trends

PCI DSS Compliance for Paysites

PCI DSS stands for Payment Card Industry Data Security Standard. PCI DSS is a Compliance standard developed in late 2004 by the main credit card companies as a method of preventing credit card fraud, hacking and security threats and vulnerabilities.

In September, 2006, the PCI DSS standard was updated to version 1.1 from 1.0 to provide some minor revisions to the original version. The next revision of PCI DSS compliance is scheduled for late 2008.

PCI DSS Compliance is not an option and is required on any site which accepts credit cards as a form of payment. Any site accepting credit cards must comply with particular standards which are based primarily on the way in which a domain is secured. Non PCI DSS compliant issues may include; open ports on a server, firewall holes, non-standard applications or applications which have not been upgraded to their latest and most secure versions.

In order for a site to be PCI DSS compliant, it must provide a report if audited by a Qualified Security Assessor (QSA) whenever requested. If the owner of site which accepts credit cards cannot prove that it meets the PCI DSS requirements, they may lose their ability to process credit cards on their sites and thereby their ability to process credit card transactions.

The amount of times a PCI DSS scan is required in order to be PCI DSS compliant depends upon the total number of transactions completed each year by that domain.

Sites and payment card service providers must validate their compliance periodically. This periodic validation is conducted by auditors who are the PCI DSS Qualified Security Assessors (QSAs). Site owners who are processing less than 80,000 transactions per year are allowed to perform a self-assessment questionnaire. Sites that process larger amounts of transactions can only be approved as compliant by a qualified QSA on behalf of the PCI DSS council.

It does not matter if you use a shopping cart, membership or VOD site, and it does not matter if you host the payment pages where the customer puts in their credit card information or if you use a gateway processor like Netbilling or DHDmedia who hosts those pages for you. You must still conform to keeping all data that is collected safe and meets the guidelines of the PCI Security Standards Council; otherwise you may be liable for huge fines. Sites that process, store or even transmit payment card data must be PCI DSS compliant or risk losing their ability to process credit card payments and risk being audited or fined. PCI DSS fines can be as high as $500,000 per incident.

A prime example of what could happen if you fail to implement or adhere to the PCI DSS compliance can be found in the March, 2007, case of a company called TJX Companies, Inc., — the owner of T.J Maxx and Marshall's department stores, which faced more than a dozen class action lawsuits in Alabama, California, Massachusetts, Puerto Rico and six Canadian provinces, for what has been called the single largest data breach in U.S history.

TJX revealed in 2007 that hackers compromised at least 45.7 million credit and debit cards from the period of July, 2005, until the discovery was made in December, 2006. In a regulatory filing made with the Securities and Exchange Commission (SEC) after the violation, TJX stated that its computer systems were first hacked in July, 2005, by one or more intruders, but did not find out about the breach until much later. TJX recently estimated that the breach will cost them about $118 million. The estimate after legal fees and regulatory fines put the costs at over $1.35 billion.

So how can you keep yourself PCI DSS Compliant? The simplest method of making sure your site meets the PCI DSS compliance requirements is to use a PCI DSS scanning company like McAfee Secure. McAfee Secure has a program which costs around $319 a year for four devices and can scan your servers to make sure they meet the PCI DSS requirements and provide the report you need in case your site ever gets audited by the PCI DSS council.

Remember, that any server which has anything to do with your payment process must be PCI DSS compliant. This may include your NATs server if you are sending information to a gateway; your payment pages (where customers put in their card information on a secure page); your server if it sends out payment information to another server (in the case of cross selling).

When you have your domains scanned for PCI DSS compliance, they are scanning the servers, checking to see what kind of information they can obtain from that server similar to what a hacker might do. (One of the things worth mentioning here is that when you employ a PCI DSS scanning company to scan your server, it may cause your website statistics to become erratic and inaccurate as the PCI DSS scanner will hit pages randomly, every day. It may also increase the amount of 404's or 'page not found' errors in your reports. If you can find a way to purge their scanning servers from your statistics it will eliminate possible stat confusion.)

Another item of note is to make sure that you have total control over your servers. I would never recommend putting your pay pages or any part of your payment process on any server which you do not have root access to. In order words, any server which is either co-located (owned by you) or dedicated would be fine. I have seen many instances where servers have been comprised by scripts (such as CGI scripts or mail forms) running on an unsecured shared server.

