Diff: FAQ #1022

I?m a small merchant who has limited payment card transaction volume. Do I need to be compliant with PCI DSS? If so, what is the deadline?

Earlier Version
Later Version
Removed
Added
AllPCI DSS is intended for all entities involved in payment processing, including merchants, whetherregardless of their size or transaction volume.  When compared with larger merchants, small ormerchants large,often have simpler environments, with limited amounts of cardholder data and fewer systems that need toprotecting, bewhich PCIcan compliant.help Thereduce payment brands have collectively adoptedtheir PCI DSS ascompliance theeffort.  Whether requirementa forsmall organizations that process, store or transmit payment cardholder data. PCI SSCmerchant is responsiblerequired forto managingvalidate compliance is determined by the security standards while each individual payment brandbrands. is responsible for managing and enforcing compliance to these standards.

For questions regarding compliance validation requirements and deadlines as well as compliance reporting requirements, wemerchants recommend that youshould contact yourtheir acquirer.acquirer For(merchant morebank) informationor regardingpayment thebrand PCIthey securitydo standardsbusiness and supporting documentation, including the ?Navigating the PCI DSS?with, as well as targeted Self Assessment Questionnaires to assist small and medium merchants, please visit the PCI SSC website at: www.pcisecuritystandards.org.applicable.

Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.