PCIDSS

Registration of compliance with the requirements of PCIDSS (Payment Card Industry Data Security Standard) is a mandatory procedure for everyone who somehow deals with the processing of payment card data. In most cases, the lack of certification not only creates risks, but makes accepting online payments virtually impossible.

Who is required to pass PCIDSS when accepting online payments

PCIDSS is mandatory for all organizations that:

  • accept online payments from Mastercard, Visa, American Express and other systems,
  • process, transfer or they store payment card data (PAN, CVV, expiration date, etc.),
  • provide payment infrastructure (acquiring, aggregators, SaaS services),
  • are integrated with processing as directly, This is also the case through the API.

Formally, any company involved in card payment processes is subject to the industry data security standard. The presence or absence of its own processing does not matter: the very fact of accessing payment card data is important.

There are four levels of merchants according to the PCIDSS standard, depending on the annual volume of transactions:

  • Level 1: more than 6 million transactions per year — requires a full PCI QSA audit,
  • Level 2: from 1 to 6 million transactions — audit or SAQ D may be required,
  • Level 3: 20 thousand. – 1 million operations — almost always SAQ,
  • Level 4: less than 20 thousand online transactions — the requirements are set by the acquiring bank.

The lack of PCIDSS certification is:

  • fines from payment systems — up to $100 thousand. for the incident,
  • the threat of suspension of service from the acquiring bank,
  • loss of the right to work with cards at all,
  • responsibility for compromising data on liability shift (all responsibility falls on the company).

That is why the design of PCIDSS becomes not a desire "for show", but a necessity. — especially in competitive areas, where abandoning bank acquiring means direct losses.

Why it`s better not to delay the PCIDSS registration

The decision to "do certification later" often ends up having to urgently refine the infrastructure, wasting time and money. Banks increasingly require confirmation of compliance with PCI DSS requirements already at the stage of opening an account or acquiring an account. Without this, it is impossible to get a merchant ID or start accepting payments through Visa, Mastercard, and American Express systems.

A common mistake for beginners of eCommerce and fintech services is underestimating the role of the Payment Card Industry Data Security Standard: "we have only the first version of the project so far, it`s too early to think about documentation and audits". However, later, when trying to scale, it turns out that the system does not meet the basic technical requirements of data protection. This leads to urgent rework and doubled costs.

If customer data is already being processed, you are formally responsible for protecting it. This cannot be avoided, even with a small volume of operations.

What is included in the PCIDSS registration process

PCIDSS registration is not just about "signing an act". This is a whole cycle of work, including the technical, regulatory and organizational adaptation of the company to the requirements of the payment card industry data security standard. This is how it looks in stages:

Infrastructure audit

The first step is to define the boundaries of the system in which payment card data circulates or may potentially circulate. This includes:

  • servers (virtual and physical),
  • API integrations with banks, payment gateways, and third-party services,
  • event logging and network perimeter security,
  • principles of storage and encryption of sensitive data.

The audit is conducted either by internal specialists trained in PCI DSS standard or by external consultants. As a result, a data map is generated. — it defines the scope of control and the area of responsibility.

Gap analysis

Based on the PCIDSS standards, the existing state of the infrastructure is compared with the requirements of the standard., identification of gaps and ranking of vulnerabilities by criticality.

Corrective measures and implementation

After the analysis, a route plan of amendments is developed and implemented:

  • code refactoring to eliminate CVV storage,
  • implementation of access logging,
  • restriction of administrative rights,
  • encryption of logs and databases,
  • creating a role model for access,
  • migration to secure hosting or isolated virtual environments,
  • integration with SIEM systems, if a level 1-2 audit is required.

Each change is recorded in the configuration and described in the auditor`s future reports.

Testing

It includes mandatory procedures:

  • penetration testing,
  • internal and external vulnerability scans,
  • SIEM log files and events,
  • firewall verification and IDS/IPS systems.

Without testing, it is impossible to prove the control of technical measures. The scan must take place over networks that interact with card data.

