THE CENZIC BLOG
Read more articles in  Web Application Security Insights
.
December 16, 2008

FAQs for PCI Compliance 6.6

Get a full list of PCI compliance 6.6 FAQs gathered from our live Web seminar

In case you have specific questions about PCI 6.6 compliance, then email me to get a full list of our FAQs gathered from our live Web seminar audience.  We take the time to list all the audience questions and answer each one, so take advantage of all our time and research and get a copy today.

Here are a couple Q/A examples below.

by
Erin Swanson
Eswanson@cenzic.com

Q:  Who is collecting the PCI fines and how?

A:  Fines are typically levied by VISA, MC, Discover etc. from the merchants and acquirers.  If a card company finds that the merchant is non-compliant they would send them a notice of non-compliance and ask them to pay penalties.

Q: Are there/what are the fines for levels 3 and 4? What are the drop dead dates for compliance by companies under versions 1.1 and 1.2?

A: Although there are no specific fines outlined by PCI, each credit card company can impose fines for non-compliance.  Right now, the guidelines are: Level 3 Merchants-Contact acquirer or credit card company; Level 4 Merchants-Must have compliance plan submitted, via acquirer, to Visa by July 30, 2007.   According to Visa, currently:

* 77 percent of Level 1 merchants were PCI compliant
* 78 percent of Level 2 merchants were PCI compliant
* 56 percent of Level 3 merchants were PCI compliant


Syndication OptionsRSS (Rich Site Summary) Feed Atom Feed OPML (Outline Processor Language) Feed MYST-ML (MyST Markup Language) Content Feed MS-Office Smart Tag Subscription