Taking card payments? Ensure your business is PCI DSS Compliant

Taking card payments? Ensure your business is PCI DSS Compliant

If your business takes card payments, either in person or online, then it will have to meet the Payment Card Industry Data Security Standard, also known as PCI DSS.

These are a set industry-wide requirements to protect you and your customers when taking payments. Even if you outsource your payment system to a third-party payment supplier, such as Stripe, you still need to follow the security protocols to be PCI DSS compliant.

Strident has extensive experience in providing both the IT technical expertise in maintaining a secure system but also writing compliance processes and policies to ensure your business meets the Payment Card Industry Data Security Standard. 

What is PCI DSS and what happens if my business is not complaint?

The standard is an agreement between the major card payment businesses, such as Mastercard and Visa, and is operated Payment Card Industry Security Standards Council. The latest version of the PCI DSS (Version 4) was released at the end of March 2022.

All merchants and payment supplier that process, transmit or store cardholder data must comply with the PCI DSS.

Although not a legal requirement yet, if your business does not meet the standard, you could be fined. The Security Standards Council will fine your bank for a security/data breach and if your business is not PCI DSS compliant, your bank provider could pass these fines onto your business.

In addition, your business may be breaching the Data Protection Act 2018 if payment card data is breached. This could be subject to enforcement action from the Information Commissioners Office (ICO).

What should my business do to be PCI DSS compliant?

There are twelve steps PCI DSS requirements. The include technical actions as well as on-going policies to maintain security.

  1. Install and maintain network security controls
  2. Apply secure configurations to all system components Protect stored account data
  3. Maintain a vulnerability management programme
  4. Protect all systems and networks from malicious software
  5. Develop and maintain secure systems and software
  6. Restrict access to system components and cardholder data by business need to know
  7. Identify users and authenticate access to system components
  8. Restrict physical access to cardholder data
  9. Log and monitor all access to system components and cardholder data
  10. Test security of systems and networks regularly
  11. Support information security with organisational policies and programs

What should my business do to be PCI DSS compliant?

We understand that not all businesses are the same, and the processes that need to be put in place are quite different if you are a small business accepting card payments for services or a large multi-site retailer.

Strident has both the IT technical and compliance expertise to ensure you can meet the Payment Card Industry Data Security Standard. Working with our Compliance team, we can help your organisation meet, maintain and prove to customers and suppliers that you meet this standard.

To discuss PCI DSS Compliance or our Data Protection services for your business, please get in touch.

Get the latest news from Strident

6 Steps for Sorted IT

ISO & Data Protection