
PCI Compliance Scanning & SAQ
Making compliance easy...
| Sign up now and get your SAQ compliance certificate online quickly and easily for your merchant bank. | Sign up now for both the SAQ Compliance certificate and your PCI Scan Compliance certificate. |
|
![]() |
How to Become PCI Compliant?
In response to the marked increase in identity fraud and theft on the internet, the Payment Card Industry Security Standards Council (PCI SSC) was formed in 2006.
Shortly thereafter, they introduced a set of basic requirements that all online merchants must follow. These rules are known as the Payment Card Industry Data Security Standard (PCI DSS).
How does it work? Well, when a company makes the decision to sell goods or services on the internet, they must apply for a merchant service account. These accounts are typically granted by banks or other financial institutions. But since these institutions are held financially responsible for the actions of their clients, they must ensure that all merchant websites are secure. The tool that they use to accomplish this is the PCI DSS.
If a company cannot present proof that their website complies with PCI DSS, it will not be granted a merchant service account and it will not be permitted to sell goods or services on the internet. Let us take a moment to talk about what it takes to become PCI complaint. There are three basic tools that are used to access PCI compliance. The first is a Self-Assessment Questionnaire (SAQ), which every online merchant must complete at least once a year. The second is a Quality Security Assessor (QSA), which is an individual or organisation whose job it is to ensure that a company has met current PCI requirements. And the third and final tool is the PCI vulnerability scan.
When applying for a merchant security account, the bank or financial institution may request that all three validation tests be completed. At the bare minimum, they will insist that an SAQ be submitted. For larger accounts, a QSA report may be required.
The PCI vulnerability scan, on the other hand, is not always needed. Only companies that store credit card information on their servers will be asked to complete a quarterly scan.

