Magento Open Source, 1.9.x

PCI Compliance Guidelines

The Payment Card Industry (PCI) has established a set of requirements for businesses that accept payment by credit card over the Internet. In addition to maintaining a secure hosting environment, merchants must meet additional requirements to ensure the privacy of cardholder data. As your business grows, you might be required to file a compliance report on an annual basis. PCI reporting requirements increase in proportion to merchant level, but are waived for businesses that process fewer than 20,000 credit card transactions per year.

Every merchant who handles customer credit card information is required by the Payment Card Industry to conduct business within the following guidelines:

  • PCI Requirements

    Install and maintain a firewall configuration to protect cardholder data.

    Do not use vendor-supplied defaults for system passwords and security parameters.

    Protect stored cardholder data.

    Encrypt transmission of cardholder data across open, public networks.

    Use and regularly update antivirus software.

    Develop and maintain secure systems and applications.

    Restrict access to cardholder data by business need to know.

    Assign a unique ID to each person with computer access.

    Restrict physical access to cardholder data.

    Track and monitor all access to network resources and cardholder data.

    Regularly test security systems and processes.

    Maintain a policy that addresses information security.