The Security Pub

Random Thoughts About Security

PCI-DSS will soon be a State Law

PCI-CardWhile the card brands have been pushing to get all organizations that accept credit cards for payments to be compliant with the well known payment card industry data security standard (PCI-DSS), there is still little enforcement especially for those smaller merchants. Merchants are broken down into 4 categories:

  • Tier 1 merchants are very large performing more than 6 million transactions each year.
  • Tier 2 merchants perform between 1 and 6 million.
  • Tier 3 merchants between 20,000 and 1 million, and lastly
  • Tier 4 merchants that do less than 20k. Smaller organizations have been reluctant to implement everything they need to do in order to be PCI compliant due to the time, cost, and expertise required.

For those companies that do business in the state of Nevada, it will soon be required by law to be PCI-DSS compliant. Nevada passed a law that goes into effect January 1, 2010 that will make this mandatory. Of course it was mandatory before, but it seems this could add additional penalties to those that are not compliant. It should also be a strong reminder for those that keep putting this off, that PCI compliance is not going away.