Merchant and Requirements for Compliance

There are twelve basic requirements (organized in six areas) which a merchant must meet in order to become certified as PCI compliant. Each of these requirements, along with POS Vendor's recommendations, is noted in this document. However, you must familiarize yourself with the details of each requirement as set forth in the PCI Data Security Standard documentation. (Refer to Section 4 "Resources" for guidance on where to get more information.) The following table lists the twelve basic requirements.

PCI Topic

Basic Requirement

Build and Maintain a Secure Network

Install and maintain a firewall configuration to protect cardholder data.

Do not use vendor-supplied defaults for system passwords and other security parameters.

Protect Cardholder Data

Protect stored cardholder data.

Encrypt transmission of cardholder data across open, public networks.

Maintain a Vulnerability Management Program

Use and regularly update antivirus software.

Develop and maintain secure systems and applications.

Implement Strong Access Control Measures

Restrict access to cardholder data by business need-to-know.

Assign a unique ID to each person with computer access.

Restrict physical access to cardholder data.

Regularly Monitor and Test Networks

Track and monitor all access to network resources and cardholder data.

Regularly test security systems and processes.

Maintain an Information Security Policy

Maintain a policy that addresses information security.

Please send us your feedback on this help page.