To help prevent fraud and to protect cardholder data, the card brands created the Payment Card Industry Data Security Standard (PCI DSS). PCI DSS is a set of security requirements that affects all businesses that store, process, or transmit cardholder data.
PCI DSS requires you to:
- Build and maintain secure systems.
- Protect cardholder data.
- Protect your systems from malware.
- Control who can access cardholder data and systems.
- Monitor and test your systems regularly.
- Set and maintain clear security rules for your business.
Benefits of PCI compliance
When you comply with PCI DSS, you:
- Reduce the risk of data breaches.
- Protect your customers’ cardholder data.
- Protect your business’s reputation.
- Avoid non-compliance fees.
Consequences of PCI non-compliance
If you don't comply with PCI DSS, you increase the risk of:
- Cardholder data breaches
- Financial losses due to fraud incidents
- Damage to your business’s reputation
- Restrictions on your ability to process card payments
- Non-compliance fees
Note: Payroc charges a non-compliance fee for every month that you don’t comply. For more information about the fee, go to PCI compliance fees.
How to comply with PCI DSS
We automatically provide you with access to SecureTrust’s PCI Manager, which guides you through the steps you need to take to achieve and maintain PCI DSS compliance.
You can use the PCI Manager to complete Self-Assessment Questionnaires (SAQs) and run vulnerability scans and penetration tests on your network.
For more information about how to use the PCI Manager, go to SecureTrust PCI Manager.