Skip to content

PCI Compliance Checks

Many of HWIT’s clients have received either an email or a phone call from a company wanting to sell them on PCI Compliance requirements.

It does outline that PCI compliance is a requirement according to Intuit’s Terms of Service. That means a few things:

  1. If you do not store credit card numbers, but simply have your customers enter them in when paying their invoices, you are compliant. There are regulations about server security, etc. that need to be met, but if your clients are entering them directly into Intuit’s server, you are compliant as Intuit maintains those security requirements already.
  2. If you do store credit card numbers for your clients, you have more obligations to fulfill to show compliance. In this case, you can hire the company in the ad email, or you can do a self-assessment if you qualify to do so. You can go straight to the horse’s mouth at https://www.pcisecuritystandards.org/

Almost all Home Watch companies would fall under a “Level 4” designation, which has some standards that should be followed and allows you to do a self-assessment. Processing less than 300,000 transactions in a year puts you in the Level 4. Most of these standards are basic and should be followed as a regular matter of cyber security anyway.

Details on the levels,are at this HWIT Link: https://hwit.me/pci

Self-Assessment guidance and instructions are here: https://listings.pcisecuritystandards.org/documents/SAQ-InstrGuidelines-v3_2_1.pdf

A direct link to the Self-Assessment Questionnaire is here: https://www.pcisecuritystandards.org/documents/SAQ_A_v3.pdf