Excuse me if I've overlooked something, but when reading Actinic's advice on PCI-DSS Compliance there seems to be a contradiction when comparing it with PCI Security Standard Council's own advice and requirements.
Actinic states:
"if you only take card payments for eCommerce orders using the web page of a compliant PSP, your website does not need a security scan, although it is still good practice to do one. You are SAQ validation type 1, and need to complete SAQ form A."
Actinic then states:
"if you take card payments for ecommerce orders using the web page of a compliant PSP, and also use the compliant PSP's web form for taking mail order related payments, you must get an external scan of your office network (to make sure hackers can’t get in from outside) and you are required to run a virus checker on every PC. You are a SAQ validation type 4, and need to complete SAQ form C."
When I read the notes on the PCI Security Standard Council's SAQ Form A it states:
"Such merchants validate compliance by completing SAQ A and the associated Attestation of Compliance, confirming that: "Your company handles only card-not-present (e-commerce or mail/telephone-order) transactions;"
and on SAQ Form C the PCI Security Standard Council states:
"Such merchants validate compliance by completing SAQ C and the associated Attestation of Compliance, confirming that: Your company has a payment application system and an Internet connection on the same device and/or same local area network (LAN);
Therefore, eCommerce and MOTO transactions appear to be covered by SAQ Form A not SAQ Form C, as Actinic claim, as SAQ Form C appears to cover card payment transactions (as I interpret it) using PDQ POS types of terminals.
Why does Actinic state that SAQ Form C applies to merchants who use a compliant PSP web form for eCommerce and MOTO transactions? That's not what PCI SSC appear to say on their SAQ form C?
I'm just starting out in eCommerce and I've arranged for Actinic Payments to be my PSP for all my transactions eCommerce and MOTO. I don't have another terminal for taking card payments. All my transactions will be by Actinic Payments who are PCI-DSS compliant. The majority of my orders will be online transactions where the customer is redirected to the Actinic Payments webpage from my Actinic eCommerce software. If I get a telephone/faxe/email order, I have insisted on my website that customers do not send me their card details. I will phone the customer back to obtain their card details. (Those details may temporarily written down on a piece of paper which will be destroyed after use). I will enter the card details into the Actinic Payments page within my Actinic eCommerce software. As far as I can tell I'm SAQ verification level 1, I don't need a website scan and I only need to complete SAQ Form A, unless someone can show me otherwise. Who needs to see the Form? My acquring bank is satisfied with me using Actinic Payments via Creditcall as my PSP.
Can you please clairify why Actinic appears to be contradicting PCI SSC SAQ Forms A and C? Actinic seem to be suggesting that I'm Level 4 and need to complete SAQ Form C and have my office network scanned. There is only one PC in my office with the eCommerce software on it. Which is correct?
If I went to Security Metrics and asked for my office network to be scanned, would it simply be their Desktop Scan package at $49.95?
Actinic states:
"if you only take card payments for eCommerce orders using the web page of a compliant PSP, your website does not need a security scan, although it is still good practice to do one. You are SAQ validation type 1, and need to complete SAQ form A."
Actinic then states:
"if you take card payments for ecommerce orders using the web page of a compliant PSP, and also use the compliant PSP's web form for taking mail order related payments, you must get an external scan of your office network (to make sure hackers can’t get in from outside) and you are required to run a virus checker on every PC. You are a SAQ validation type 4, and need to complete SAQ form C."
When I read the notes on the PCI Security Standard Council's SAQ Form A it states:
"Such merchants validate compliance by completing SAQ A and the associated Attestation of Compliance, confirming that: "Your company handles only card-not-present (e-commerce or mail/telephone-order) transactions;"
and on SAQ Form C the PCI Security Standard Council states:
"Such merchants validate compliance by completing SAQ C and the associated Attestation of Compliance, confirming that: Your company has a payment application system and an Internet connection on the same device and/or same local area network (LAN);
Therefore, eCommerce and MOTO transactions appear to be covered by SAQ Form A not SAQ Form C, as Actinic claim, as SAQ Form C appears to cover card payment transactions (as I interpret it) using PDQ POS types of terminals.
Why does Actinic state that SAQ Form C applies to merchants who use a compliant PSP web form for eCommerce and MOTO transactions? That's not what PCI SSC appear to say on their SAQ form C?
I'm just starting out in eCommerce and I've arranged for Actinic Payments to be my PSP for all my transactions eCommerce and MOTO. I don't have another terminal for taking card payments. All my transactions will be by Actinic Payments who are PCI-DSS compliant. The majority of my orders will be online transactions where the customer is redirected to the Actinic Payments webpage from my Actinic eCommerce software. If I get a telephone/faxe/email order, I have insisted on my website that customers do not send me their card details. I will phone the customer back to obtain their card details. (Those details may temporarily written down on a piece of paper which will be destroyed after use). I will enter the card details into the Actinic Payments page within my Actinic eCommerce software. As far as I can tell I'm SAQ verification level 1, I don't need a website scan and I only need to complete SAQ Form A, unless someone can show me otherwise. Who needs to see the Form? My acquring bank is satisfied with me using Actinic Payments via Creditcall as my PSP.
Can you please clairify why Actinic appears to be contradicting PCI SSC SAQ Forms A and C? Actinic seem to be suggesting that I'm Level 4 and need to complete SAQ Form C and have my office network scanned. There is only one PC in my office with the eCommerce software on it. Which is correct?
If I went to Security Metrics and asked for my office network to be scanned, would it simply be their Desktop Scan package at $49.95?
Comment