<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integration methods that reduce PCI compliance in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Integration-methods-that-reduce-PCI-compliance/m-p/56253#M31059</link>
    <description>&lt;P&gt;Hi rob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case you have not already found more specific answers, my research indicates that Accept.js still achieves&amp;nbsp;a&amp;nbsp;&lt;SPAN&gt;PCI scope of&amp;nbsp;&lt;EM&gt;no less&lt;/EM&gt; than SAQ&amp;nbsp;A-EP (not the simpler SAQ A) due to its javascript&amp;nbsp;submission method and the fact that the cardholder data fields are&amp;nbsp;still&amp;nbsp;generated by your own website.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here are two articles that discuss this specifically:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.endertechnology.com/blog/notable-updates-authorize-net-july-2016" target="_blank"&gt;https://www.endertechnology.com/blog/notable-updates-authorize-net-july-2016&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paradoxlabs.com/blog/accept-js-paradoxlabs-authorize-net/" target="_blank"&gt;https://www.paradoxlabs.com/blog/accept-js-paradoxlabs-authorize-net/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here are some other resources that help clarify:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://pciguru.wordpress.com/2015/01/07/saq-a-and-saq-a-ep-clarification/" target="_blank"&gt;https://pciguru.wordpress.com/2015/01/07/saq-a-and-saq-a-ep-clarification/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://blog.sucuri.net/2016/06/navigating-pci-self-assessment-questionnaires-saq-ecommerce-websites.html" target="_blank"&gt;https://blog.sucuri.net/2016/06/navigating-pci-self-assessment-questionnaires-saq-ecommerce-websites.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://pciguru.wordpress.com/2011/11/12/of-redirects-and-reposts/" target="_blank"&gt;https://pciguru.wordpress.com/2011/11/12/of-redirects-and-reposts/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.pcisecuritystandards.org/pci_security/completing_self_assessment" target="_blank"&gt;https://www.pcisecuritystandards.org/pci_security/completing_self_assessment&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is also important to note that both SAQ A and SAQ A-EP &lt;EM&gt;&lt;STRONG&gt;only&lt;/STRONG&gt;&lt;/EM&gt; apply to e-commerce transactions and do not apply to&amp;nbsp;card-present situations (see that last article from the PCI Standards Council).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point, it appears that only the SIM hosted payment page can help you reach SAQ A compliance, so we all anxiously await the SIM replacement hosted page that will be&amp;nbsp;responsive and mobile-friendly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS&amp;nbsp;- I am not a PCI expert so it is advisable to do your own research. (That's my CYA, which is apparently the name of the game these days.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Fritz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Nov 2016 18:05:52 GMT</pubDate>
    <dc:creator>coppercup</dc:creator>
    <dc:date>2016-11-22T18:05:52Z</dc:date>
    <item>
      <title>Integration methods that reduce PCI compliance</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Integration-methods-that-reduce-PCI-compliance/m-p/56125#M30936</link>
      <description>&lt;P&gt;We are already integrated with Authorize.net AIM but would like to reduce PCI&amp;nbsp;scope. &amp;nbsp;We looked at the SIM integration method but were surprised that it's not responsive and honestly is not very attractive. &amp;nbsp;Then we looked at the Accept.js solution but that solution&amp;nbsp;(to our understanding) doesn't reduce our PCI scope as much as say a Stripe.js. &amp;nbsp;We are currently looking at Spreedly but honestly that seems really strange that we'd have to resort to a separate company altogether. &amp;nbsp;Am I just totally missing something?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 17:35:43 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Integration-methods-that-reduce-PCI-compliance/m-p/56125#M30936</guid>
      <dc:creator>rob</dc:creator>
      <dc:date>2016-11-07T17:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: Integration methods that reduce PCI compliance</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Integration-methods-that-reduce-PCI-compliance/m-p/56144#M30954</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/14697"&gt;@rob&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you've discovered, you can move to Accept.js and build your own form. &amp;nbsp;We are working on solutions to replace SIM that provide will be both responsive and help meet PCI DSS SAQ A, but that will coming in the next few weeks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2016 03:42:55 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Integration-methods-that-reduce-PCI-compliance/m-p/56144#M30954</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2016-11-09T03:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Integration methods that reduce PCI compliance</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Integration-methods-that-reduce-PCI-compliance/m-p/56165#M30973</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/7546"&gt;@RichardH&lt;/a&gt;! &amp;nbsp;We looked at Accept.js but my understanding is that from a PCI standpoint it isn't as good as a provider which hosts the credit card fields. &amp;nbsp;Is this an accurate statement? