PCI DSS Compliance Certification
Protect yourself and your customers when taking payments, and become a trusted partner for online transactions.
Reflare’s strategic alliance with Dot.Bit delivers cost-effective PCI DSS solutions for your technologies and teams. Our integrated training and audit offering helps you achieve your compliance requirements.
Payment Processors
The standard represents a baseline of technical and operational requirements designed to protect cardholder data and is maintained by the PCI Security Standards Council.
The council is a global forum for the ongoing development, enhancement, storage, dissemination and implementation of security standards for account data protection.
The Six Principles
The core of the PCI DSS is a group of six principles and accompanying requirements, around which the specific elements of the data security standard are organised.
1. Build and Maintain a Secure Network and Systems
2. Protect Cardholder Data
3. Maintain a Vulnerability Management Program
4. Implement Strong Access Control Measures
5. Regularly Monitor and Test Networks
6. Maintain an Information Security Policy
Transaction Safety
PCI DSS is designed to ensure that ALL companies that accept, process, store or transmit credit card information maintain a secure environment.
It is aimed at ALL entities involved in payment card processing (merchants, processors, acquirers, issuers, and service providers) as well as ALL other entities that store, process or transmit cardholder data (CHD) and/or sensitive authentication data (SAD).
Validation levels
There are two validation levels for service providers, which are based on annual transaction volumes and the type of provider you are.
Your validation requirements may include:
- Quarterly onsite assessments by a QSA
- Detailed Report on Compliance (RoC)
- Attestation of Compliance (AoC)
- Annual self-assessment questionnaire
- Quarterly network scan by an ASV
Validation Levels
There are four validation levels for merchants, each based on volumes ranging from fewer than 20 thousand to greater than 6 million transactions per year.
Your validation requirements may include:
- Annual onsite assessments by a QSA
- Detailed Report on Compliance (RoC)
- Attestation of Compliance (AoC)
- Annual self-assessment questionnaire
- Quarterly network scan by an ASV