SWIPE ACADEMY - CONFIDENTIAL AGENT RESOURCE ================================================================= PCI-DSS COMPLIANCE FACT SHEET ================================================================= The Payment Card Industry Data Security Standard (PCI DSS) THE FOUR LEVELS OF COMPLIANCE: Level 1: Over 6 million transactions annually (Requires strict on-site audit by QSA). Level 2: 1 to 6 million transactions annually (Requires SAQ). Level 3: 20,000 to 1 million e-com transactions annually. Level 4: Under 20,000 e-com transactions, or under 1 million physical swipes. (This is 99% of your portfolio). SAQ TYPES: SAQ-A: E-commerce sites that outsource ALL payment processing to PCI DSS validated third-party providers (Hosted IFrames). The easiest to pass. SAQ-D: Merchants who store raw card data locally. The hardest to pass. Avoid this at all costs. THE FINE STRUCTURE: Non-Compliance Fee: Processors usually charge the merchant $19.95 to $39.95 a month if they fail to fill out their annual SAQ. Data Breach Fines: $5,000 to $100,000+ per month until compliance is achieved.