Maintaining Payment Card Industry Data Security Standard (PCI DSS) compliance is crucial for businesses handling customer payment information, with Segpay achieving Level 1 PCI-compliant service provider recertification for the 20th consecutive year in August. This ongoing commitment to security is vital as the PCI compliance landscape continues to evolve, with the current PCI DSS 4.0 standard addressing modern complexities like cloud infrastructure and remote workforces.

The Evolution of PCI Compliance

The major card brands established a unified framework in 2004 to protect cardholder data and reduce payment fraud. Before PCI DSS, each card brand had its own security requirements, leading to complexity and inconsistency. The unified framework now provides a standardized set of security requirements and a common language for acquiring banks, payment processors, payment facilitators, and technology providers.

The original PCI 1.0 standard focused on secure networks, protecting stored cardholder data, encryption in transit, secure systems, access restrictions, monitoring, testing, and written security policies. Security procedures must continually evolve to keep pace with fraudsters. The current version, PCI DSS 4.0, is designed for today's complex environments, including cloud infrastructure, mobile applications, software-as-a-service platforms, and remote workforces. This latest version emphasizes strong authentication and access management, security awareness and training, secure development practices, protection of cloud and virtualized environments, ongoing validation of security controls, and heightened awareness of payment page threats.

Cathy Beardsley, president and CEO of Segpay, noted that she helped write Segpay's original PCI policy documents more than two decades ago and has observed firsthand how PCI compliance has evolved. Segpay is a merchant services provider offering custom financial solutions, including payment facilitation, direct merchant accounts, and secure gateway services. Under Beardsley's direction, Segpay has become one of four companies approved by Visa to operate as a high-risk internet payment services provider.

Responsibilities for Merchants and Processors

Businesses that process, transmit, or store cardholder data need to achieve PCI compliance. Failure to attain PCI compliance or a breach can result in large fines, or in extreme cases, closure of an account and inability to accept credit card payments. A PCI-compliant processor should have appropriate policies and controls in place to protect cardholder data and demonstrate compliance through independent assessments and regular audits. Merchants should not assume their payment processor is PCI compliant simply because it processes payments.

PCI compliance is not handled solely by a payment processor; service providers also have significant PCI responsibilities. Many acquiring banks require merchants to complete the PCI DSS SAQ A (Self-Assessment Questionnaire). Merchants play an important role in PCI compliance by completing the PCI DSS SAQ A when required, using strong passwords, keeping software up to date, and training employees on security best practices. Merchants can verify if their payment provider is PCI compliant through Visa's Global Registry of Service Providers.

Behind the scenes, payment processors should continuously monitor their systems, validate security controls, apply updates, test for vulnerabilities, and document compliance. PCI DSS 4.0 places greater emphasis on ongoing security rather than simply passing an annual audit. PCI compliance is now part of an overall security strategy rather than a once-a-year certification. While the PCI assessment takes place annually, preparation begins the day the audit ends. Organizations must demonstrate daily that their security controls are working as intended. The goal is to keep pace with fraudsters, who are constantly adapting as payment systems become more secure.

Benefits of PCI Compliance

Working with a PCI-compliant service provider offers several benefits. Consumers are more likely to trust businesses that invest in strong payment security. PCI DSS helps safeguard card information, expiration dates, and other sensitive personal data, such as email and mailing addresses. Following PCI requirements also reduces opportunities for criminals to steal payment information and commit fraud. While no security standard can eliminate every cyber risk, PCI DSS requires organizations to maintain security controls that help detect, contain, and respond to attacks more quickly, reducing the impact of a potential breach. It also helps build confidence that businesses are following recognized security practices and treating customers' payment information responsibly.

Organizations with stronger security practices are generally better prepared to prevent or recover from cyberattacks, resulting in fewer service disruptions. Working with a PCI-compliant provider can also provide peace of mind for both businesses and consumers. PCI compliance helps make everyday card transactions more secure. Organizations that properly implement PCI controls are better equipped to prevent common attacks and minimize the impact if one does occur. For consumers, that means a lower risk of payment card theft and fraud, and less inconvenience from replacing compromised cards or disputing unauthorized charges.

Key Facts

  • Segpay was recertified as a Level 1 PCI-compliant service provider in August, marking its 20th consecutive year.
  • The PCI DSS framework was established in 2004 by major card brands to unify cardholder data protection.
  • The current standard is PCI DSS 4.0, designed for complex environments like cloud infrastructure and mobile applications.
  • PCI compliance requires ongoing validation of security controls, not just annual audits.
  • Merchants are responsible for completing the PCI DSS SAQ A, using strong passwords, and training employees.
  • Cathy Beardsley is president and CEO of Segpay, one of four companies approved by Visa as a high-risk internet payment services provider.