PCI Compliance Merchant User Guide



Similar documents
Access EEC s Web Applications... 2 View Messages from EEC... 3 Sign In as a Returning User... 3

BRILL s Editorial Manager (EM) Manual for Authors Table of Contents

Durango Merchant Services QuickBooks SyncPay

Service Desk Self Service Overview

CSAT Account Management

Welcome to CNIPS Training: CACFP Claim Entry

Shelby County Schools Online Employee Accident Reporting User Manual

Grants Online. Quick Reference Guide - Grantees

Employee Self Service (ESS) Quick Reference Guide ESS User

iphone Mobile Application Guide Version 2.2.2

Treasury Gateway Getting Started Guide

Using McAllister Payment Solutions and Updating to AVImark version

Montana Acquisition & Contracting System (emacs) emacs Handbook. Vendor Registration and Data Management

MDSB. MemberDirect Small Business. User Guide

Using PayPal Website Payments Pro UK with ProductCart

PENNSYLVANIA SURPLUS LINES ASSOCIATION Electronic Filing System (EFS) Frequently Asked Questions and Answers

PROCESSING THROUGH MPS and AVIMARK

imarket Welcome Pack Version: 1.1 Status: Issued Date: 10/07/2015 Copyright 2012 Polaris U.K. Limited All Rights reserved

Grants Online. Quick Reference Guide Grant Recipients

IT Quick Reference Guides Resetting Your Password

Vancouver Island University Job Posting System Instruction Manual

efusion Table of Contents

Merchant Management System. New User Guide CARDSAVE

BackupAssist SQL Add-on

Create a Non-Catalog Requisition

FOTO Patient Inquiry Practice Administrator Training Guide Version

Volume THURSTON COUNTY CLERK S OFFICE. e-file SECURE FTP Site (January 2011) User Guide

Program Administrator s Guide to. Student Management

GETTING STARTED With the Control Panel Table of Contents

Supervisor Quick Guide

990 e-postcard FAQ. Is there a charge to file form 990-N (e-postcard)? No, the e-postcard system is completely free.

Process of Setting up a New Merchant Account

ISAM TO SQL MIGRATION IN SYSPRO

CenterPoint Accounting for Agriculture Network (Domain) Installation Instructions

STANLEY Healthcare University Training & Certification Portal. Student Quick Reference Guide

Using Identity Finder. ITS Training Document

Training Script: Documenting Provider

VCU Payment Card Policy

CLIENT PORTAL GUIDE SUMMARY

AP Capstone Digital Portfolio - Teacher User Guide

Connecting to

CREDIT REPORTING USER GUIDE

Table of Contents. Welcome to Employee Self Service... 3 Who Do I Call For Help?... 3

esupport Quick Start Guide

INSTRUCTIONS ON HOW TO IMPORT (Attach) DOCUMENTS TO TRANSACTIONS IN THE EMPLOYEE REIMBURSEMENT SYSTEM

FOCUS Service Management Software Version 8.5 for Passport Business Solutions Installation Instructions

Macintosh Operating System Online Proctoring Guide

Merchant Processes and Procedures

How To Install Fcus Service Management Software On A Pc Or Macbook

FOCUS Service Management Software Version 8.5 for CounterPoint Installation Instructions

HSBC Online Home Loan Application Process

Configuring an Client for your Hosting Support POP/IMAP mailbox

MaaS360 Cloud Extender

LeadStreet Broker Guide

Optimal Payments Extension. Supporting Documentation for the Extension Package v1.1

SDES Service Desk Portal: Opening a Service Ticket

The ad hoc reporting feature provides a user the ability to generate reports on many of the data items contained in the categories.

KronoDesk Migration and Integration Guide Inflectra Corporation

1) Update the AccuBuild Program to the latest version Version or later.

Application Advisories for Data Integrator for Non- EDI location

User Manual Brainloop Outlook Add-In. Version 3.4

APTA ONLINE PROGRAM LISTING INTERFACE PROGRAM MANUAL

Using PayPal Website Payments Pro with ProductCart

UCDHS PeopleSoft HRMS 8.8 External Applicants User Guide. External Applicants User Guide

Tipsheet: Sending Out Mass s in ApplyYourself

University of Texas at Dallas Policy for Accepting Credit Card and Electronic Payments

Student Web Time Entry Guide

Stage 2 Meaningful Use - Core Measure 12 Patient Reminders Configuration Guide

FINRA Regulation Filing Application Batch Submissions

Setup O365 mailbox access on MACs

Selling System Security Wire Instructions

Tips & Tricks. Table of Contents. Browser Update - WebEx Plugin. Updated Global Access Numbers

AT&T U-verse App for Android FAQs

Cloud Services MDM. Windows 8 User Guide

Valley Transcription Service I-Phone/I-Pod App User s Guide

PIC Online Application Help Document

STIOffice Integration Installation, FAQ and Troubleshooting

IMPORTANT INFORMATION ABOUT MEDICAL CARE FOR YOUR WORK-RELATED INJURY OR ILLNESS

Setup Instructions Glion Online

Access to the Ashworth College Online Library service is free and provided upon enrollment. To access ProQuest:

Intel Hybrid Cloud Management Portal Update FAQ. Audience: Public

Net Conferencing User Guide: Advanced and Customized Net Conference with Microsoft Office Live Meeting Event Registration

Level 3 SM Ready-Access User Guide

Hartford Seminary s. Online Application Instructions

Point2 Property Manager Quick Setup Guide

This page provides help in using WIT.com to carry out the responsibilities listed in the Desk Aid Titled Staffing Specialists

User Guide Version 4.4

CHAPTER 26: INFORMATION SEARCH

AT&T U-verse App ios FAQs

Your Outlook Mailbox can be accessed from any PC that is connected to the Internet.

