Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

Upcoming X-Cart v 4.4.6 (now renamed to 4.5.0) & PCI-DSS requirements

 
Closed Thread
   X-Cart forums > News and Announcements
 
Thread Tools
  #181  
Old 04-26-2012, 02:35 PM
  cflsystems's Avatar 
cflsystems cflsystems is offline
 

Veteran
  
Join Date: Apr 2007
Posts: 14,201
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

I feel like re-posting this - maybe QT missed it?
Can we get an answer please

Quote:
Just out of curiosity - how other carts can have updates and be certified? I can't imagine they are released bug free and I can't imagine they release bugs fixes once or twice per year and I can't imagine them paying big bucks every 2-3 months for being certified. So somehow they have managed to be certified, release bug fixes and new versions and stay in business. I guess there has to be a way then
__________________
Steve Stoyanov
CFLSystems.com
Web Development
  #182  
Old 04-26-2012, 04:55 PM
 
adammc adammc is offline
 

Member
  
Join Date: Feb 2012
Posts: 22
 

Question Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

Hi,

Does this mean that I cannot develop a payment processor / module for NAB Transact without forking out over $1000 for Xpayments??

This is the payment system that we were just about to begin to implement:
http://www.nab.com.au/wps/wcm/connect/nab/nab/home/business_solutions/1/3/12/4

What now do we need to do to use this method?
__________________
X-Cart Gold 4.4.5
  #183  
Old 04-26-2012, 11:23 PM
  ambal's Avatar 
ambal ambal is offline
 

X-Cart team
  
Join Date: Sep 2002
Posts: 4,129
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

No, that means you'll need to have your integration certified under PA-DSS with the PCI Council and that costs much much more.

Also, X-Payments doesn't integrate with that method of NAB. So you don't need to buy X-Payments here.

Alex


Quote:
Originally Posted by adammc
Hi,

Does this mean that I cannot develop a payment processor / module for NAB Transact without forking out over $1000 for Xpayments??

This is the payment system that we were just about to begin to implement:
http://www.nab.com.au/wps/wcm/connect/nab/nab/home/business_solutions/1/3/12/4

What now do we need to do to use this method?
__________________
Sincerely yours,
Alex Mulin
VP of Business Development for X-Cart
X-Payments product manager
  #184  
Old 04-26-2012, 11:45 PM
 
adammc adammc is offline
 

Member
  
Join Date: Feb 2012
Posts: 22
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

Quote:
Originally Posted by ambal
No, that means you'll need to have your integration certified under PA-DSS with the PCI Council and that costs much much more.

Also, X-Payments doesn't integrate with that method of NAB. So you don't need to buy X-Payments here.

Alex


Hi Alex,

Thanks for the reply.
Is that certification needed only in the US at the moment or ALL of the world ?
So I can still do a custom integration for NAB's direct post gateway without any hassle?
__________________
X-Cart Gold 4.4.5
  #185  
Old 04-27-2012, 04:27 AM
  totaltec's Avatar 
totaltec totaltec is offline
 

X-Guru
  
Join Date: Jan 2007
Location: Louisville, KY USA
Posts: 5,823
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

Its a global standard Adam. It is set by the PCI council which is formed of the major credit card companies (visa, amex, mc, discover, jcb)

https://www.pcisecuritystandards.org/organization_info/index.php
__________________
Mike White - Now Accepting new clients and projects! Work with the best, get a US based development team for just $125 an hour. Call 1-502-773-6454, email mike at babymonkeystudios.com, or skype b8bym0nkey

XcartGuru
X-cart Tutorials | X-cart 5 Tutorials

Check out the responsive template for X-cart.
  #186  
Old 04-27-2012, 05:07 AM
 
adammc adammc is offline
 

Member
  
Join Date: Feb 2012
Posts: 22
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

[quote=totaltec]Its a global standard Adam. It is set by the PCI council which is formed of the major credit card companies (visa, amex, mc, discover, jcb)

So what must I do to develop a new payment system / processor for 'NAB Transact that conforms with PA-DSS?

