1
3 Comments

Certificate of Attestation for PCI Compliance: I need help.

I need help understanding what requirements I would need to satisfy this "Certificate of Attestation for PCI Compliance".

What is the PCI DSS Attestation of Compliance?
Your company must attest that it is complying with the Data Security Standard annually, if it handles credit card data electronically. This involves delivering a package of two or three items:
1. Self Assessment Questionnaire
2. Regular network or web site scanning by an Approved Scanning Vendor (may not be required in some cases) and a Report on Compliance by a Qualified Security Assessor (only needed by the very largest companies)
3. Attestation of Compliance
There are versions of the Attestation of Compliance, just as there are 5 versions of the Self Assessment Questionnaire. If you qualify to use version A of the Questionnaire, use version A of the Attestation, etc.

I don't have a high number of transactions. The only way I plan on processing transactions is through a web portal that is completely managed by stripe and I don't touch any credit card data (not even to do customer sign ups manually). So based on that, what do I fill out? This process seems like bureaucratic hell and need to satisfy this certification for a data partner. There are multiple version of the forms mentioned for 1, and 3. I'm not sure if 2 is strictly necessary for my situation. Any input would be appreciated.

posted to Icon for group Legal, Tax, and Accounting
Legal, Tax, and Accounting
on June 23, 2020
  1. 1

    Good afternoon. This is an important question now because there are a lot of businesses online and people who are going to use any product, want to have a feeling of safeness when they pay for it. I recommend you to check clear information about PCI DSS payment solutions on https://www.verygoodsecurity.com/compliance-solutions/pci. You can ask any specific question there as well.

  2. 1

    Nevermind, I believe I figured this out.

    1. 2

      This comment was deleted 4 years ago.

      1. 1

        Thanks! I understand your reasoning. I had to tick a box and submit paperwork to a data partner to further access to their API. Understandably stripe does handle pretty much everything, and I have been quite intentional about that. I don't want to handle credit card data if I don't have to. However, I didn't have the minimum 20 transactions or so through stripe where they could handle the form(s) automatically. I ended up filling out a SAQ A and AOC form from PCISS site and submitted that.

Trending on Indie Hackers
I built a text-to-video AI in 30 days. User Avatar 64 comments What 300 Builders Taught Us at BTS About the Future of App Building User Avatar 52 comments I built something that helps founders turn user clicks into real change 🌱✨ User Avatar 49 comments From a personal problem to a $1K MRR SaaS tool User Avatar 30 comments You don't need to write the same thing again User Avatar 29 comments How An Accident Turned Into A Product We’re Launching Today User Avatar 28 comments