PCI Compliance for Service Providers FAQ

What is a PCI Service Provider? 

Any company that stores, processes, or transmits cardholder data on behalf of another entity is defined to be a Service Provider by the Payment Card Industry (PCI) guidelines. Visa’s website provides the clearest information about how the PCI Data Security Standard (DSS) applies to Service Providers. However, Visa is just one of the companies participating in PCI, so a Service Provider must understand and adhere to the security program for all major credit card companies with its own set of requirements for compliance and registration.

How do we know what Service Provider Level we fit in?

Each of the credit card companies that participate in PCI has its own rules that define Service Provider Levels. For example, Visa, whose rules are available on its CISP for Service Providers page, defines the levels based on the number of annual transactions. However, there is one very important distinction in Visa’s rules that is overlooked by many service providers. By Visa’s definition, any service provider that stores, processes, and/or transmits cardholder data as part of a payment transaction is a Level 1 Service Provider. So in other words, a company that has access to cardholder data as part of a payment is automatically defined to be Level 1.

MasterCard is also very clear in defining the levels for Service Providers for its SDP program. MasterCard defines two categories of Service Providers: Third Party Processors (TPP) and Data Storage Entities (DSE). The Service Provider Levels Defined page defines all Third Party Processors to be Level 1.

What are the requirements for becoming a Level 1 Service Provider in compliance with the PCI DSS?

There are two primary qualifications of a PCI Level 1 Service Provider. The first is the successful completion of an On-Site PCI Data Security Assessment that is validated by a Qualified Security Assessor. To pass the Data Security Assessment, the company must demonstrate compliance with 100% of the requirements detailed in the PCI Security Audit Procedures, which contains over 250 specific points of compliance. The second qualification is successful completion of a PCI Security Scan by an Approved Scanning Vendor. Given the complexity of meeting the requirements, the compliance process often takes more than one year to complete.

Leave a Reply