{"id":43,"date":"2010-11-21T20:17:43","date_gmt":"2010-11-21T20:17:43","guid":{"rendered":"urn:uuid:1c7f60e7-07eb-47b2-9933-33d8302e0055"},"modified":"2017-06-13T20:02:56","modified_gmt":"2017-06-13T20:02:56","slug":"pci-dss-compliance-the-basics","status":"publish","type":"post","link":"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/","title":{"rendered":"PCI DSS Compliance: The Basics"},"content":{"rendered":"\t<p><strong>What is <span class=\"caps\">PCI<\/span> <span class=\"caps\">DSS<\/span> Compliance?<\/strong><\/p>\n\n\t<p>Over the years, retailers have lost millions of dollars to fines and in compensation to customers as a result of compromised credit cards and personal information. These losses, moreover, do not take into account the hidden costs of lost sales and damage to merchant brands. In response to this increase of credit card hackers and thieves, American Express, Discover Financial Services, <span class=\"caps\">JCB<\/span> International, MasterCard Worldwide, and Visa Inc came together in 2006 to launch a global forum called the <span class=\"caps\">PCI<\/span> Security Standards Council. Together they developed the Payment Card Industry Data Security Standard (<span class=\"caps\">PCI<\/span> <span class=\"caps\">DSS<\/span>) requirements.<\/p>\n\n\t<p>According to the <a href=\"https:\/\/www.pcisecuritystandards.org\/security_standards\/documents.php?category=standards\"><span class=\"caps\">PCI<\/span> Security Standards Council<\/a> website, &#8220;The <span class=\"caps\">PCI<\/span> <span class=\"caps\">DSS<\/span> is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organizations proactively protect customer account data.&#8221;<\/p>\n\n\t<p><span class=\"caps\">PCI<\/span> <span class=\"caps\">DSS<\/span> compliance is not an option but a requirement for all merchants &#8212; whether small or large &#8212; that process credit cards. In other words, if your organization plans to accept credit card payments prior to and\/or at your event auction \u2013 e.g. for online ticket sales, online cash donations, as payment for items won in an online auction, and as payment for items won at your event auction \u2013 then it must be <span class=\"caps\">PCI<\/span> <span class=\"caps\">DSS<\/span> compliant.<\/p>\n\n\t<p><strong>What is required for <span class=\"caps\">PCI<\/span> <span class=\"caps\">DSS<\/span> compliance?<\/strong><\/p>\n\n\t<p>Your organization\u2019s &#8220;Merchant Level&#8221; determines your requirements for <span class=\"caps\">PCI<\/span> <span class=\"caps\">DSS<\/span> compliance. The number of transactions your organization processes each year and whether those transactions are performed from a brick and mortar location or via the Internet help determine which of four merchant levels it falls under. <\/p>\n\n\t<p>Keep in mind, even though the <span class=\"caps\">PCI<\/span> Security Standards Council developed the <span class=\"caps\">PCI<\/span> <span class=\"caps\">DSS<\/span> standards, compliance is actually mandated separately by the individual payment card brands (Visa, MasterCard, etc.). Accordingly, each payment card brand determines its own definitions of Merchant Levels and has its own set of compliance requirements.<\/p>\n\n\t<p>To give you a general idea of how to determine your <span class=\"caps\">PCI<\/span> compliance level, here are Visa&#8217;s <span class=\"caps\">PCI<\/span> compliance merchant level definitions: <\/p>\n\n\t<ul>\n\t\t<li><span class=\"caps\">PCI<\/span> Compliance Level 1 &#8212; Merchants processing over 6 million Visa transactions annually (all channels) or Global merchants identified as Level 1 by any Visa region<\/li>\n\t\t<li><span class=\"caps\">PCI<\/span> Compliance Level 2 &#8212; Merchants processing 1 million to 6 million Visa transactions annually (all channels)<\/li>\n\t\t<li><span class=\"caps\">PCI<\/span> Compliance Level 3 &#8212; Merchants processing 20,000 to 1 million Visa e-commerce transactions annually<\/li>\n\t\t<li><span class=\"caps\">PCI<\/span> Compliance Level 4 &#8212; Merchants processing less than 20,000 Visa e-commerce transactions annually and all other merchants processing up to 1 million Visa transactions annually<\/li>\n\t<\/ul>\n\n\t<p>In a future article, I will discuss the 12 <span class=\"caps\">PCI<\/span> <span class=\"caps\">DSS<\/span> requirements for becoming <span class=\"caps\">PCI<\/span> <span class=\"caps\">DSS<\/span> compliant and the importance of two technologies \u2013 end-to-end encryption and Tokenization \u2013 that help your organization achieve compliance.