View Single Post
  #30  
Old 06-01-2009, 09:23 PM
  markvo's Avatar 
markvo markvo is offline
 

Advanced Member
  
Join Date: Sep 2005
Location: Oregon
Posts: 52
 

Default Re: X-Cart and PCI-DSS / PA-DSS compliance

I agree that you should be okay if you allow all the credit card info to be handled by your merchant service provider and your shopping cart never sees this information. However, I believe it is the case that cart owners will need to prove this to their merchant service provider. Based on less than rock solid definitiveness, my sense is that ultimately each cart will need to pass the software audit in addition to the self assessment questionnaire. If your volume is high enough you will also need to pass the on-site audit.

There are 2 main benefits of allowing the merchant service provider to handle the entire credit card info trail. We avoid the devastating cost of lost credit card information and, if we're lucky, we might avoid the PA-DSS compliance requirement...TBD

Mark
__________________
Mark in Oregon
Xcart Gold version 4.1.8, 4.1.10
Linux
MySQL server 3.23.58
Apache 1.3.27
PHP 4.4.2
Reply With Quote