Card Brands or Acquirers require the entities transferring, processing and/or storing card holder data, Merchants levels, criteria, and related validation requirements are defined according to the volume count of transactions.
Level 1 (1) Any merchant, regardless of acceptance channel, processing more than 6,000,000 payment card transactions per year. (2) Any merchant that has had a data breach or attack that resulted in an account data compromise. (3) Any merchant identified by any card association as Level 1 | (1) Annual Report on Compliance (ROC) (2) Quarterly network scan by Approved Scan Vendor (ASV). (3) Attestation of Compliance Form | Qualified Security Assessor (QSA) Approved Scan Vendor (ASV) |
Level 2 1 million – 6 million (all channels). | (1) Annual Self-Assessment Questionnaire (SAQ). (2) Quarterly network scan by ASV. (3) Attestation of Compliance Form. | Merchant Approved Scan Vendor |
Level 3 20,000 to 1 million E-commerce | (1) Annual Self-Assessment Questionnaire (SAQ). (2) Quarterly network scan by ASV. (3) Attestation of Compliance Form. | Merchant Approved Scan Vendor |
Level 4 Less than 20,000 E-Commerce | (1) Annual Self-Assessment Questionnaire (SAQ). (2) Quarterly network scan by ASV. (3) Attestation of Compliance Form. | Merchant Approved Scan Vendor |
The Standards
The purpose of PCI DSS is to protect the card holder data. The 12 requirements are seen as shell protects to the card holder data.
ulnerability
Transfer Encryption
Dev
System
Data Security
Monitor
Network Firewall
Access Control
Policy
PCI DSS Compliance Assessment and Consulting Service
The PCI DSS compliance assessment work process flow is as shown below. Normally, the time frame needed from the planning of implementation to completion of assessment, for small and medium organizations, is around 6 to 8 weeks [not including systems development], and 8 to 12 weeks for a large organization.The estimated time including planning, consulting and assessment stages.
Generally speaking, PCI DSS Assessment is a continuous process. Our Consultants and PCI DSS QSA will work with the client organization through the Planning Stage, Implementation Stage, Consulting Stage, and the Assessment Stage.
All processes will be leaded by the PCI DSS QSA to check and review system securities, technical controls, management controls and consultants follow by assistance of fixing the findings of non-compliances.
After successful completion of the assessment, Report of Compliance (ROC) will be prepared and signed off by one of our PCI DSS QSAs, and Attestation of Compliance (AOC) will be prepared by QSA Company which is then signed off by the client’s executive management. The AOC, and sometime together with ROC, is then submitted to the Acquirer or the Card brand to complete the PCI DSS Compliance process.