Is your credit card processor PCI-Level 1 certified?

PCI-DSS

Although you would think that the answer would always be ‘yes’, many merchants are surprised to hear that the company they have been dealing with is not certified.

Q: Do all processors need to be certified?

Any institution that handles credit card information is required to be PCI certified. However, some providers will portray themselves as ‘processors’ but are simply reselling someone else’s services. These resellers are technically not required to be certified since they are not doing any of the processing and settlements themselves. Some sales offices will even blur the lines by trying to claim that they are certified through their processing “partner”, while never admitting that their own systems have not been approved by Visa and MasterCard.

Q: How do I check if my provider is on the list?

It only takes about 30 seconds to find out! Below is a link to Visa’s world-wide list of PCI Level-1 certified providers. Simply load the PDF document and search for your provider:

Visa CISP List: http://usa.visa.com/download/merchants/cisp-list-of-pcidss-compliant-service-providers.pdf

Q: What if this provider is not on the list?

If your provider is not on the list, then they are either a reseller or are not compliant. Merchants you should be careful about what sensitive information they are willing to provide and should deal with organizations that take the safekeeping of personal information seriously.

Posted in Credit Card Processing | Tagged , , , , , | 1 Comment