<\/p>\n\n\t<p>As a merchant who accepts credit cards, it is your responsibility to ensure the security of your customers\u2019 credit card and personal information. Therefore, you should evaluate your level of <span class=\"caps\">PCI<\/span> <span class=\"caps\">DSS<\/span> compliance, determine if you are meeting all requirements, and if not, what you need to do to become <span class=\"caps\">PCI<\/span> <span class=\"caps\">DSS<\/span> compliant. Your merchant processor is a great resource. They should help you determine which merchant level your organization belongs to and how to achieve <span class=\"caps\">PCI<\/span> <span class=\"caps\">DSS<\/span> compliance.<\/p>","protected":false},"excerpt":{"rendered":"<p>What is PCI DSS Compliance? Over the years, retailers have lost millions of dollars to fines and in compensation to customers as a result of compromised credit cards and personal information. These losses, moreover, do not take into account the hidden costs of lost sales and damage to merchant brands. In response to this increase [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","fifu_image_url":"","fifu_image_alt":"","footnotes":"","_wp_rev_ctl_limit":""},"categories":[6],"tags":[],"class_list":["post-43","post","type-post","status-publish","format-standard","hentry","category-auction-tips-strategies"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.4 (Yoast SEO v26.9) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>PCI DSS Compliance: The Basics - ReadySetAuction Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PCI DSS Compliance: The Basics\" \/>\n<meta property=\"og:description\" content=\"What is PCI DSS Compliance? Over the years, retailers have lost millions of dollars to fines and in compensation to customers as a result of compromised credit cards and personal information. These losses, moreover, do not take into account the hidden costs of lost sales and damage to merchant brands. In response to this increase [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/\" \/>\n<meta property=\"og:site_name\" content=\"ReadySetAuction Blog\" \/>\n<meta property=\"article:published_time\" content=\"2010-11-21T20:17:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2017-06-13T20:02:56+00:00\" \/>\n<meta name=\"author\" content=\"Amanda Foran\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Amanda Foran\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/\"},\"author\":{\"name\":\"Amanda Foran\",\"@id\":\"https:\/\/www.readysetauction.com\/rsablog\/#\/schema\/person\/a50b0bf07bc8a9e8c52d1799821ad066\"},\"headline\":\"PCI DSS Compliance: The Basics\",\"datePublished\":\"2010-11-21T20:17:43+00:00\",\"dateModified\":\"2017-06-13T20:02:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/\"},\"wordCount\":532,\"commentCount\":0,\"articleSection\":[\"Auction Tips &amp; Strategies\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/\",\"url\":\"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/\",\"name\":\"PCI DSS Compliance: The Basics - ReadySetAuction Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.readysetauction.com\/rsablog\/#website\"},\"datePublished\":\"2010-11-21T20:17:43+00:00\",\"dateModified\":\"2017-06-13T20:02:56+00:00\",\"author\":{\"@id\":\"https:\/\/www.readysetauction.com\/rsablog\/#\/schema\/person\/a50b0bf07bc8a9e8c52d1799821ad066\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.readysetauction.com\/rsablog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PCI DSS Compliance: The Basics\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.readysetauction.com\/rsablog\/#website\",\"url\":\"https:\/\/www.readysetauction.com\/rsablog\/\",\"name\":\"ReadySetAuction Blog\",\"description\":\"Take your auction fundraising event to the next level with ReadySetAuction\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.readysetauction.com\/rsablog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.readysetauction.com\/rsablog\/#\/schema\/person\/a50b0bf07bc8a9e8c52d1799821ad066\",\"name\":\"Amanda Foran\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.readysetauction.com\/rsablog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/059b337be46a71db620356667eee03818ae82c40c1fa9d577bec21b4e8177b50?