On their info page it states
Quote:
"With NAB Transact Direct Post you can have Payment Card Industry Data Security Standards (PCI DSS) compliance and still host your own payment page"
__________________
X-Cart Gold 4.4.5
  #187  
Old 04-27-2012, 07:36 AM
  cflsystems's Avatar 
cflsystems cflsystems is offline
 

Veteran
  
Join Date: Apr 2007
Posts: 14,201
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

This material is so confusing (the PCI) in any aspect that you have to go to the source. Don't count on forum users to tell you what to do as most of us don't even know for ourselfs. Ask the payment gateway what they mean by that. Ask your bank if they will accept something like this and if not what they will accept. Read the PCI docs - they do mention scenarios when you develop your own payment application - if not clear email CC companies... And keep records of everything they tell you and who told you what so you don't end up being blamed for something,...

As you can see in this thread there are so many questions and not a straight answer to any of them...
__________________
Steve Stoyanov
CFLSystems.com
Web Development

The following 2 users thank cflsystems for this useful post:
ambal (04-29-2012), klinetim (04-27-2012)
  #188  
Old 04-27-2012, 09:52 AM
 
joelrhome joelrhome is offline
 

Advanced Member
  
Join Date: Dec 2003
Posts: 89
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

I agree with Steve. I do see one constant though. All merchants must be PCI Compliant, and it is an overall process that involves the merchant and how they handle cc data both offline and online. X-Cart is just one component that is related to the SAQ(Self Assessment Questionnaire). That question is something like "Do you process credit cards online?". If someone has a website, most likely they will think "Of course I do" and select Yes on the SAQ. The fact is, you only need to answer yes if you use en embeded gateway directly into X-Cart such as Authorize.net AIM. At this point, X-Cart becomes "In Scope" for PCI DSS Compliance Validation. This is why solutions like X-Payments takes X-Cart "Out Of Scope" for PCI Validation. It is because the cc info is entered into X-Payments(Validated), not X-Cart(Not Validated). Other methods of taking X-Cart "Out of Scope" are to use a hosted payment page. This is where a customer enters cc info on a separate page after checkout, thus taking customers away from X-Cart which is proven to have a decrease on sales conversion. Keeping customers on the website is the best way to go.

So...We had this dilemma, and we searched for a solution. When we could not find a solution that would please our customers and be 100% certain that it would take X-Cart "Out of Scope", we decided to take it upon ourselves to create a solution. As of yesterday, we are a Certified Software Partner with Accelerated Payment Technology, and their PCI DSS Compliant Validated middleware, XCharge, is now integrated into a module for X-Cart. We are offering our module for free of charge to anyone who switches their payment processor to X-Charge. I want to make this available to anyone who wants to go this route, and we made a page on our website that has screen shots and a brief explanation of everything. http://www.dxweb.net/xcharge.html

The best thing about them is that they match or in most cases beat out your current rates.

The only thing that this will cost is the time it takes to switch your payment processing over to XCharge. Once approved, we will deliver the Module for installation. If anyone has any other questions that aren't clear on my website, feel free to contact me.
__________________
Joel Rhome
x-cart 4.4.X
  #189  
Old 04-27-2012, 09:59 AM
 
joelrhome joelrhome is offline
 

Advanced Member
  
Join Date: Dec 2003
Posts: 89
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

One Quick thing I forgot to mention.. This solution is only for US US Currency. It also only removes X-Cart from PCI Compliance, not necessarily the merchant. You still need to be compliant in other areas of your business.
__________________
Joel Rhome
x-cart 4.4.X
  #190  
Old 04-27-2012, 01:14 PM
  tam10's Avatar 
tam10 tam10 is offline
 

eXpert
  
Join Date: Mar 2007
Posts: 252
 

Default Re: Upcoming X-Cart v 4.4.6 & PCI-DSS requirements

Joel, what do you refer to by "other areas"?
__________________
Tammy
x-cart gold + 4.7.2
x-cart 5.2.10

Closed Thread
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 06:36 PM.

   

 
X-Cart forums © 2001-2020