Chase Paymentech - merchant services and credit card processing
site map faq glossary help search
 
About Us Solutions Partners Newsroom My Paymentech
Chase Paymentech Home | Solutions | Card Brand
Gift Cards Your Way

Solutions
FEATURED PRODUCT
POS SOLUTIONS
PROCESSING SOLUTIONS
CONNECTIVITY
REPORTING SOLUTIONS
PCI Security Compliance
- Requirements
- Risk Assessment
- Helpful Tips
- Contacts
- Frequently Asked Questions
FRAUD PROTECTION
GIFT CARDS
METHODS OF PAYMENT
MERCHANT SUPPORT CENTER
CONTACT SALES



Requirements
Guidelines and Information Provided by the Card Associations

Arrow Graphic Reporting
Arrow Graphic Obligations
Arrow Graphic Prohibited Data
Arrow Graphic General Guidelines about Fines


Reporting
Chase Paymentech reports progress toward PCI compliance for Level 1, 2, and 3 merchants prior to each of the following dates to MasterCard and Visa to mitigate potential fines.

First Quarter - End of March
Second Quarter - End of June
Third Quarter - End of September
Fourth Quarter - End of December

Merchants must become fully PCI compliant to prevent fines. As your acquirer, Chase Paymentech requests that all non-compliant merchants provide a compliance target date for the non-compliant items on a quarterly basis until fully compliant.

Obligations

Level Selection Criteria Validation Actions Validation Process Merchant Requirements
1
Arrow Graphic 6 million annual Visa or MC trans.
(all acceptance channels)
Arrow Graphic Incurred a compromise
Arrow Graphic Annual onsite security visit
- and -
Arrow Graphic Quarterly network scan
Qualified Independent Security Assessor or Internal Audit Staff with CISA designation if signed by company officer
Arrow Graphic Submission of successful Report on Compliance (ROC)
Arrow Graphic Quarterly scan showing no high vulnerabilities
2 1 million to 6 million annual Visa or MC trans. (all acceptance channels)
Arrow Graphic Annual PCI self-assessment questionnaire
- and -
Arrow Graphic Quarterly network scan
Arrow Graphic Validated by merchant
Arrow Graphic Qualified independent scan vendor
Arrow Graphic Submission of PCI self-assessment questionnaire with green rating
Arrow Graphic Results of quarterly scan showing no high vulnerabilities
3 20,000 - 1 million
Visa or MC
e-commerce trans.
Arrow Graphic Annual PCI self-assessment questionnaire
- and -
Arrow Graphic Quarterly network scan
Arrow Graphic Validated by merchant
Arrow Graphic Qualified independent scan vendor
Arrow Graphic Submission of PCI self-assessment questionnaire with green rating
Arrow Graphic Results of quarterly scan showing no high vulnerabilities
4 Others
(regardless of acceptance channel)
Arrow Graphic Recommended annual PCI self-assessment questionnaire
- and -
Arrow Graphic Recommended quarterly network scan
Arrow Graphic Validated by merchant
Arrow Graphic Qualified independent scan vendor
Arrow Graphic Compliance mandatory
Arrow Graphic Validation optional


back to top

Prohibited Data

Merchants and their services providers are allowed to store only the following data subsequent to authorization:
Arrow Graphic Cardholder Account Number

Arrow Graphic Cardholder Name

Arrow Graphic Card Expiration Date

Arrow Graphic Service Code

Card Verification Data (CVV2/CVC2/CID) and full content of the magnetic stripe can never be stored after authorization.


back to top

General Guidelines About Fines

Visa Fines MasterCard Fines
Arrow Graphic Non-compliance
1st violation - $50,000
2nd violation - $100,000
3rd violation - discretionary
Arrow Graphic Failure to report compromise - $100,000
Arrow Graphic Egregious violation - $500,000
Arrow Graphic Storing full track data
$50,000 initial fine
$100,000 monthly until issue is resolved
Failure to comply with the SDP mandate
Arrow Graphic Level 1 Merchants - Up to $25,000
Arrow Graphic Level 2 Merchants - Up to $5,000
Arrow Graphic Level 3 Merchants - Up to $5,000


back to top


For card association updates on data security, visit the Merchant Support Center


Contact Sales Contact Customer Service

Chase Paymentech Solutions | Privacy Policy | Terms of Use
© Copyright 2007, Chase Paymentech Solutions, LLC All Rights Reserved.