Validation on Demand

The PCI standards provides very clear guidelines for assessing compliance. All enterprises with cardholder agreements are required to comply. And to do so, they must ensure that their service providers, i.e. Payment Gateways and Processors, are also compliant.

Are You a Service Provider?

What is less clear, however, is the definition of a ‘service provider’.

Certainly, any third party that stores, processes or transmits cardholder data and helps merchants in the accepting of payments is a service provider. It includes Payment Gateways and Processors. Increasingly, security-conscious enterprises look forward from service providers for managing important controls to follow and validate compliance.

This new broader definition of a service provider is good for both the merchants and the service providers as it includes important business partners into discussions on security.

How to Get Validated

If an organisation is a Level 1 service provider, it requires an independent assessment and Attestation of Compliance (AOC) in order to fulfil requirements of the major card brands . Xiarch Solutions is the top independent consultant for service providers. The assessment reports have always fulfilled the Compliance requirements set forth by Visa and MasterCard .

If you are a Level 2 service provider (that is, you process fewer than 200,000 transactions annually), you are also required to be fully compliant with the Payment Industries standards, but you have options regarding validation.

The fastest and easiest way may be to complete a Self Assessment Questionnaire (SAQ). Now, you may accomplish this either on your own or with the help of an outside assessor. However, many service providers choose to conduct external assessments so AOC can be filed and they are listed by Visa and MasterCard.

Xiarch Solutions encourages you to pick the validation method that is most appropriate for your customers and is the best match for your in-house skill sets. Regardless of your choice, Xiarch Solutions can help.