PCI Compliance, PA-DSS, and our shopping cart software
Compliance with the Payment Card Industry (PCI) cardholder data security standards is a requirement for all Internet merchant. It makes sense. All Web stores should adhere to a common set of security measures to protect everyone's confidential information.
Here you will find answers to frequently asked questions about PCI compliance and ProductCart.
Can my ProductCart-powered store be PCI compliant?
Yes, ProductCart v4 is PA-DSS validated. This means that it has been audited and verified to be compliant with the strict requirements of the Payment Application Data Security Standards (PA-DSS).
This, however, does not mean automatic PCI compliance. ProductCart is only one element of your e-commerce business, and other elements of your business (e.g. your Web hosting environment, your payment gateway, your own internal payment data handling practices, etc.) must be compliant as well.
What should I do to obtain a certificate that says that my store is compliant?
You need to sign up for PCI compliance testing with one of the companies that offer this service. There are many vendors that offer this service. We have partnered with McAfee - one of the leaders in the field - to offer you FREE PCI compliance testing. Learn more about free PCI compliance testing from McAfee.
Can software like ProductCart automatically grant PCI compliance?
No, a software application like ProductCart cannot by itself grant a Web store that uses it the status of "PCI Compliant". That's because PCI compliance refers to the entire ecommerce system that powers your store, including your Web hosting environment and the payment gateway used for credit card processing. However, the fact that ProductCart is PA-DSS approved represents a big step towards demostrating that you are compliant.
The PCI compliance testing service that you sign up with will ask you questions about your entire ecommerce system (e.g. where you are hosted, which payment gateway you are using, etc.).
Will Early Impact assist me in my PCI compliance testing?
No, the PCI compliance testing provider that you sign up with will provide customer service throughout the process. What we have done is to certify ProductCart v4 through the PA-DSS program, as mentioned above. The fact that you are using a PA-DSS certified shopping cart system represents a major step towards PCI compliance.
So... what's next?
- Upgrade your ProductCart-powered store ProductCart v4.
Enroll in the ProductCart Support & Updates Plan to obtain the v4 Upgrade (free under the plan).
- More about ProductCart, PA-DSS, and PCI compliance, including the PA-DSS Implementation Guide.
Sign up for free PCI compliance testing with McAfee.
McAfee® PCI Compliance Service is a simplified, easy-to-use system that enables Level 2-4 merchants to successfully satisfy PCI DSS compliance requirements. And you also have the opportunity to sign-up for McAfee Secure, which is proven to help you increase sales!
|