Forum Moderators: buckworks
Within days received a letter from NOVA that our web site does not meet security requirements set forth by VISA and MasterCard. We are unable to process orders. One Stop Merchant says they have never had this happen before and are working on the issue with NOVA.
Any ideas what may be going on here? Your insight/knowledge would be most helpful.
Thanks.
Will people be entering their credit card information on your site or going to a 3rd party site? If on your site, do you have SLL? If not, then that's your main problem right there.
For other compliance issues, go to visa.com and then do a search fro CISP.
Do go to visa.com and have a look at the CISP info. They have a self-assessment questionnaire that runs 8 pages. Some of it is pretty technical, so you may need to ask your hosting company about it.
Also, write back to NOVA and ask them exactly what's wrong so you can fix it. They should be more interested in helping you get compliant than banning you completely and cutting off an income stream.
CISP program info: [usa.visa.com...]
Self-assesmnet questionnaire:
[usa.visa.com...]
NOVA says they cannot do this since there is not a match between the name on the secure certificate and my company name.
It's probably an uphill battle to fight it with them, so see if you can get your own SSL (hey- I typed it right this time! :) ) to make them happy. It's a few hundred dollars at most/year. But if it greases the squeeky wheel and lets you go forward...
It seems that this might cause a lot of problems as well for merchants who use a shared SSL