How can you get PCI compliant? Becoming PCI compliant means, you do not store credit cards after you process them or you are using the PCI compliance standard to store credit cards after your process them.
Some Shopping Carts (open source or those that require you to host your own) advertise themselves as PCI compliant. But their solution to PCI compliance is to not allow you to store credit card data for your clients. This is a simple answer to PCI compliance, but not the most convenient one. For example, by not having the ability to store credit card data, you:
If you host your own Shopping Cart software , YOU MUST be PCI compliant. Getting PCI compliant for your own hosted solution will require you to pay for:
These upgrades will cost you around $10,000 - $35,000 and a few thousand dollars annually. Shopping Cart Elite paid over $65,000 to get PCI complaint, in addition to paying a monthly maintenance fee to maintain the PCI compliance.
Shopping Cart Elite PCI Compliance
Shopping Cart Elite is PCI compliant, and we offer a much cheaper solution to the above costs.
First Solution: In Shopping Cart Elite settings, you can set it not to store credit cards, which will make you PCI compliant. Most merchant processors require proof of your PCI compliance, and if you fail to send it to them, they may bill you a penalty fee.
To get proof of your PCI compliance, you can contact Shopping Cart Elite staff to request a PCI compliance scan of your website ($125 fee) and fill out a self questionnaire (provided by Shopping Cart Elite) that confirms you are not storing credit card data.
Second Solution: Subscribe to a data vault partner. A data vault company, is someone who is PCI complaint and takes the liability of storing credit card data for you. You will still have to complete the first solution to show proof of your PCI Compliance, but by going with a data vault company you will also have the ability to store credit card data with Shopping Cart Elite (and avoid paying thousands of dollars in PCI compliance upgrades).
Shopping Cart Elite is PCI compliant and we protect our client data at all costs. But we outsource the data vault service to a third party partner because we are software provider and not a data vault provider.
Data Vaults have their own business model and liabilities that require special attention such as monitoring staff, hardware and software upgrades, liability funds, etc.
Internet Security is an evolving industry, the founders of internet did not expect it to be the size it is today. They did not design the infrastructure to be as secure as it needs to be today. Data vaults have more chance of minimizing breaches because they specialize in internet security, update their technology and software monthly, follow standards and protocols, and evolve in internet security industry as fast as the professional hackers do.
Our chosen data vault partner is Rek9 who is currently creating a custom monitoring software, on top of the infrastructure that PCI compliance requires. Rek9 integration with Shopping Cart Elite is scheduled to be released by 8/1/2010.
If you require a data vault service in the mean time, Shopping Cart Elite can accommodate it temporarily, until Rek9 integration is complete.