I am now in contact with the PCI DSS Programme Director at Barclays.
Please can as many Barclays merchants as possible comment here on any experience they have with Security Metrics in the last three months. As I understand it, some changes were made a few months ago, so only recent experience is relevant.
Please can you explain:
- the date or approximate date of the discussions that you had
- what you were advised by Security Metrics and in particular what you were advised if you told them you used a PCI DSS compliant PSP and did not capture card details at your site
Once we have the information, I can go back to Barclays and ensure there are no mis-understandings among the parties.
My own understanding remains that if you use a PCI DSS compliant PSP and do not capture card details at your site, compliance is provided by your PSP.
Chris Barling
CEO, Actinic
Please can as many Barclays merchants as possible comment here on any experience they have with Security Metrics in the last three months. As I understand it, some changes were made a few months ago, so only recent experience is relevant.
Please can you explain:
- the date or approximate date of the discussions that you had
- what you were advised by Security Metrics and in particular what you were advised if you told them you used a PCI DSS compliant PSP and did not capture card details at your site
Once we have the information, I can go back to Barclays and ensure there are no mis-understandings among the parties.
My own understanding remains that if you use a PCI DSS compliant PSP and do not capture card details at your site, compliance is provided by your PSP.
Chris Barling
CEO, Actinic
Comment