Low Cost Level 1 PCI Compliance
Problem
When handling credit card payments it is of the utmost importance that credit card information is transmitted and stored securely. Any breach of security can be extremely costly both to the consumer and the vendor. Some of the most famous credit card frauds in recent times was at TJX where a breach of their systems exposed data from more than 45.6 million credit cards. Another high profile case involved information stolen from more than 130 million credit and debit cards at Heartland Payment Systems, retailers 7-Eleven and Hannaford Brothers, and two unidentified companies.
To prevent such events from happening, the Payment Card Industry Data Security Standard (PCI DSS) is an information security standard for organizations that handle cardholder information for the major debit, credit, prepaid, e-purse, ATM, and POS cards. Some critics claim the standards do not go far enough. However, as a consumer you have some peace of mind that if you buy from a level 1 compliant merchant you do have certain levels of protection.
Consumer
As a consumer if you purchase from a non-PCI Compliant Merchant you run the risk that your credit card details may be compromised or stolen.
Merchant
If you process credit cards online and are found to be non-compliant not only do you run the risk of reputational damage you also may be liable to pay large fines (currently from $5,000 to $100,000 per month) for PCI compliance violations. (see PCI Compiance fees)
Cost of Compliance
The cost of PCI Compliance can be rather onerous. Firstly the source code must be separated from the data storing the credit information. This usually requires at least one dedicated server possibly two. Essentially you must satisfy the 250 questions in the PCI SAQ. Even with the extra hosting overhead you also require a quarterly scan per IP address and an annual audit that can cost anything from €200k to €500k. In short, PCI compliance is expensive.
Solution
Partnering with Realex Payments. We use the full suite of products provided by Realex to ensure your solution is Compliant to Level 1 PCI DSS.
- Credit and Debit Card Authorisations – Real Auth
- 3D Secure Cardholder Authentication - Verified by Visa/ SecureCode by Mastercard
- Dynamic Currency Conversion – Real FX
- Card and customers information Storage - Recurring or subscription payments
Benefits
PCI DSS Compliance without the over head of compliance costs. ng>
PCI Compliance
PCI Self Assessment Questionaire