PCI-DSS Compliance: Questions and Answers

{Note: We will update this article as we receive new questions from clients.  If you have a question that is not answered here, please feel free to contact us.}

What if we don't accept credit cards?

If you don't accept credit cards, PCI-DSS compliance does not apply to you.

What does 'PCI-DSS' stand for?

PCI-DSS stands for 'Payment Card Industry - Data Security Standards' a multifaceted security standard that includes requirements for security management, policies, procedures as established by the PCI Security Standards Council.  

Who represents the PCI Security Council?

The organization was founded by several credit card companies including: American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa, Inc. It's mission is to to enhance payment account data security by driving education and awareness of the PCI Security Standards.

What exactly are the PCI-DSS standards?

PCI-DSS standards exist as a form of risk management - intended to help organizations proactively protect customer account data.  To learn more, visit the PCI Security Standards website at www.PCIsecuritystandards.org.

If the software I use is PCI-DSS compliant, is my organization fully PCI-DSS compliant?

No.  In order to become fully PCI-DSS compliant, you must also adopt certain internal processes that protect cardholder data.  Please visit the PCI Security Standards website at www.PCIsecuritystandards.org.

How do I become 'PCI-DSS Certified'?

You can become 'PCI-DSS Certified' by a third-party security audit.  Names of organizations who provide this service are available at the PCI Security Standards website at www.PCIsecuritystandards.org.

Can I use TCS Software's products and be PCI-DSS compliant?

You must follow certain protocols when using TCS Software's products.  Namely, you must not store credit card numbers within any of our products, even temporarily.  Our products now integrate with online third-party payment systems that are PCI-DSS compliant.

Do I need to establish a new merchant account?

Yes.  If you're accepting credit card details and payment information for any online transactions (i.e. Prima and Association WebSuite Input Forms) then you will need to establish a new online merchant account.  Online merchant accounts are separate from regular merchant accounts.

Will my merchant fees increase?

Most likely.  We realize that minimizing transaction costs is something everyone wants to do.  But keep in mind that online merchant account fees are often higher than traditional merchant accounts.

Can I select another provider for my online merchant account?

No. We've modified our systems to work with these three widely used and well-known providers to offer our clients more than one payment-processing vendor to choose from.  You can compare all three and choose the best option to fit your organization.

What if I don't want to change my present merchant account and/or processes?
You can continue to use your current provider and processes.  We simply ask that you notify us by completing this form.

Printer-Friendly Version