>>2. All the requirements for PCI compliance are actually met. The client will count as a level 4 merchant - If so I presume they will need to do the self assessment questionare and have regular 'security scans' by a third party ? (Again, wording is vauge)<<
Yes, you need to complete the scan / questionnaire. However, Level 4 merchants have no set date to be compliant (Breaking Down the Levels of PCI DSS)- this is set by the merchant account provider. Some providers require their compliance now, while some have not set a date. But to protect yourself, you should be compliant - if a breach happens, the merchant can be fined and placed on the TMF / MATCH list. This could cause problems in getting a merchant account, cause the discount rate to be higher, and require the merchant to have a rolling reserve.
Check out Comodo for some PCI scanning solutions.





by: hmarePosted on 2009-08-11 at 05:51:02ID: 25068357
Contact the payment handler and the bank. They can tell you if compliance scans are necessary, and sometimes they will even pay for it.