merchant's computer infrastructure should be configured, maintained and secured.

To receive certification under the standard, all merchants must meet the security requirements, which include:

— Installing and maintaining a firewall;

— Not using default passwords;

— Using strong protection for stored data; Implementing controls that restrict data access to a need-to-know basis;

— Assigning a unique identity authentication to each person accessing computer systems;

— Encrypting cardholder data transmitted over public networks;

— Not storing credit card verification codes;

— Installing and regularly updating anti-virus software;

— Developing and maintaining an information security policy;

— Restricting physical access to cardholder data;

— Monitoring and tracking network resources and cardholder data regularly; and,

— Testing security systems and processes frequently.

The rules affect adult and mainstream Internet companies that offer Visa International, JCB International Credit Card, Diners Club International, Discover, American Express and MasterCard International are part of the consortium. American Express, however, refuses to process online adult charges.

Companies that fail to comply will face fines and other penalties, which include, in some instances, being banned from processing transactions using payment cards.

With the new regulations, most online adult companies will be forced to buy automated compliance tester software. Qualys sells a package for under $500.

The new rules ramp up with large companies that process more than six million transactions a year. Those companies must conduct an annual on-site security audit, a quarterly network scan, and an annual self-assessment questionnaire.

Each card company has implemented its own program under the standard — Visa's is called Cardholder Information Security Program.

Most of the larger credit card companies’ data security programs have been in existence for several years, but it was optional. It became mandatory in 2003, but only for the largest merchants.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Inside the Impact of New AV Laws on Sex Toy Ecommerce

Over the past few years, age verification (AV) has gone from a niche policy discussion to a very real, very immediate concern for anyone operating in the adult space.

Report: Irish Justice Minister Seeks UK-Style Ban on 'Extreme' Content

Ireland’s justice minister plans to introduce legislation criminalizing possession and distribution of “extreme” pornography, according to a report by the Irish Independent.

Orion Debuts New Styles From 'Svenjoyment' Line

Orion Wholesale has released three new styles from its Svenjoyment undergarment line.

New Kickstarter Rules Ban Fundraising for Adult Content, Products

Crowdfunding platform Kickstarter has posted new “Mature Content” rules banning projects that involve adult content and sextech.

Full Circle Expands Enhancements Collection

Full Circle has expanded its collection of performance enhancers.

WebGroup Czech Republic Settles Florida AV Suit, Will Pay $1.2 Million

WebGroup Czech Republic (WGCZ), the parent company of XVideos, XNXX, BangBros and GirlsGoneWild, has settled a lawsuit filed by the state of Florida over those sites’ alleged failure to age-verify Florida users before allowing access to adult content.

Screaming O Debuts New 'Rechargeable Rings' Collection

Screaming O has introduced its new collection of rechargeable, vibrating cock rings.

AEBN Publishes Popular Searches for March, April

AEBN has published the top search terms for March and April from its straight and gay theaters in all 50 states and the District of Columbia.

Ofcom Investigates Two Sites Over Possible AV Violations

U.K. media regulator Ofcom on Wednesday launched investigations into two adult sites as part of its age assurance enforcement program under the Online Safety Act (OSA).

Orion Debuts 'Panthera Double' Dildo From 'Beastly Cocks' Line

Orion Wholesale has introduced the new Panthera Double dildo from its Beastly Cocks line.

Show More