Attaining – and maintaining – PCI DSS (Payment Card Industry Data Security Standard) Compliance is an ongoing concern for ISVs. The PCI DSS was formulated to ensure that a comprehensive list of security standards to protect cardholder data was adopted globally. The payment brands (American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc.) have mandated that all businesses that store, transmit or process cardholder information must maintain compliance with PCI DSS. All of Capital's payment products are PCI DSS compliant, but we take it a step further by offering our Compliance Assistance Service Program - free of charge - directly to our ISV partners and their clients.
What ISVs Need to Know
There are different levels of PCI compliance depending on processing volume:
Businesses that process over 6 million Visa or MasterCard transactions a year are required to have an annual on-site review by a 3rd-party and quarterly security scans by a certified 3rd party for external IP addresses.
Businesses that process between 20,000 and 150,000 Visa or MasterCard transactions a year are required to have an annual self-assessment and quarterly security scans by a certified 3rd party for external IP addresses.
Businesses that process between 150,000 and 6 million Visa or MasterCard transactions a year are required to have an annual self-assessment and quarterly security scans by a certified 3rd party for external IP addresses.
All businesses not included in Levels 1, 2 or 3; annual self-assessment is recommended and quarterly security scans are also recommended.
Going through the audits required for PCI compliance can be daunting for any business. That's why Capital Payments offers a Compliance Assistance Service Program that helps our ISV partners and their clients achieve and manage PCI compliance. Our partnership with SecurityMetrics, a leading provider of PCI audit and scan services certified by the PCI Security Council as a Qualified Security Assessor (QSA) and Approved Scanning Vendor (ASV), provides our partners with tools, resources and guidance to achieve compliance. Once an ISV partners with Capital, we will conduct an analysis to assist with any necessary remediation efforts and help certify compliance - for free.

Additionally, Capital offers an ongoing quality assurance program that notifies our partners and clients of changes or updates to the compliance standards put forth by the payment brands, the PCI Security Council and various government entities.