Spectra
North American Bancard
United Bank Card
Wausau
July 30, 2010


News
Current Issue
Subscribe
Advertise
Archive
About Us
Contact Us
Calendar
Buyers Guide
Web Transaction
Performance Indexes
NEW! Data on outage hours

Bill2Phone
PCI Expert Cautiously Optimistic As Compliance Rate Looks to Climb

(July 7, 2006) Of 232 large U.S. merchants identified by Visa USA in 2004 and 2005, some 23% now comply with the Payment Card Industry data-security standard (PCI), but 73% are projected to be in compliance by the end of the year “based on progress reports,” says Michael Dahn, president of Volubis Inc., a San Francisco company that has contracted with Visa to help train PCI assessors and educate merchants on the standard.

Although the compliance statistics seem to indicate merchants are climbing on the PCI bandwagon in the wake of a long series of well-publicized data-security breaches, Dahn cautions that the numbers refer only to those merchants identified by Visa in 2004 and last year. “What about the ones identified in ’06, how long will it take them to comply?” he asks. At the same time, he says, a number of factors continue to slow down compliance rates, from technical and logistical difficulties to cost issues. A large chain merchant, for example, might have to change out point-of-sale software at each of hundreds of stores. “The compliance process is difficult, and merchants are looking for a reason to comply, looking to their acquirers for lower interchange, for example,” Dahn notes.

Dahn, who says he recently conducted an educational session on PCI for 150 large retailers, says a lack of understanding of how the standard applies to their networks is also causing merchants to drag their feet. “For large organizations, they are facing a really complex system,” he says. Many aren’t aware, for example, of the standard’s allowance for so-called compensating controls, which permit merchants to satisfy certain rules using less costly measures. One merchant, for example, met a requirement for file-integrity monitoring, which could have triggered huge software costs, by using “an open-source product that did not require them to incur a per-license fee,” making it cheaper to install on the company’s multiple servers, Dahn says.

Still, Dahn is cautiously optimistic about PCI compliance. “You’re seeing [the payment industry] move very slowly toward compliance,” he says. “Rolling out a compliance program is like turning the Titanic. It’s a long process that takes a while.”

Introduced in January 2005 and backed by MasterCard Inc., American Express Co., Discover Financial Services Inc., and other card companies as well as Visa, PCI sets out rules for the handling and storage of card data by merchants and processors. Among these, for example, are requirements for data encryption and anti-virus protection. Merchants are prohibited from storing any data other than account number, name, and expiration date.







Visa Hopes It Can Come to Terms with the Justice Department
Barely a week after Congress landed a hard left punch on the card networks, the U.S. Department of...

The Emerging Case for a Rules Change to Force Same-Day ACH
With the Federal Reserve set to begin offering on Monday same-day clearing of automated clearing...

Acculynk Scores Again, This Time with Its MasterCard Pact
Just two weeks after announcing its biggest EFT network partnership with the Discover Financial...

Some NFC Consensus Emerges, Thanks to Fed Mediation
Executives with a number of the leading players in telecommunications and electronic payments have...

The Dodd-Frank Interchange Haircut Could Exceed $10 Billion
Visa and MasterCard debit card issuers stand to lose up to $10.7 billion in interchange income a...

Regulation, Economy Weigh on Acquiring Executives’ Minds
In a year when Congress is beefing up regulation of the financial system, merchant-acquiring...

PayPal Sees Transaction Growth Level off in the Latest Quarter
The nation’s sluggish recovery from a long and deep recession kept second-quarter transaction...

Square’s Founder Says the Main Act Is About To Begin
After taking a time out in June to resolve problems ranging from a parts shortage to merchant...


Copyright 2010 by Boland Hill Media LLC. All the text, graphics, audio, design, software, and other works are
the copyrighted works of Boland Hill Media LLC. All rights reserved. Any redistribution or reproduction of any
materials herein is strictly prohibited.
Privacy policy