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2016 20:53:06 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Integration-methods-that-reduce-PCI-compliance/m-p/56165#M30973</guid>
      <dc:creator>rob</dc:creator>
      <dc:date>2016-11-10T20:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Integration methods that reduce PCI compliance</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Integration-methods-that-reduce-PCI-compliance/m-p/56166#M30974</link>
      <description>&lt;P&gt;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/14697"&gt;@rob&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest having a conversation with your QSA or merchant account provider. These solutions help meet PCI DSS requirements but you'll need to discuss with an expert on what is best for your organization.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2016 21:00:05 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Integration-methods-that-reduce-PCI-compliance/m-p/56166#M30974</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2016-11-10T21:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Integration methods that reduce PCI compliance</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Integration-methods-that-reduce-PCI-compliance/m-p/56253#M31059</link>
      <description>&lt;P&gt;Hi rob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case you have not already found more specific answers, my research indicates that Accept.js still achieves&amp;nbsp;a&amp;nbsp;&lt;SPAN&gt;PCI scope of&amp;nbsp;&lt;EM&gt;no less&lt;/EM&gt; than SAQ&amp;nbsp;A-EP (not the simpler SAQ A) due to its javascript&amp;nbsp;submission method and the fact that the cardholder data fields are&amp;nbsp;still&amp;nbsp;generated by your own website.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here are two articles that discuss this specifically:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.endertechnology.com/blog/notable-updates-authorize-net-july-2016" target="_blank"&gt;https://www.endertechnology.com/blog/notable-updates-authorize-net-july-2016&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paradoxlabs.com/blog/accept-js-paradoxlabs-authorize-net/" target="_blank"&gt;https://www.paradoxlabs.com/blog/accept-js-paradoxlabs-authorize-net/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here are some other resources that help clarify:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://pciguru.wordpress.com/2015/01/07/saq-a-and-saq-a-ep-clarification/" target="_blank"&gt;https://pciguru.wordpress.com/2015/01/07/saq-a-and-saq-a-ep-clarification/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://blog.sucuri.net/2016/06/navigating-pci-self-assessment-questionnaires-saq-ecommerce-websites.html" target="_blank"&gt;https://blog.sucuri.net/2016/06/navigating-pci-self-assessment-questionnaires-saq-ecommerce-websites.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://pciguru.wordpress.com/2011/11/12/of-redirects-and-reposts/" target="_blank"&gt;https://pciguru.wordpress.com/2011/11/12/of-redirects-and-reposts/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.pcisecuritystandards.org/pci_security/completing_self_assessment" target="_blank"&gt;https://www.pcisecuritystandards.org/pci_security/completing_self_assessment&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is also important to note that both SAQ A and SAQ A-EP &lt;EM&gt;&lt;STRONG&gt;only&lt;/STRONG&gt;&lt;/EM&gt; apply to e-commerce transactions and do not apply to&amp;nbsp;card-present situations (see that last article from the PCI Standards Council).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point, it appears that only the SIM hosted payment page can help you reach SAQ A compliance, so we all anxiously await the SIM replacement hosted page that will be&amp;nbsp;responsive and mobile-friendly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS&amp;nbsp;- I am not a PCI expert so it is advisable to do your own research. (That's my CYA, which is apparently the name of the game these days.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Fritz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 18:05:52 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Integration-methods-that-reduce-PCI-compliance/m-p/56253#M31059</guid>
      <dc:creator>coppercup</dc:creator>
      <dc:date>2016-11-22T18:05:52Z</dc:date>
    </item>
  </channel>
</rss>