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/059b337be46a71db620356667eee03818ae82c40c1fa9d577bec21b4e8177b50?s=96&d=mm&r=g\",\"caption\":\"Amanda Foran\"},\"url\":\"https:\/\/www.readysetauction.com\/rsablog\/author\/aforansofterware-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"PCI DSS Compliance: The Basics - ReadySetAuction Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/","og_locale":"en_US","og_type":"article","og_title":"PCI DSS Compliance: The Basics","og_description":"What is PCI DSS Compliance? Over the years, retailers have lost millions of dollars to fines and in compensation to customers as a result of compromised credit cards and personal information. These losses, moreover, do not take into account the hidden costs of lost sales and damage to merchant brands. In response to this increase [&hellip;]","og_url":"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/","og_site_name":"ReadySetAuction Blog","article_published_time":"2010-11-21T20:17:43+00:00","article_modified_time":"2017-06-13T20:02:56+00:00","author":"Amanda Foran","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Amanda Foran","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/#article","isPartOf":{"@id":"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/"},"author":{"name":"Amanda Foran","@id":"https:\/\/www.readysetauction.com\/rsablog\/#\/schema\/person\/a50b0bf07bc8a9e8c52d1799821ad066"},"headline":"PCI DSS Compliance: The Basics","datePublished":"2010-11-21T20:17:43+00:00","dateModified":"2017-06-13T20:02:56+00:00","mainEntityOfPage":{"@id":"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/"},"wordCount":532,"commentCount":0,"articleSection":["Auction Tips &amp; Strategies"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/","url":"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/","name":"PCI DSS Compliance: The Basics - ReadySetAuction Blog","isPartOf":{"@id":"https:\/\/www.readysetauction.com\/rsablog\/#website"},"datePublished":"2010-11-21T20:17:43+00:00","dateModified":"2017-06-13T20:02:56+00:00","author":{"@id":"https:\/\/www.readysetauction.com\/rsablog\/#\/schema\/person\/a50b0bf07bc8a9e8c52d1799821ad066"},"breadcrumb":{"@id":"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.readysetauction.com\/rsablog\/2010\/11\/21\/pci-dss-compliance-the-basics\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.readysetauction.com\/rsablog\/"},{"@type":"ListItem","position":2,"name":"PCI DSS Compliance: The Basics"}]},{"@type":"WebSite","@id":"https:\/\/www.readysetauction.com\/rsablog\/#website","url":"https:\/\/www.readysetauction.com\/rsablog\/","name":"ReadySetAuction Blog","description":"Take your auction fundraising event to the next level with ReadySetAuction","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.readysetauction.com\/rsablog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.readysetauction.com\/rsablog\/#\/schema\/person\/a50b0bf07bc8a9e8c52d1799821ad066","name":"Amanda Foran","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.readysetauction.com\/rsablog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/059b337be46a71db620356667eee03818ae82c40c1fa9d577bec21b4e8177b50?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/059b337be46a71db620356667eee03818ae82c40c1fa9d577bec21b4e8177b50?s=96&d=mm&r=g","caption":"Amanda Foran"},"url":"https:\/\/www.readysetauction.com\/rsablog\/author\/aforansofterware-com\/"}]}},"_links":{"self":[{"href":"https:\/\/www.readysetauction.com\/rsablog\/wp-json\/wp\/v2\/posts\/43","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.readysetauction.com\/rsablog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.readysetauction.com\/rsablog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.readysetauction.com\/rsablog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.readysetauction.com\/rsablog\/wp-json\/wp\/v2\/comments?post=43"}],"version-history":[{"count":1,"href":"https:\/\/www.readysetauction.com\/rsablog\/wp-json\/wp\/v2\/posts\/43\/revisions"}],"predecessor-version":[{"id":98,"href":"https:\/\/www.readysetauction.com\/rsablog\/wp-json\/wp\/v2\/posts\/43\/revisions\/98"}],"wp:attachment":[{"href":"https:\/\/www.readysetauction.com\/rsablog\/wp-json\/wp\/v2\/media?parent=43"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.readysetauction.com\/rsablog\/wp-json\/wp\/v2\/categories?post=43"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.readysetauction.com\/rsablog\/wp-json\/wp\/v2\/tags?post=43"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}