Announcement

Collapse
No announcement yet.

Easy PCI Compliance

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Easy PCI Compliance

    In March I switched merchant accounts from Wells Fargo to Fattmerchant because WF announced a 50% authorization fee increase. The fees at Fatt are about 20% lower than WF even before the increase, resulting in savings of several hundred $ per month. My total monthly credit card processing fees are now averaging 2.8%-2.9%.

    The downside of switching is that I had to complete a new PCI Self-Assessment Questionnaire. We all know what those are like, endless arcane questions that only an IT wizard like David Hubbard could answer. Much to my happy surprise, Fattmerchant took the info over the phone in a call that lasted less than 10-minutes. I wish Fattmerchant would change their name but otherwise, I am a very happy customer.



    Merchant service provider. Offering flat-rate, month-to-month, and no strings attached transparent credit card processing. Direct Cost + 0% Ultra Low Fees.
    Bill Dunn
    SunCam, Inc.
    http://www.SunCam.com
    [email protected]

    #2
    Bill,

    It's worth noting unless they're using an iFramed gateway (and we don't support anything by them natively) that you're likely not PCI compliant and they're simply telling you to do an SAQ-A since they know enforcement by Visa, etc... is lax unless you're a mega-merchant.

    In other words don't assume you're PCI compliant from what you've described above.
    Thanks,

    Rick Wilson
    CEO
    Miva, Inc.
    [email protected]
    https://www.miva.com

    Comment


      #3
      Originally posted by Rick Wilson View Post
      Bill,

      It's worth noting unless they're using an iFramed gateway (and we don't support anything by them natively) that you're likely not PCI compliant and they're simply telling you to do an SAQ-A since they know enforcement by Visa, etc... is lax unless you're a mega-merchant.

      In other words don't assume you're PCI compliant from what you've described above.
      Looks like they might use Authorize.net as the gateway?
      Leslie Kirk
      Miva Certified Developer
      Miva Merchant Specialist since 1997
      Previously of Webs Your Way
      (aka Leslie Nord leslienord)

      Email me: [email protected]
      www.lesliekirk.com

      Follow me: Twitter | Facebook | FourSquare | Pinterest | Flickr

      Comment


        #4
        Good chance that's the most commonly used Gateway we see. Using our native Auth.met nodule would not qualify you for a PCI SAQ-A unless you're also using MivaPay on top of it.
        Thanks,

        Rick Wilson
        CEO
        Miva, Inc.
        [email protected]
        https://www.miva.com

        Comment


          #5
          They do use Authorize.net and they do have IFramed available. We are not using it yet but we are working on implementing it because that will result in even more savings.

          Rick, I'll admit that it seems too good to be true. Would appreciate a full explanation of the downside.
          Bill Dunn
          SunCam, Inc.
          http://www.SunCam.com
          [email protected]

          Comment


            #6
            Bill,

            My point isn't about their rates, it's the idea that what they're offering has any impact at all on your PCI Compliance.

            A merchant processor using a third party gateway like Auth.net has no ability to verify your PCI Compliance and to the extent they're using that as a sales pitch (especially with you using our native Auth.net) module, then they're demonstrably "full of it" if that's what hooked you. They're in essence doing the opposite of what First Data was notorious for doing. First Data was notorious (through it's sales agents) of forcing on people a crappy PCI scan they could never pass and then "fining" them for it. This is essentially the other side of that poor sales practice, implying you're covered without any diligence and getting you hooked on their low rates.

            If you were to be hacked right now, you'd be found to be non-compliant and that you'd used the wrong SAQ when you filled out the questionnaire and ultimately liable for any penalities and they would likely have little or no liability in the process was my point.
            Thanks,

            Rick Wilson
            CEO
            Miva, Inc.
            [email protected]
            https://www.miva.com

            Comment


              #7
              Easy PCI compliance was never a part of their sales pitch, it was all about the rates.

              Bill Dunn
              SunCam, Inc.
              http://www.SunCam.com
              [email protected]

              Comment


                #8
                Bill,

                I'm confused then, you titled this Post Easy PCI Compliance? Why?
                Thanks,

                Rick Wilson
                CEO
                Miva, Inc.
                [email protected]
                https://www.miva.com

                Comment


                  #9
                  The easy PCI SAQ was a pleasant and unexpected surprise that came a month after I signed-up.
                  Bill Dunn
                  SunCam, Inc.
                  http://www.SunCam.com
                  [email protected]

                  Comment


                    #10
                    I think that's the disconnect here (and you wrote this very much like a promotion). I can say with certainty that you're not actually Compliant based on what you've described and I'm worried others will read this and follow your lead.
                    Thanks,

                    Rick Wilson
                    CEO
                    Miva, Inc.
                    [email protected]
                    https://www.miva.com

                    Comment


                      #11
                      It was a testimonial, not a promotion. I don't have a financial interest in the company and no one paid me to write the post. I think you have admonished me sufficiently that no one will be tempted to follow my lead.
                      Bill Dunn
                      SunCam, Inc.
                      http://www.SunCam.com
                      [email protected]

                      Comment


                        #12
                        Bill,

                        I was not trying to admonish you at all, I was legitimately confused. I saw a post about Easy PCI Compliance and then a testimonial for a merchant provider. If an unknown poster had posted that, I would have assumed it was spam, but since it was you and I know you from the Forums, I decided to ask and explain.

                        Good deal on the rates though.
                        Thanks,

                        Rick Wilson
                        CEO
                        Miva, Inc.
                        [email protected]
                        https://www.miva.com

                        Comment

                        Working...
                        X