Website Design North Wales & Chester
Move your shop Online
Do it Yourself
Does your club/group need a website?
Sell quickly on eBay

PSPs & PCI DSS

PCI SSC Logo

What is PCI DSS?

The Payment Card Industry Data Security Standard was developed by the Payment Card Industry Security Standards Council, PCI SSC, as a global security standard that is applied to any organisation that store, process or transmit cardholder data. Any such organisation must comply with PCI DSS version 1.2.

How do I comply with PCI DSS?

Each card brand has its own enforment programs and has specified requirements for complience. You could use a Qualified Security Assessor or a self-assessment questionnaire.

Which ever route you choose, you should thoroughly research the standard and speak with your merchant account provider. We beleive that most SMEs should be able to meet all of the criteria without the need to employ Security Assessors, but understand that for larger or financially affluent companies, bringing in an outside contractor may be an option.

Is there any way around PCI DSS?

No, if you process credit cards you have to comply, but there are ways of making this easier.

Using a compliant PSP, Payment Service Provider, to handle your online transactions means that some or all sensitive information covered in the standard is entered on their secure compliant website.

Most PSPs have the facility for MOTO, Mail Order Telephone Order, transactions. This will allow you to enter a customers details directly into the user interface whilst on the phone or to record the details and enter them in at a more convenient time. Remember, you must destroy or store that information inline with PCI-DSS.

You're probably already aware of PayPal. PayPal allow two independant parties to exchange funds using each others email address. While we encourage the use of PayPal as a secondary PSP, some customers may not have an account, and recommend that you use another as your primary payment method.

  • Actinic Payments
  • Protx
  • Nochex
  • HSBC

PCI DSS and Passwords

The PCI DSS requires you to change you PSP and computer hardware passwords at least every 90 days. Remember, if you've have a high turn over of staff or have let someone go recently, then perhaps you should update you passwords today.

Actinic Payments and PCI DSS

Actinic Payments Secure Shield Logo

Actinic Payments is a secure payment service powered by Creditcall. It was developed by Actinic specifically for users of their ecommerce software.

We have recently moved a client to Actinic Payments and are very impressed with it's intergration with Actiic's latest software release. It allows the merchant to view the payment status from within the ecommerce software, void, refund and if you have MOTO set up you can add to already downloaded orders.

Suggested PCI DSS Links

PCI Security Standards Council
Self Assessment Questionnaire
Streamline PCI DSS Guide
Actinic Payments

What have we done?
No extra costs.
Secure Card Processing
Get more visitors