The owner of the merchant account requires to be PCI Compliant. If you're outsourcing transactions then this is cut back somewhat, and if you don't take any face-to-face transactions (ie have a POS device in your store), then SAQ-A would be most relevant (v1.2):
https://pcisecuritystandar
This requires you to implement strong physical/access controls on any card data onsite (for example, maybe you're printing it off, or have historical records?) and an information security policy that ensures there is a written agreement between yourself and any 3rd parties that handle cardholder data.
Authorize.net are soon up for re-certification (this month), but are currently compliant for customers in the US region (not sure about India?):
http://usa.visa.com/downlo
However, it's not enough just to refer to this document if asked by your acquiring bank or assessor - you need a contract in place to ensure that your providers remain PCI Compliant and take full responsiblity for any compromise that occurs. Remember that certification is a one-time process and in the case of Authorize.net, validated that they were PCI Compliant in Novemeber of last year. Who knows what's happened since...?
Main Topics
Browse All Topics





by: jason1178Posted on 2008-10-30 at 16:57:04ID: 22846628
Hi ldbkutty,
olutions/m erchantsol utions/ mer chantservi ces/ambiro ntrustwave /
There's a lot of noise about PCI DSS compliance at the moment and no one is really sure where things will end up. If there was a push to drop all e-commerce that is not PCI DSS compliant overnight, the economy would probably collapse, so don't treat this as a major emergency. However, compliance DOES make a difference as to the rates you pay on the transactions from the credit companies, so you should pay attention.
Right now, I am telling all of my clients to treat it as a best practices issue and to try to maintain compliance when possible. If you have the time and energy to read and redesign to comply, go for it.
Authorize.Net claims that they are in compliance:
http://www.authorize.net/s
so you would just need to make sure your end of things are okay.