<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PCI Compliance - Service Provider vs Merchant in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-Compliance-Service-Provider-vs-Merchant/m-p/71683#M44164</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will be providing a service to a client, where the end user logged on to our system can submit their payment information to Authorize .Net.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need help figuring out if we as a service provider need to be PCI Compliant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will either select the Accept Hosted option or Accept.js option (SAQ A or SAQ A-EP solutions.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I also found out here: &lt;A href="https://www.authorize.net/resources/blog/understanding-pci-compliance.html" target="_blank"&gt;https://www.authorize.net/resources/blog/understanding-pci-compliance.html&lt;/A&gt;, that PCI Valdiation requirements depend on the number of transactions as well, so does that fall on the merchant(the client) or us as service provider?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will just route the payment information to Authorize .Net, and we will only keep the last four of card number/ bank account and the transaction ID if available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my question really is, whether&lt;/P&gt;&lt;P&gt;1. Only we need to be PCI Compliant&lt;/P&gt;&lt;P&gt;2. Only the merchant needs to be PCI Compliant&lt;/P&gt;&lt;P&gt;3. We both need to get the same level of compliance&lt;/P&gt;&lt;P&gt;4. We will need to get different levels of compliance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I couldn't really find any thing that differentiates Service Providers and Merchants, so not sure what needs to be done in this case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: We will use the Merchant provided credentials while making calls to the Authorize .Net API.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Apr 2020 16:46:35 GMT</pubDate>
    <dc:creator>alimalik</dc:creator>
    <dc:date>2020-04-23T16:46:35Z</dc:date>
    <item>
      <title>PCI Compliance - Service Provider vs Merchant</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-Compliance-Service-Provider-vs-Merchant/m-p/71683#M44164</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will be providing a service to a client, where the end user logged on to our system can submit their payment information to Authorize .Net.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need help figuring out if we as a service provider need to be PCI Compliant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will either select the Accept Hosted option or Accept.js option (SAQ A or SAQ A-EP solutions.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I also found out here: &lt;A href="https://www.authorize.net/resources/blog/understanding-pci-compliance.html" target="_blank"&gt;https://www.authorize.net/resources/blog/understanding-pci-compliance.html&lt;/A&gt;, that PCI Valdiation requirements depend on the number of transactions as well, so does that fall on the merchant(the client) or us as service provider?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will just route the payment information to Authorize .Net, and we will only keep the last four of card number/ bank account and the transaction ID if available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my question really is, whether&lt;/P&gt;&lt;P&gt;1. Only we need to be PCI Compliant&lt;/P&gt;&lt;P&gt;2. Only the merchant needs to be PCI Compliant&lt;/P&gt;&lt;P&gt;3. We both need to get the same level of compliance&lt;/P&gt;&lt;P&gt;4. We will need to get different levels of compliance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I couldn't really find any thing that differentiates Service Providers and Merchants, so not sure what needs to be done in this case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: We will use the Merchant provided credentials while making calls to the Authorize .Net API.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 16:46:35 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-Compliance-Service-Provider-vs-Merchant/m-p/71683#M44164</guid>
      <dc:creator>alimalik</dc:creator>
      <dc:date>2020-04-23T16:46:35Z</dc:date>
    </item>
  </channel>
</rss>

