Forum Moderators: buckworks
The new penalty structure:
Level 1 merchants, TPP's and DSE's: Up to 100.000 and USD 10.000 per day after 60 days, not to exceed 500.000
Level 2 merchants, TPP's and DSE's: Up to 50.000 and USD 10.000 per day after 60 days, not to exceed 500.000
Level 3 merchants, TPP's and DSE's: Up to 25.000 and USD 10.000 per day after 60 days, not to exceed 500.000
Who do they think they are? This really is a David vs Goliath story, although I can't see David winning this one. I am planning to give up right now, MasterCard is AGAIN changing their rules & regulations just to force us to be in compliance. I hate that company!
I don't think you have had a full PCI compliance, I think you have only registered your sales volume and number of orders per month.
A full PCI costs around 10,000 USD for 3PP companies. All merchants who have many sales and have their own direct merchant account with their own secure server have to be PCI compliant.
Level 4 is fewer than 20,000 visa e-commerce transactions per year. Level 3 is 20,000 to 150,000 visa e-commerce transactions per year.
So this is just visa transactions? If this is so, then many of us don't need to be in compliance? or does mastercard have a different policy (visa and mastercard transactions counted rather than just mastercard transactions?) - their web site is completely useless in describing what the minimum is...
BTW, our servers are quite secure and I keep security at the top of my list - I just think this compliance thing is totally stupid - the credit card cos. have ways of securing data but are slowwww to make things happen.
Although many companies do consider security issues in their normal activities, the audits of these security assessors are very strict and they will find every hole.
The good thing about this is that the small and (maybe) fraud sensitive 3PP will disappear. The bad thing might be that they will also rule out 3PP who are on a small budget and just can't afford to have all those security issues installed.
I guess only time can tell.