PCI compliance - executive guide image

UK Guide to PCI Compliance

What is PCI compliance?

To achieve PCI compliance means to meet the standards of the Payment Card Industry Data Security Standard (PCI DSS). This standard contains a set of requirements designed to increase data security and protect merchants and customers when taking and making payments by debit or credit card.

The PCI Security Standards Council (PCI SSC) is a global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments worldwide.

The Council was founded in 2006 by American Express, Discover, JCB International, MasterCard and Visa Inc.

The current standard is PCI DSS 3.2.1

Is PCI compliance necessary in the UK?

Yes!

All UK merchants and service providers that process, transmit or store payment card data must be PCI DSS compliant.

For merchants: if you accept payment by debit or credit card for goods or services, you must be PCI DSS compliant, even if you use a third-party organisation or platform to process the payment (see below).

For service providers: if you are involved in processing, storing or transmitting cardholder data on behalf of another party, you must be PCI DSS compliant.

Do I need PCI compliance if I use a payment provider like Stripe or SagePay?

Yes!

If you use a payment service provider, PCI compliance becomes a shared responsibility between yourself as the merchant and the payment provider.

Using a payment service provider will normally mean you, as the merchant, have no need to see or have any access to the card holder’s information. This makes it much easier to meet your PCI compliance requirements, but it does not remove them.

What could be the consequences of not being PCI compliant?

The main consequence of not being PCI compliant is that you may not be protecting cardholder data. This means you could be responsible for a breach and that could be enormously costly for your business and your customers.

A data breach could result in both financial and identity theft from your customers. This will need to be reported to the Information Commissioner (and your customers) and you could be liable to financial penalties that could be significant under the GDPR (General Data Protection Regulation), as well as the card brands.

In addition, your bank may set considerable (and costly) requirements for you to be able to continue accepting card payments after the breach. For example, if you have been subject to a cardholder data breach, you will be required to conduct a PCI council-approved forensic investigation and then achieve the highest level of compliance (Level 1 – see below) regardless of the number of payments you take.

Beyond these fines, the impact of a cardholder data breach on your reputation could be catastrophic.

Even in the absence of a breach, failure to be PCI DSS compliant means you are likely to be liable for fines and additional transaction charges from your bank. They may also withdraw the facility to take payment by credit and debit card if you continue to be non-compliant.

How much could I be fined if I am not PCI compliant?

If you continue failing to meet your PCI compliance requirements, in the worst circumstances your acquirer could withdraw your facoility for accepting payment cards.

You could also be subject to increased fees for every card payment you take. One company we recently engaged with was paying over £1,000 per month in non-compliance fees when the issue was resolvable with a one-off investment of around £3,000.

On top of this, you can incur fines costing as much as tens of thousands of pounds depending on the level of breach and cardholder data stolen.

What are the PCI compliance levels?

There are four levels of merchant based on the number and type of transactions they take. Level 1 concerns those merchants that take the highest number of transactions (or who have had a data breach previously) and Level 4 concerns those merchants who take the fewest number of card payments.

The specific criteria for each compliance level are:

Level 1

Merchants who process over 6 million payment card transactions a year (or those who have suffered a cardholder data breach in the past).

Level 2

Merchants processing between 1 million and 6 million payment card transactions a year.

Level 3

Merchants processing between 20,000 and 1 million payment card transactions a year.

Level 4

Merchants processing fewer than 20,000 payment card transactions a year.

See more from VISA and Mastercard.

What does it take to be PCI compliant?

PCI DSS compliance covers three main areas:

  • Handling card data: ensuring card holder data is collected and transmitted securely
  • Storing data securely: ensuring that if you store card data, the payment environment meets a series of specific requirements into terms of the technology, people and processes involved – see the 12 steps of PCI DSS below
  • Annual validation: for all levels, an annual validation via form – an SAQ or Self Assessment Questionnaire – is required. However, the specific requirements depend on a number of factors and vary by level of merchant and acceptance channels (see below). In addition, any organisation that needs to be PCI DSS compliant may need to validate that to payment processors, suppliers or clients, and customers.

What are the 12 steps PCI DSS version 3.2.1?

These 12 steps are the main security controls or requirements for achieving PCI compliance, broken into six objectives:

Build and maintain a secure network and systems

1) Install and maintain a firewall configuration to protect cardholder data

2) Do not use vendor-supplied defaults for system passwords and other security parameters

Protect cardholder data

3) Protect stored cardholder data

4) Encrypt transmission of cardholder data across open or public networks

Maintain a vulnerability management programme

5) Protect all systems against malware and regularly update anti-virus software

6) Develop and maintain secure systems and applications

Implement strong access control measures

7) Restrict access to cardholder data by business need to know

8) Identify and authenticate access to system components

9) Restrict physical access to cardholder data

Regularly monitor and test networks

10) Track and monitor all access to network resources and cardholder data

11) Regularly test security systems and processes

Maintain an information security policy

12) Maintain a policy that addresses information security for all personnel

What are the PCI compliance validation requirements by level?

