How to Become PCI Compliant: 10 Steps (with Pictures) (2024)

Explore this Article

parts

1Reviewing the PCI DSS Basics

2Implementing PCI Compliance Programs

3Testing and Maintaining PCI Compliance

Other Sections

Tips and Warnings

Related Articles

References

Co-authored byClinton M. Sandvick, JD, PhD

Last Updated: May 6, 2021References

PCI, often called PCI DSS, stands for Payment Card Industry Data Security Standard. In short, PCI is a set of industry standards used to measure the security of businesses that accept, process, store, and transmit credit card information. Companies that are PCI compliant are less likely suffer data breaches that could expose customers to identify theft. If you have a Merchant ID and accept credit cards in either your physical or virtual business, then you are subject to PCI DSS industry standards. The PCI Security Standards Council is an independent group of industry professionals who investigate emerging PCI security issues and create the programs and standards to maintain the integrity of the payment card system.

Part 1

Part 1 of 3:

Reviewing the PCI DSS Basics

  1. 1

    Confirm your merchant level. The first step is to discuss and verify your merchant level with the bank or clearinghouse that handles your credit card transactions. Merchants are divided into four categories based on VISA card transaction over 12 months. Your merchant level will determine how stringent your PCI compliance programs must be.[1]

    • A Level 1 merchant processes over 6 million VISA transactions per year or is designated Level 1 by the VISA company.
    • A Level 2 merchant accepts between 1 and 6 million VISA transactions annually. This includes in-person and online.
    • A Level 3 merchant will process between 20,000 and 1 million VISA transactions per year.
    • A Level 4 merchant, considered a small merchant, takes in fewer than 20,000 VISA payments per year.[2]
    • PCI DSS requirements also apply to businesses that accept other credit cards, such as American Express, MasterCard, and Discover. VISA is used as the benchmark for establishing merchant levels.
  2. 2

    Understand the penalties for PCI DSS violations. Businesses that are not PCI DSS compliant may be subject to fines, sanctions, and loss of privileges from the clearinghouse that processes credit card payments. If the PCI failure results in an actual loss of data, the business could face fines, higher fees, and other sanctions from banks and credit card processors.[3]

    • Businesses that are not PCI-compliant may be subject to lawsuits and governmental prosecution for failing to protect customer data.

    Advertisem*nt

  3. 3

    Familiarize yourself with the best security practices. The first PCI DSS standard, implemented September 2009 (DSS v 1.2) introduced the 12 requirements that a merchant should examine in order to be PCI compliant. Depending on your merchant level, the amount of technology, training, and expertise to implement the standards will vary. For example, a network that handles 2 million transactions will be more sophisticated than a network that processes 2000.

    • PCI 3.1 went into effect in June of 2015 and deals with new standards in technology and addresses vulnerabilities in common encryption programs.[4]
    • PCI compliance best practices fall into five general categories: secure network, data protection, vulnerability management, access control, monitoring, and security policy. The PCI Council has a self-assessment questionnaire to help small businesses determine compliance with the security standards.[5]

    Advertisem*nt

Part 2

Part 2 of 3:

Implementing PCI Compliance Programs

  1. 1

    Build and maintain a secure network. For businesses, this will mean developing a relationship with a trusted contractor. Unless you are an IT professional, you should not install your own network if it will store customer data. Even an out-of-the-box system may have vulnerabilities if not installed and updated properly.[6]

    • Keep your firewalls up-to-date and operational. Do not let employees disable firewalls for any purpose.
    • Change passwords provided by the vendor immediately. Also, implement a password program for your employees. Passwords should be changed regularly in compliance with vendor instructions. For example, passwords should be alpha-numeric-character combinations that are not dictionary words. If your vendor works on your system, you should change all passwords when it comes back online.[7]
  2. 2

    Protect cardholder information. If you manually process credit cards, the slips and receipts should be maintained in locked files with limited access. If cardholder information is stored in your network, it should be encrypted and protected behind the company firewalls

  3. 3

    Create a vulnerability management program. Your system should be protected with appropriate anti-virus software. You should also have a company program that prohibits adding software, such as games, that could compromise the system.[8]

  4. 4

    Implement Access Control. Password access to your system should be restricted. Each employee should only have the access he needs to do his job. Explain that this protects both your employees and your customers. If there is a data breach, restricted access will narrow the possibilities and help the investigation.[9][10]

    • For your network, give each user and each terminal a unique ID number. In the event of a confirmed or suspected breach, your IT professionals will be able to quickly identify the entry point.
    • Secure physical records that contain customer and cardholder data. Use either a card key system or a physical lock and key.

