No thanks, stay here.  

  We notice you are visiting from a U.S. Internet provider. Switch to our U.S. website.

Industry News

PCI SSC: Level 4 merchants shouldn't hold breath for tiered payment processing security requirements

By Joseph Trigliari

16/03/2010 - A common complaint among small, Level 4 merchants is that the PCI compliance mandates are too intense and burdensome for them, and are better suited to larger merchants.

However, small merchants should not expect the PCI DSS burden to be lifted anytime soon, according to PCI Security Standards Council general manager Bob Russo and council CTO Troy Leach.

In an interview with payment processing security expert Anton Chuvakin at the recent RSA conference, Russo and Leach said that tiered security requirements are not in the cards, Chuvakin reported on his blog.

"You cannot dumb security down below a certain level," they told Chuvakin. "More education efforts will be needed to explain to merchants how to satisfy requirements and become compliant."

However, the PCI SSC will try to help out in this respect - Russo and Leach said that the council "is planning to build more tools in order to help merchants understand what exactly they need to do to become compliant," such as a wizard interface to simply the SAQ process.

PCI compliance has historically been particularly difficult for small merchants to achieve - a survey of U.S. Level 4 merchants by the National Retail Federation, ControlScan and the PCI Knowledge Base, for example, found that 29 percent of respondents admitted to not being compliant.ADNFCR-2514-ID-19672809-ADNFCR

Related News - Security and Fraud

Banks get creative to promote overdraft protection

29/07/2010

New regulations born of the financial reform bill may help cut costs for consumers who use point-of-sale terminals, yet banks are still searching for a way to recoup their potential losses.

Full Article

Tokenization can eliminate PCI compliance worries

27/07/2010

Retailers, payment processing companies and others are learning how to implement and accommodate new security practices to protect consumers and lessen their PCI compliance burden.

Full Article

Chip-and-pin technology has reduced fraud, but not interest rates

26/07/2010

With the introduction of credit card chip technology, consumers charging purchases at credit card machines were promised savings in interest rate charges, but have not seen them yet.

Full Article

Consumers have trouble reading credit card agreements

23/07/2010

Credit card customers have no problems using point-of-sale terminals, but when it comes to reading their account paperwork, that is a whole other issue.

Full Article