How Can I Prove PCI Compliance?

Created by Alsabana Sahubarali, Modified on Mon, 4 Nov, 2024 at 9:11 AM by Alsabana Sahubarali

Proving PCI compliance is difficult and more complex than it should be. Oftentimes there is a monthly penalty for lack of compliance. 
 
But, becoming compliant requires addressing many to-do's in your office, and then going through a cumbersome PCI self-audit process. We cover this in detail on the Intranet: [link].
 
After reviewing the PCI section on the Intranet and speaking to the relevant vendor and their PCI support/consulting providers, you'll learn that being in Cloud does not automatically make anyone PCI compliant. While we built Cloud to handle credit cards in a PCI compliant manner, your local PCI compliance for you as a merchant is related to many factors beyond what we can and have done with the design of Cloud. The Intranet link included in this article covers topics like local network security, scans, security policy, etc. - all of which are part of PCI compliance and outside of our control. 
 
An additional factor to consider is that we accept credit cards over the phone. The simple act of having a person take a card number over the phone and type it into the system completely changes the thresholds and requirements for you locally. They view the risk of someone typing that in (even though the card is gone and locked away after they hit save) as much greater than if the client enters it directly into a site (like you do when buying from Amazon). 
 
The best thing we can recommend is to call your vendor and ask them to put you in touch with the PCI support program they have in place for merchants. You can also contact those support vendors directly via the info noted on the Intranet. They will need to know that you are a moto vendor taking cards over the phone and help guide you accordingly. At the same time—if they have some new information to add to the process we have already put significant time into with the vendor—please tell them to contact Jeff and the Cloud team.
 
Please know this is a major pain for everyone, not just MaidPro, and that everyone agrees that the PCI system is incredibly outdated and burdensome—there's not a processor, business, developer, or merchant out there that doesn't think it needs a massive overhaul. If we could, we would change the PCI system top to bottom. 
 
This (and the Intranet link above) is all of the information we have on PCI Compliance.  If you still have additional questions, please contact an outside consultant.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article