The different levels (see above) require a different set of validation procedures which can be summarised as follows:

Level 1

Annually

  • File a ROC (Report on Compliance) by a Qualified Security Assessor (QSA – see below) or an internal assessor if signed by a company officer
  • Submit an AOC (Attestation of Compliance) Form submitted

Quarterly

  • Network scan conducted by an Approved Scan Vendor (ASV)

Level 2

Annually

  • File a ROC (Report on Compliance) or SAQ (Self Assessment Questionnaire) by a Qualified Security Assessor (QSA – see below) or an internal assessor if signed by a company officer
  • Submit an AOC (Attestation of Compliance)

Quarterly

  • Network scan conducted by an Approved Scan Vendor (ASV)

Level 3

Annually

  • Complete an SAQ (Self-Assessment Questionnaire – see below) signed by a company officer
  • Submit an AOC (Attestation of Compliance)

Quarterly

  • Network scan conducted by an Approved Scan Vendor (ASV

Level 4

Annually

  • Complete an SAQ (Self-Assessment Questionnaire – see below) signed by a company officer
  • Submit an AOC (Attestation of Compliance)

Quarterly

  • Network scan conducted by an Approved Scan Vendor (ASV

What is an SAQ (Self Assessment Questionnaire)?

A Self-Assessment Questionnaire (SAQ) is a self-validation tool to assess security for cardholder data. It’s suitable for smaller merchants and service providers who are not required to submit a Report on Compliance.

The Self-Assessment Questionnaire includes a series of yes-or-no questions for the security requirements. If an answer is no, your organisation may need to specify what you will do to achieve the required level and by when.

There are a series of nine different SAQs available from the PCI Security Standards Council to meet different types of merchant and service provider requirements.

See more from the PCI Security Standards Council

What is a PCI QSA (Qualified Security Assessor)?

  1. Qualified Security Assessor (QSA) companies are independent security organisations that have been qualified by the PCI Security Standards Council to validate an organisation’s compliance with PCI DSS.
  2. QSA employees are individuals who are employed by a QSA Company and have satisfied and continue to satisfy all QSA Requirements.

Common PCI compliance myths

There are many myths and misunderstandings about PCI compliance. These are some we encounter on a regular basis:

MYTH – PCI compliance is only ‘a thing’ for big businesses.

If you’ve read this guide you will be clear that every merchant that takes payment by credit or debit card needs to be PCI DSS compliant and can face significant consequences if they aren’t.

MYTH – We use Sage Pay/Stripe/Paypal etc and they are fully PCI compliant so we don’t need to be.

As explained above in this guide, every merchant who takes payment by card needs to be PCI compliant. Using a payment provider like Sage Pay or Stripe or Paypal may make it much easier to achieve and demonstrate that you are PCI compliant, but it does not in any way make you exempt.

MYTH – I do not need to be PCI compliant because it is not a legal requirement.

This is not the case, but it is required by the payment card companies and banks. Failure to comply means they can both remove the option for a merchant to take credit card payments and charge them much more for doing so. Should an organisation face a breach of cardholder data and not be PCI DSS compliant, the penalties are likely to be more severe.

MYTH – I can just answer ‘Yes’ to all the questions on the Self-assessment Questionnaire (SAQ).

This is an extremely dangerous position to take because the SAQ has to be signed by an officer of the company. If they answer ‘Yes’ to a question when they aren’t adequately meeting that control, the banks and payment card companies will take that very seriously. If a card data breach occurs and it becomes clear the merchant was never actually compliant, the consequences for the organisation could be extremely serious.

MYTH – I never committed to being PCI compliant and I can wait until the bank asks me to.

This is a common misunderstanding and another very dangerous one. The terms signed when a merchant opens a bank account will state that PCI compliance is required and you will not be allowed to operate a merchant account if you are not PCI compliant.

How much does it cost to achieve PCI compliance?

The cost of PCI engagement will depend on scope which includes a number of different scenarios. For example: number of transactions, type of transactions (e.g. face to face, ecommerce), payment environment and so on.

It will also depend on where you are and how much work is needed to meet the appropriate compliance levels.

How can Securious help me get or maintain PCI compliance?

Securious has been a PCI QSA company since 2016 and has two fully qualified and highly experienced PCI QSAs.

We are based in Exeter, Devon but undertake PCI QSA work nationally and internationally.

Our mission is to build cyber security confidence and when it comes to PCI DSS compliance, we will work with you to make the process as efficient as possible, helping you understand what you need to do, and why.

Typically, we approach PCI QSA engagements as follows:

  • We start by assessing your situation to determine the scope and what level you need to be reporting at. Then, we conduct a gap analysis, looking at what you already have in place against the requirements, so we can determine the additional measures you need to implement to achieve compliance.
  • We will then advise and assist with any remediation work needed to meet the standard.
  • Finally, we will carry out your assessment and complete the necessary reports and questionnaires as required.

What should I do next?

If you need any help, feel free to contact the team at Securious, the South West’s leading cyber security company. They have provided the content on this site and are passionate about helping businesses and organisations understand and improve their cyber security.

If you have any questions, a member of the team would be more than happy to speak with you – just fill in the contact form below, or get in touch with them on 01392 241110, or info@securious.co.uk