New Visa PCI Compliance Stats: Level 1s Up, Level 3s Down Slightly, Level 2s Down Sharply
Written by Evan SchumanNovember 1st, 2011
Level 3 merchants, whose compliance Visa only started making public this summer, have seen their relatively weak compliance numbers drop further, according to new figures the card brand released Monday (Oct. 31). Level 2 chains saw an even stronger drop, while Level 1s continued their improvement trend.
The numbers on their own are somewhat of a concern, given that compliance in any group is supposed to steadily improve. That's especially true with a new entry, such as Level 3s, which start at such a relatively low level of compliance. In this instance, though, the explanation for the compliance dip might lie in a recent increase in the number of Level 3s trying to get compliant.
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Already a Subscriber? Login Here
2 Comments | Read New Visa PCI Compliance Stats: Level 1s Up, Level 3s Down Slightly, Level 2s Down Sharply
Leave a Reply
Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.

-Christine

November 2nd, 2011 at 7:45 pm
One possible explanation for the drop in Level 2 compliance is MasterCard’s new compliance validation regime. This new (this year) process requires merchants have either a QSA or the company’s own Internal Security Assessor (ISA) sign off on their PCI compliance.
Based on my experience, there can be a world of difference between a company completing their own Self-Assessment Questionnaire (SAQ, aka the PCI honor system) and proving to an independent assessor that you meet each requirement and can prove it.
The new MasterCard compliance standards may be having the desired effect of improving not just compliance, but also security.
November 14th, 2011 at 12:15 pm
Mastercard pushed back the requirement for a QSA or certifed ISA to 2012. If the compliance percent went down this year, just wait unitl MasterCards compliance standards take effect next year.