Another item to keep in mind is that if you are running a program like NATS, which hosts a pre-payment form asking the client to put in their name, country and email, it may be prudent to secure that server as well. Since your NATS server hosts the this pre-payment form and this form passes over this information to a payment gateway, a hacker could use vulnerabilities in your server to get this information and get the rest from a gateway which is not secure and both of you could be liable.

In my opinion is always best to protect yourself by making sure that any server which accepts any information in the payment process be secured. Adding a Hacker Safe logo can also help customers feel more at ease with your payment process and thereby may be more willing to fill in your pre-payment page or self-hosted payment pages.

If you are curious if your payment gateway is PCI DSS compliant, you can go to Visa's compliant list of service providers. Some of the processors which are PCI DSS compliant include Linkpoint; CCBill; DHD Media; Epoch; eProcessing Network; Jettis; Netbilling; and Rocketgate.

PCI DSS compliance is a necessary part of processing credit cards online and cannot be taken likely. Hackers are always looking for vulnerabilities to exploit. I recently spoke to someone on the VISA council which estimated that only about 40 percent of all sites are currently PCI DSS compliant.

Make sure your payment process is PCI DSS compliant and protect your business. If you have any questions on how to get your site PCI DSS compliant, please don't hesitate to contact me at cs@integrationmind.com.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

profile

WIA Profile: Laurel Bencomo

Born in Cambridge, England but raised in Spain, Laurel Bencomo initially chose to study business at the University of Barcelona simply because it felt familiar — both of her parents are entrepreneurs. She went on to earn a master’s degree in sales and marketing management at the EADA Business School, while working in events for a group of restaurants in Barcelona.

Women In Adult ·
profile

Gregory Dorcel on Building Upon His Brand's Signature Legacy

“Whether reflected in the storyline or the cast or even the locations, the entertainment we deliver is based on fantasy,” he elaborates. “Our business is not, and never has been, reality. People who are buying our content aren’t expecting reality, or direct contact with stars like you can have with OnlyFans,” he says.

Jeff Dana ·
opinion

How to Turn Card Brand Compliance Into Effective Marketing

In the adult sector, compliance is often treated as a gauntlet of mandatory checkboxes. While it’s true that those boxes need to be ticked and regulations must be followed, sites that view compliance strictly as a chore risk missing out on a bigger opportunity.

Jonathan Corona ·
opinion

A Look at the Latest AI Tools for Online Safety

One of the defining challenges for adult businesses is helping to combat the proliferation of illegal or nonconsensual content, as well as preventing minors from accessing inappropriate or harmful material — all the more so because companies or sites unable or unwilling to do so may expose themselves to significant penalties and put their users at risk.

Gavin Worrall ·
opinion

Know When to Drop Domains You Don't Need

Do you own too many domains? If so, you’re not alone. Like other things we accumulate, every registered domain means something to us. Sometimes a domain represents a dream project we have always wanted to do but have never quite gotten around to.

Juicy Jay ·
opinion

Understanding 'Indemnification' in Business Contracts

Clients frequently tell me that they didn’t understand — or sometimes, even read — certain portions of a contract because those sections appeared to be just “standard legalese.” They are referring, of course, to the specialized language used in legal documents, including contracts.

Corey D. Silverstein ·
opinion

5 Steps to Make Card Brand Compliance Easy

It’s February, the month of love. Just once, wouldn’t it be great to receive a little candy heart asking you to “Be Mine” instead of more forms to fill out and documents to submit? Of course, regulatory compliance does have one important thing in common with romance: Fail to put in the work, and your relationship is likely over — your relationship with the card brands, that is.

Cathy Beardsley ·
opinion

Protecting Your Business With a Data Backup Strategy That Works

If the subject of backups sounds boring to you, maybe this will grab your attention: Without properly implemented backups, your business is vulnerable to partial or even catastrophic data loss, which could screw your company and tank your income.

Brad Mitchell ·
profile

WIA Profile: Paulita Pappel

Raised in Spain, surrounded by a predominantly Catholic community, Paulita Pappel grew up being told porn was bad. When she became a feminist, she was told her fascination with porn was not in line with her desire to empower women. This inner conflict made her feel like there was something wrong with her.

Women In Adult ·
opinion

Complying With New Age Assurance and Content Moderation Standards

For adult companies operating in today’s increasingly regulated digital landscape, maintaining compliance with card brand requirements is essential — not only to safeguard your operations but also to ensure a safe and transparent environment for users.

Gavin Worrall ·
Show More