To help our merchants and partners understand more about PCI DSS, we've prepared some questions and answers below, which outline our compliance with PCI DSS.
The Payment Card Industry Data Security Standard (PCI DSS) Program is a mandated set of security standards that were created by the major credit card companies to offer merchants and service providers a complete, unified approach to safeguarding cardholder data for all card brands.
The standard is made of 12 requirements which are validated by a QSA (Qualified Security Assessor) on a yearly basis.
PCI DSS 4.0 is the latest standard - find out more information here:
Merchants that have applied to use our payment solutions may be required to fill out an SAQ depending on their turnover and type of integration.
See the below table to find out more about the form you'll need then click the link below to access these.
| PCI Merchant Level | Annual Transaction Volume (per MID) | Typical Requirement |
| Level 1 | Over 6 million transactions annually | Full annual PCI assessment/audit and Attestation of Compliance. Quarterly ASV scans |
| Level 2 | 1 million – 6 million transactions annually | POS – Annual SAQ P2Pe |
| Level 3 | 20,000 – 1 million eCommerce transactions annually | Annual SAQ A and quarterly ASV scans |
| Level 4 | Fewer than 20,000 eCommerce transactions annually, or up to 1 million total transactions annually | No SAQ requested |
We know merchants need the security of their transactions as a priority and that's why we're fully compliant with PCI DSS. Compliance is validated yearly by a qualified security assessor who will ensure that all requirements within the standard are met.
Our compliance with the standard is designed to reduce payment card fraud by increasing our control of cardholder data.
Any organisation that processes, transmits or stores cardholder data must comply with PCI DSS. The PCI DSS standard is made of 12 requirements which are related to payment security
The standard assists organisations with determining the minimum requirements to protect cardholder data. Merchants can be comfortable in knowing their data is processed securely.
Merchants are always responsible for protecting cardholder data. Even if a merchant is not required to complete an SAQ the merchant should never write down, record, photograph, screenshot, copy, retain, transmit or store Cardholder Data or Sensitive Authentication Data except through DNAP-approved payment functionality and strictly in accordance with applicable PCI DSS requirements.
Get in touch with us to find out more about our fully compliant Payment Solutions for your business