Reporting and documentation

At the final stage, a complete package is formed.:

  • SAQ (Self-Assessment Questionnaire) or ROC (Report on Compliance) — depending on the level,
  • AoC — Attestation of Compliance for a bank or an international payment system,
  • related policies and regulations (DLP, password policy, incident response procedures, etc.).

Getting certified

After the final verification and approval of the documentation, the certification is considered completed. Depending on the trading level, it is confirmed by QSA (Qualified Security Assessor) auditors or a SAQ questionnaire is completed if all supporting documents are available. Banks and systems (Visa, Mastercard, American Express) accept certification as the basis for the system`s admission to card transactions.

How we speed up and simplify PCIDSS registration

The main difficulty in obtaining PCIDSS compliance is not the verification itself, but the preparation for it. Most companies are faced with the fact that the requirements of security standards contradict the current architecture, business logic or processes. Here, even a minor mistake is worth losing deadlines or refusing approval by the auditor.

We have set up the process so that we can get the company through certification as quickly and painlessly as possible. How?

Audit before the start of the project

Even before signing the contract, we carry out a technical screening of the infrastructure.:

  • we identify all the bottlenecks,
  • we determine whether refactoring, migrations, and code base changes will be required,
  • we outline the whole path — without surprises along the way.

This gives the client a real understanding of what is ahead and allows them to calculate the budget in advance. If the infrastructure already meets PCI DSS payment card industry requirements — we immediately switch to SAQ/ROC and save time.

Individual route maps for each platform

Our experts have developed route maps for dozens of popular architectures:

  • Bitrix, WooCommerce, Shopify, self-written CMS,
  • integration with LiqPay, Yandex.Yandex.Checkout, Stripe and similar,
  • cloud deployments (AWS, Yandex.Cloud, Google Cloud),
  • microservice architectures with dockerization,
  • frameworks: Django, Laravel, Express.js, Spring.

Thanks to this, we don`t "guess" how to structure incoming and outgoing traffic. — We know exactly how your system works and what is required to comply with the DSS payment card industry.

Support of interaction with the bank

We provide full support to the client:

  • we respond to the bank`s certification requirements,
  • we help to correctly present the safety of processes,
  • we delineate areas of responsibility — our team or yours
  • helps verify PCI DSS compliance on the website or platform.

This is critical when opening merchant accounts or entering new markets.

Minimizing time due to a clear structure

The speed of the passage depends on how systematically the work is structured. We have it debugged:

  • We will start within 1 business day after agreeing on the primary parameters,
  • All the stages are described in advance — you know what will happen tomorrow, in three days, at the next stage,
  • We use PaaS access to testing tools. — you don`t need to put something on the server manually,
  • The logic of the work includes the possibility of lock-free iterations (you can refine the infrastructure in parallel with the design of part of the documentation).

Clear result and without risks

We do not promise abstract “compliance with the payment card industry security standard". We give the client:

  • AoC and SAQ certification — official conformity confirmations,
  • a roadmap that needs to be updated in a year (because this is an annual commitment),
  • incident management and logging based on the actual infrastructure,
  • support in case of external verification by a bank or partner,
  • transparent tracking of the project progress at any time.

Issue an invoice for payment in 2 clicks

Need to make a payment quickly? In your personal account, you can instantly issue an invoice for payment in any of the cryptocurrencies offered by the service for the required amount. After the customer pays the bill, the funds will be credited to your account within a few minutes.

After paying the client`s bill, the daily messages will be published on your website within a few minutes.

Contact us


E-Mail
Telegram
WhattsApp
Make a call
Wallex

Your request has been sent successfully!

You will be contacted as soon as possible.

Support is available in our Telegram Bot


Write to support

Support is available in our WhattsApp


Go to WhattsApp

Phone number for contacting us


+7 (495) 185-63-92

Reliable infrastructure

Compliance

Start

Thank you for your interest in our solutions. Fill out the form and we will contact you soon to discuss the right solution for your business.

Wallex

Your request has been sent successfully!

You will be contacted as soon as possible.

Wordpress module

Opencart module

Joomla module

Drupal module

1C Bitrix module

API For Developers

Payout API

PHP SDK

Python SDK