    Advertisem*nt

Part 3

Part 3 of 3:

Testing and Maintaining PCI Compliance

  1. 1

    Monitor and test your networks. Your security program must include regular scans and tests to track and monitor the flow of customer data through your network. Your IT professional or vendor can implement tests both when the system is at low use (for example, late at night on weekends) and in real time when the system is in use.

    • Maintain a log of test results. Discuss how long to maintain test records with your bank and insurance company.
  2. 2

    Develop an Information Security Policy. All of the steps in your PCI-compliance program must be documented in your Security Policy.[11] This document should detail all the steps your company takes to secure customer data. For Level 1 to 3 merchants, this program may run for several volumes and integrate the employee manual.

    • Level 1 to 3 merchants will likely either contract with a security professional or have dedicated staff trained in the intricacies of writing and maintaining the Information Security Policy.
    • A Level 4 merchant should contact the credit card clearinghouse for advice and assistance on creating the Security Policy. If the processor doesn’t provide a program template, then you should consider contracting with a security professional to create the document. Unless you are an IT professional, it is unlikely that you will be sufficiently versed in the technical details of your system to create a PCI-compliant security policy. Once it is created, it will only need to be updated when your network is expanded or updated. Your IT contractor can provide you with the documents you need to keep your security policy up to date.
    • Most of your security program will be technical in nature, as in choice of firewall and security software, as well as the testing protocols. However, you should also include sections about the process when an employee leaves the company and passwords are revoked.
    • Develop a process to keep track of keys and keycards. Master keys should be as strictly regulated as high level passwords.
  3. 3

    Assess, remediate, and report your PCI compliance. Once the 12 parts of the PCI best practices are implemented, you should periodically run through the PCI Council three-step review process to ensure that compliance is maintained.

    • Inventory your IT systems and business processes. If anything has changed, update your security programs and vulnerability management plans.
    • If you find a weakness in your system, remediate the problem. This may require new equipment or software, user training, or updating your network. IT professionals should implement these changes.
    • Keep records of your actions and submit reports of your compliance efforts to your bank and credit card companies. Your reports, efforts, and insights may help another company protect customer data.

    Advertisem*nt

Expert Q&A

Ask a Question

200 characters left

Include your email address to get a message when this question is answered.

Submit


      Advertisem*nt

      Warnings

      • Level 4 merchants should discuss PCI compliance with the bank or credit card clearinghouse and follow the recommendations.[12]

        Thanks

        Helpful0Not Helpful0

      • If you are a very small merchant, such as a home business, it is unlikely that you will be storing card data on your personal network. However, you should still review your processes with your bank. The PCI Council has online training and resources to help you prevent theft of customer data.[13]

        Thanks

        Helpful0Not Helpful0

      Advertisem*nt

      You Might Also Like

      Best Online Casinos USA in 2024How toBecome Taller Naturally
      How toPrevent Small Worms in BirdbathsHow toGet Rid of Blackheads on Your NoseHow toApply for a GrantHow toIronHow toForget SomeoneHow toGet Your House to Not Smell Like Your PetsHow toSlim Your FaceHow toFind Things You Lost14 Effective Ways to Kill Cabbage Worms and Cabbage LoopersHow toBleach a White ShirtHow toTan in the SunHow toUse Pore Strips

      Advertisem*nt

      More References (4)

      About this article

      How to Become PCI Compliant: 10 Steps (with Pictures) (24)

      Co-authored by:

      Clinton M. Sandvick, JD, PhD

      Lawyer

      This article was co-authored by Clinton M. Sandvick, JD, PhD. Clinton M. Sandvick worked as a civil litigator in California for over 7 years. He received his JD from the University of Wisconsin-Madison in 1998 and his PhD in American History from the University of Oregon in 2013. This article has been viewed 71,430 times.

