PCI-DSS standards: complying to accept online payments
Accepting card payments online requires PCI-DSS compliance. Without it, no merchant account can legally be opened.
- 12 requirements cover the network, access, encryption and monitoring
- Your compliance level depends on your annual transaction volume
- Entrusting card data storage to a certified provider handles most of the work
An obligation, not an option
PCI-DSS compliance is imposed by the card networks (Visa, Mastercard, Amex) on any merchant accepting card payments. Without it, opening a merchant account is impossible, with the risk of substantial fines.
It also reassures your customers and complements GDPR requirements on the protection of personal data, including banking data.
12 requirements, 4 compliance levels
Firewall, encryption, security updates, restricted access, authentication, log monitoring and penetration testing make up the foundation of the 12 requirements.
The level (1 to 4) depends on your annual transaction volume: most SMBs fall under level 4, with a simple self-assessment questionnaire rather than an external audit.
Getting compliant, step by step
Choose a PCI-DSS-certified payment provider from the start: it carries most of the secure storage burden. Then complete the appropriate self-assessment questionnaire and document your internal security policy.
Never store card data yourself: it is the most costly and most frequent mistake among small businesses.
Toward v4.0, and lasting compliance
Version 4.0 makes multi-factor authentication mandatory for any remote access and requires an annual penetration test, even for the smallest businesses.
Compliance is recertified every year: plan a maintenance budget and regular training for your teams on security risks.
Bringing your e-commerce into compliance is part of our e-commerce support.