Is there any other e-commerce site besides PayPal?

Would it be okay to consider our ecommerce site a "Virtual Terminal"? (for PCI-DSS purposes)

  • Our ecommerce site is hosted in an environment that passes all the PCI-DSS requirements, and we have call center employees that input orders (with credit card info) into a special screen on our ecommerce site to place orders for customers. I was recently told by a Trustwave support employee that assuming our ecommerce website was hosted and maintained in a PCI-DSS manner, we could consider that our call center employees use a "virtual terminal". If this is the case then our job of answering the SAQ questions just got a whole lot easier, and I am looking to see what anybody else is able to confirm this. (I did some web research and didn't find much - just that a "virtual terminal" is where the credit card is input into a browser over a secure connection and the processing happens remotely on a secure network)

  • Answer:

    At the end of the day it's really your payment processor that would make that call so for peace of mind I would get their take on this if I were you. In PCI DSS 2.0 there was a new SAQ added for for virtual terminal users (C-VT) so you can make the argument for any hosted web app to be eligible as long as it's only used for manually entered cards. This however typically applies to virtual terminals that have already been certified by the company that provides the service like http://Auth.net and those companies usually undergo a level 1 audit which is the most in depth. From your question it sounds like this might be a web application you have developed yourself which might not let you qualify as a simple virtual terminal merchant. Also, since you have a call center, you need to ensure cardholder data doesn't exist anywhere else like order/customer notes and even call recordings.

Markiyan Malko at Quora Visit the source

Was this solution helpful to you?

Related Q & A:

Just Added Q & A:

Find solution

For every problem there is a solution! Proved by Solucija.

  • Got an issue and looking for advice?

  • Ask Solucija to search every corner of the Web for help.

  • Get workable solutions and helpful tips in a moment.

Just ask Solucija about an issue you face and immediately get a list of ready solutions, answers and tips from other Internet users. We always provide the most suitable and complete answer to your question at the top, along with a few good alternatives below.