PCI level for credit card storage

I'm just wondering what the level of PCI certification will be if you keep encrypted credit card numbers for billing again.

I plan to have less than 20,000 transactions per year, but I'm not sure if I save credit card numbers.

+5
source share
1 answer

If you really (really) need to store card numbers, you fall into the most stringent PCI compliance level. This requires an annual on-site audit, a quarterly network scan, and (as you already know) will be very expensive. This is independent of the number of transactions. (The old first PCI drafts gave different levels depending on the number of cards processed. This is no longer the case)

/ , , , (SAQ) . , . ( ) , / /

, , QSA (Qualified Security Assessor). , , . , , QSA, PCI.

+5

All Articles