Card data security standards.
WHAT THE STANDARD IS
A set of requirements imposed by the card schemes on anyone handling card data.
WHO IT APPLIES TO
Any party storing, processing or transmitting card data.
WHAT THE LEVELS DEPEND ON
Transaction volume, determining validation requirements.
WHAT THE REQUIREMENTS COVER
Network security Protection of stored data Encryption in transit Access control Monitoring and testing An information security policy
WHAT REDUCES SCOPE ENORMOUSLY
Never touching card data.
HOW THAT IS ACHIEVED
Hosted checkout, or fields served directly by the provider.
WHY THAT IS THE RIGHT DEFAULT
It reduces obligations from a substantial programme to a short questionnaire.
WHAT MUST NEVER BE STORED
The security code Full track or chip data The personal identification number
WHAT MAY BE STORED, IF PROTECTED
The card number, rendered unreadable
WHAT TOKENISATION PROVIDES
Charging again without holding the number at all.
WHAT VALIDATION INVOLVES
A self-assessment questionnaire, or an external assessment at higher volumes Vulnerability scanning
WHAT TO ESTABLISH
Which questionnaire applies to your integration.
WHAT TO NEVER ASSUME
That using a provider removes all obligations.