PCI DSS is the leading security standard for safeguarding cardholder data from breaches, but its strict requirements can make certification feel overwhelming, especially for first-timers.
Where do you start? What policies and controls are necessary? And if an audit is required, how can you be sure youโre ready?
By understanding the PCI certification process, you can better prepare for a successful audit or self-assessment. To help, weโll break down each step of the process below.
Identify the level of compliance needs
PCI DSS has varying levels depending on the organization size, number of transactions, and customer size.
Complete a readiness assessment
After implementing controls, undergo a readiness assessment with a company specialised in PCI DSS
Complete an SAQ or RoC
A Self assessment Questionnaire or Report on Compliance is required – depending on your level of compliance
Maintain Certification
To maintain compliance, complete SAQ or RoC annually.
Meet with Matt and book a free 15-min call below to
better understand how to implement PCI DSS compliance in your company
Organization Size
2. Annual Credit Card Transactions
3. Requirements from Customers or Acquiring Banks
The first step toward certification is identifying your required compliance level.
Typically, the entity requesting your complianceโwhether customers, acquiring banks, or credit card companiesโwill specify if you need to complete a Report on Compliance (RoC) or a Self-Assessment Questionnaire (SAQ).
If no specific request is made, use these guidelines to determine your compliance level.
Step 1: Are you a merchant or a service provider?
โข Merchants accept card payments in exchange for goods or services, like e-commerce businesses.
โข Service Providers process payments on behalf of other companies.
Step 2: Determine your annual transaction volume.
For merchants:
โข Level 1: Over 6 million transactions
โข Level 2: 1-6 million transactions
โข Level 3: 20,000 - 1 million transactions
โข Level 4: Fewer than 20,000 transactions
For service providers:
โข Level 1: Over 300,000 transactions
โข Level 2: Fewer than 300,000 transactions
Organizations at Merchant Level 1 and Service Provider Level 1 must complete a PCI-RoC. If you do not meet these criteria, an SAQ is required.
The SAQ consists of two main components:
1. A set of self-guided questions assessing your compliance level.
2. An Attestation of Compliance (AoC), in which you confirm your qualification and completion of the SAQ.
In some cases, depending on your compliance level, a Qualified Security Assessor (QSA) firm may be needed to attest to your SAQ results.
To prepare for an assessment, ensure that all necessary policies, procedures, and controls are established and consistently followed throughout the audit period. Additionally, youโll need to conduct an ASV scan and a penetration test.
At this stage, many organizations choose to complete a readiness assessment with a Qualified Security Assessor (QSA) or with Benchmarked. This PCI DSS expert will evaluate whether your scope, controls, and processes are audit-ready.
If you are a Level 1 Merchant or Service Provider, youโre required to complete an annual Report on Compliance (RoC). This is an external audit performed by a QSA. The QSA will review your policies, processes, controls, and evidence to decide if you meet PCI DSS requirements.
If you do not need a Report on Compliance (RoC), youโll fill out an SAQ. This questionnaire covers each requirement, the expected testing, and asks if the control is:
In place
In place with a compensating control (Compensating controls may be considered when an entity cannot meet a requirement explicitly as stated, due to legitimate technical or documented business constraints, but has sufficiently mitigated the risk associated with the requirement through implementation of other controls.)
Not in place
N/A
Not tested
Both the RoC and AoC are valid for one year. To maintain certification, youโll need to complete an RoC or SAQ and AoC annually.
Here are some other periodic tasks youโll need to plan on throughout the year to maintain your PCI certification:
Embarking on the PCI compliance journey requires a structured approach. Here are five essential steps to guide your business to successful adherence.
Determine if PCI DSS applies to your business by assessing how you handle cardholder data and transactions.
Educate your team on the importance of PCI compliance and cybersecurity best practices to ensure secure cardholder data handling.
Implement necessary technical and operational safeguards, such as firewalls, encryption, and access controls, to meet PCI DSS standards.
Assign dedicated personnel, tools, and budget to manage PCI compliance, ensuring all requirements are met efficiently.
Regularly audit and test your systems to maintain compliance, addressing any vulnerabilities and staying updated with PCI requirements.
Meet with Matt and book a free 15-min call below to better understand how to implement PCI DSS compliance in your company
Curated by PCIcompliant.org, this page provides publicly-sourced information on everything related to the PCI DSS Directive. Presented in a clear and concise manner for easy consumption.
Disclaimer
The information provided on this website is intended for educational and informational purposes only. The content is not intended to be a substitute for professional advice or any other legal advisory, service, etc. The site’s administrators and contributors make no representations or warranties of the information on the site. Any reliance you place on such information is therefore strictly at your own risk.
Copyright By PCIcompliant.org