Forum Moderators: buckworks
1) If you simply transmit CC data to your payment gateway (lets use PayPal via Web Payments Pro for these examples), do you need to take exactly the same rigorous measures as if you were to store the data in your database? Or are there parts of the compliance that you can "leave out" so to speak? If so, what are they?
2) Is having a 128-bit SSL certificate (plus bulletproof code) enough to be able to collect the CC data and immediately transmit it to PayPal (again through a secure connection), assuming you're not storing the data?
3) Is being on a shared hosting account automatically considered "not compliant"? Are some web hosts better than others? How would one find out?
4) It seems every rinky-dink-looking website out there is accepting credit cards. Why does the process seem so common/easy for seemingly small shops, yet seem like there's so many hoops to jump through for a beginner? Is there something we're missing?
Another gimmick from the banks and card processors that care so deeply for us merchants...
... and, relevant to brandyace's post, the next step in throttling small U.S. businesses to extinction (or survival in spite of the stranglehold,) Red Flags Rule [webmasterworld.com].
PCI compliance is just the beginning.