Society of Payment Security Professionals Forum  

Go Back   Society of Payment Security Professionals Forum > Discussion Groups > PCI DSS Q&A

Reply
 
Thread Tools Display Modes
  #1  
Old 02-20-2007, 07:30 PM
K Heath K Heath is offline
Junior Member
 
Join Date: Feb 2007
Location: Sydney Australia
Posts: 12
Default Audit Timing

We have heard from an unconfrmed source that all Level 1 merchants should have an audit completed by 30th June. However, I haven't been able to find anything in print confirming this. My understanding was that audit timeframes were driven by the card brands, through the acquiring banks and that audits would be staggered across the year.

Is there any deadline that has been imposed by a card brand on level 1 merchants ?
Reply With Quote
  #2  
Old 02-20-2007, 07:47 PM
admin admin is offline
Administrator
 
Join Date: Feb 2007
Location: San Francisco, CA (USA)
Posts: 29
Default

I would contact the card brands/associations and acquiring banks for any deadlines. Presently, all merchants need to be compliant. Any "deadlines" are extension given based on the discretion of the responsible agent.
Reply With Quote
  #3  
Old 03-07-2007, 03:17 AM
K Heath K Heath is offline
Junior Member
 
Join Date: Feb 2007
Location: Sydney Australia
Posts: 12
Default Audit Timing

I have received confirmation from one of the card brands that, though PCI compliance is mandatory now, they have imposed deadlines for compliance audits for level 1 merchants. These card band imposed deadlines are not consistent across the various card brands and may differ from region to region.
Reply With Quote
  #4  
Old 03-07-2007, 08:20 AM
admin admin is offline
Administrator
 
Join Date: Feb 2007
Location: San Francisco, CA (USA)
Posts: 29
Default

This is correct. Remember that Visa and MasterCard work through acquiring banks, so you will always hear about their deadlines from your acquirer or gateway/processor.

As for American Express and Discover, merchants have a direct relationship with these card brands and will hear directly from them about any compliance deadlines. If you have not heard anything or don't know then be sure to ask about it. You can find contact email addresses here.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 04:21 PM.


Copyright (c) The Aegenis Group, Inc.