Skip to content
RONPAY

PCI DSS

Home / PCI DSS

1. What PCI DSS certification is

PCI DSS (Payment Card Industry Data Security Standard) is the global security standard created by Visa, Mastercard, American Express, Discover and JCB to protect cardholder data at every stage of a transaction.

Level 1 is the most rigorous validation level. For merchants, it applies to those with more than 6 million Visa or Mastercard transactions a year; for payment service providers, to those with more than 300,000. It requires an annual audit by a Qualified Security Assessor (QSA), quarterly ASV scans and regular penetration testing.

The standard comprises 12 fundamental requirements, divided into 6 control objectives: from network protection to vulnerability management, and from access control to continuous system monitoring.

2. Why is PCI DSS essential for payments?

Mandatory in order to operate with the card networks

Visa, Mastercard and the other international networks require PCI DSS compliance from every party that handles card data. Non-compliance can lead to fines and even the loss of the right to accept card payments.

3. Protection against security breaches and penalties

A data breach exposes a company to GDPR fines of up to EUR 20 million or 4% of global annual turnover, whichever is higher, and to fines from the payment networks. PCI DSS reduces that exposure.

4. A requirement for enterprise and the public sector

In public tenders and B2B supplier selection processes, PCI DSS certification is often a knock-out criterion. Holding it speeds up onboarding with enterprise partners and clients.

5. How does PCI DSS apply to RONPAY payments?

RONPAY payments run on RoxPay's infrastructure, which is PCI DSS Level 1 certified. The certification covers, among other things:

a) Card data encryption

Card data is protected with strong encryption in transmission and is not stored in clear text. Card numbers (PAN) are replaced with tokens.

b) Controlled access to card data

The environment where card data is processed (Cardholder Data Environment, CDE) is protected by network security controls, and access is limited to the people who need it.

c) Continuous monitoring and penetration testing

Access to systems and card data is logged and monitored. The standard requires quarterly ASV scans and penetration tests at least once a year and after significant changes.

d) Annual audit by a certified QSA

Every year, an independent Qualified Security Assessor verifies compliance with all 12 PCI DSS requirements and issues the official Report on Compliance (ROC).

6. Concrete benefits for your business. Less exposure to card data

If you use the hosted checkout or secure fields, card data is captured directly by RoxPay's PCI DSS Level 1 certified infrastructure and does not pass through your servers. You remain responsible for your own website's compliance, which you usually validate with the SAQ A questionnaire.

7. Lower risk of card data theft

The controls PCI DSS requires reduce the risk of card data being stolen and used for fraud, which comes back to the merchant as chargebacks.

8. Faster onboarding with banks and partners

The PCI DSS Level 1 certification of RoxPay's infrastructure simplifies the security checks required in due diligence with financial institutions and acquirers.

9. Trust from enterprise and the public sector

Payments processed on PCI DSS Level 1 certified infrastructure can strengthen your credibility in tenders, in requests for proposals and with corporate clients who require certified suppliers.

10. Frequently asked questions about PCI DSS certification

a) What is PCI DSS certification and why is it needed?

PCI DSS is the global security standard for protecting payment card data. Compliance is mandatory for every organisation that processes, transmits or stores card data. How you demonstrate it (an audit or a self-assessment questionnaire) depends on your level.

b) What is the difference between PCI DSS Level 1 and the other levels?

Level 1 is the most rigorous. For merchants, it applies to those with more than 6 million Visa or Mastercard transactions a year; for payment service providers, to those with more than 300,000. It requires an annual audit by a QSA, quarterly ASV scans and penetration testing. For merchants, Levels 2 - 4 have less strict requirements and are usually validated with self-assessment questionnaires.

c) How does PCI DSS certified infrastructure protect my online store?

If you use the hosted checkout or secure fields, your customers' card data does not pass through your servers. Tokenisation and hosted checkout pages greatly reduce your PCI scope and, with it, your compliance risks and costs.

d) Do I also need PCI DSS certification if I use RONPAY?

In most cases you do not need a full audit, but compliance remains mandatory. With the hosted checkout or PCI Proxy secure fields, your PCI scope is greatly reduced and you usually validate compliance with the simplified SAQ A questionnaire. If card data passes through your servers, for example with a direct API integration, the requirements are higher.

11. Protect your business's payments

Find out how RoxPay's PCI DSS Level 1 certified infrastructure helps you reduce risk and simplify compliance.