      51 votes - 76%

      Co-authors: 20

      Updated: May 6, 2021

      Views:71,430

      • Print

      Thanks to all authors for creating a page that has been read 71,430 times.

      Did this article help you?

      Advertisem*nt

      How to Become PCI Compliant: 10 Steps (with Pictures) (2024)
      Top Articles
      Return status has not changed | T-Mobile Community
      Tmobile problems on my return of phone | T-Mobile Community
      Skigebiet Portillo - Skiurlaub - Skifahren - Testberichte
      Creepshotorg
      Elleypoint
      Craigslist Monterrey Ca
      Time in Baltimore, Maryland, United States now
      Jonathan Freeman : "Double homicide in Rowan County leads to arrest" - Bgrnd Search
      Merlot Aero Crew Portal
      Ribbit Woodbine
      Here's how eating according to your blood type could help you keep healthy
      Big Y Digital Coupon App
      Bubbles Hair Salon Woodbridge Va
      [2024] How to watch Sound of Freedom on Hulu
      Blue Ridge Now Mugshots Hendersonville Nc
      Jessica Renee Johnson Update 2023
      Hillside Funeral Home Washington Nc Obituaries
      How Many Slices Are In A Large Pizza? | Number Of Pizzas To Order For Your Next Party
      Shuiby aslam - ForeverMissed.com Online Memorials
      Diablo 3 Metascore
      Bfg Straap Dead Photo Graphic
      Driving Directions To Bed Bath & Beyond
      Spider-Man: Across The Spider-Verse Showtimes Near Marcus Bay Park Cinema
      Gopher Hockey Forum
      Leccion 4 Lesson Test
      The best firm mattress 2024, approved by sleep experts
      Mail.zsthost Change Password
      Keci News
      Sodium azide 1% in aqueous solution
      Ac-15 Gungeon
      Watch Your Lie in April English Sub/Dub online Free on HiAnime.to
      Mythical Escapee Of Crete
      Safeway Aciu
      Mjc Financial Aid Phone Number
      10-Day Weather Forecast for Santa Cruz, CA - The Weather Channel | weather.com
      Ff14 Sage Stat Priority
      Warren County Skyward
      Dubois County Barter Page
      Darrell Waltrip Off Road Center
      Pensacola 311 Citizen Support | City of Pensacola, Florida Official Website
      Bimar Produkte Test & Vergleich 09/2024 » GUT bis SEHR GUT
      To Give A Guarantee Promise Figgerits
      Pinellas Fire Active Calls
      Kelly Ripa Necklace 2022
      Craigslist Gigs Wichita Ks
      boston furniture "patio" - craigslist
      Uc Davis Tech Management Minor
      Unlock The Secrets Of "Skip The Game" Greensboro North Carolina
      Port Huron Newspaper
      Sams La Habra Gas Price
      Causeway Gomovies
      Pulpo Yonke Houston Tx
      Latest Posts
      Article information

      Author: Twana Towne Ret

      Last Updated:

      Views: 5313

      Rating: 4.3 / 5 (44 voted)

      Reviews: 91% of readers found this page helpful

      Author information

      Name: Twana Towne Ret

      Birthday: 1994-03-19

      Address: Apt. 990 97439 Corwin Motorway, Port Eliseoburgh, NM 99144-2618

      Phone: +5958753152963

      Job: National Specialist

      Hobby: Kayaking, Photography, Skydiving, Embroidery, Leather crafting, Orienteering, Cooking

      Introduction: My name is Twana Towne Ret, I am a famous, talented, joyous, perfect, powerful, inquisitive, lovely person who loves writing and wants to share my knowledge and understanding with you.