Software Distribution

Business Digital Voice Site Services - Phone & User Assignments

Helpdesk Support Tickets & Knowledgebase

HeartCode Information

Spamguard SPAM Filter

edoc Lite Recruitment Guidelines

Regions File Transmission

Accessing SpringBoard Online Table of Contents: Websites, pg 1 Access Codes, 2 Educator Account, 2 How to Access, 3 Manage Account, 7

State Bank Virtual Card FAQs

Transcription:

PCI Cmpliance Merchant User Guide Table f Cntents Intrductin... 5 PCI Prgram Overview... 5 PCI10 2.0 Applicatin Tl Overview... 6 Lgin Prcess... 6 Update My Prfile... 7 Frgt Yur Passwrd... 8 Welcme Pages... 9 Welcme Page (First Cntact)... 9 Welcme Page (Returning Merchant)... 10 Welcme Re-Assessment Page (Returning Cmpliant Merchant)... 12 Welcme Page (Offline Merchant)... 13 Merchant Infrmatin Page... 14 Questinnaire Selectin Page... 15 Questinnaire Wizard Prcess... 16 Pre-Filled Questins... 19 Questinnaire Selectin Prcess... 19 Questinnaire Page... 20 View All Sectin (x) Questins Link... 22 End f Questinnaire Page... 24 Review and Sign Page... 26 Reprts Page... 29 Netwrk Scan... 30 Landing Page 1... 30 Landing Page 2... 32 Additinal Infrmatin/Prcesses... 33 Resurce Library... 33 Cntact Us... 33 Chained Merchants... 34 Returning Master Merchant Prcess... 36

Returning Assciated Merchant Prcess... 37 Re-Assessing While In A Cmpliant Status... 37

Intrductin The purpse f this PCI Cmpliance Merchant User Guide is t prvide an verview f the PCI Cmpliance validatin prcess and prvide detailed infrmatin n hw t use the PCI Applicatin Tl when assisting the merchants thrugh the prcess. PCI Prgram Overview All merchants accepting credit cards fr purchases are asked frm their acquiring bank r prcessr t prvide dcumentatin f cmpliance with the Payment Card Industry Data Security Standard (PCI DSS). PCI DSS The Payment Card Industry Data Security Standard (PCI DSS) is a set f guidelines put in place t ensure that merchants are fllwing best practices in rder t reduce credit card fraud and security breaches. The PCI DSS was frmed by the five majr card brands (Visa, MasterCard, American Express, Discver, and Japan Card) t help facilitate the adptin f cnsistent data security measures glbally. The PCI DSS includes cmprehensive requirements fr security management, plicies, prcedures, netwrk architecture, sftware design and ther critical prtective measures intended t practively prtect custmer accunt data. Validating Cmpliance with the PCI DSS Mst merchants are PCI Level 2, 3, r 4 and validating cmpliance will vary and depend n whether yu have an Internet cnnectin. A self-assessment questinnaire must be perfrmed t determine whether yu meet the PCI DSS requirements fr yur type f business. This shuld be dne annually. If yu have an Internet cnnectin and transmit credit card data ver the Internet, than a Netwrk Scan is required and must be perfrmed n yur business. This shuld be dne every three mnths. Dcumentatin f Validatin Autmatic reprting f cmpliance validatin t the acquiring bank r prcessr. Printing/E-Mailing the current r past Certificate f Cmpliance, questinnaire, and Review and Sign frm is an ptin t use fr prf that the prcess has been cmpleted.

PCI10 2.0 Applicatin Tl Overview Lgin Prcess The merchant will lg int the PCI Applicatin Tl using their username and passwrd. The merchant will get lcked ut f the system during the lgin prcess if they enter an invalid passwrd three times. At this time the passwrd must be reset by a Custmer Service Cnsultant. Example f lgin page Example f lgin page with an invalid lgin/invalid passwrd

Update My Prfile After the merchant has successfully lgged int the PCI Applicatin Tl they will be prmpted t update their prfile befre they get t the initial welcme page. (See example f screen sht) Merchants are frced t reset their passwrd nce they have lgged in with a temprary passwrd. New passwrd must be between 7-10 characters. Must have a cmbinatin f alpha and numeric. Des nt allw special characters r spaces. Expires in 90 days fr security purpses. The cunt is based n the last time that the merchant changed the passwrd.

Temprary Passwrd Details Initial Lgin: The default/temprary passwrd fr all merchants is the last 5 digits f their Merchant ID # and their state abbreviatin. After the initial lgin, the system will prmpt the merchant t change the passwrd. Reset Passwrd: A temprary passwrd is assigned when the passwrd is reset by a Custmer Service representative r MS Hierarchy user. Update My Prfile Details Username: read-nly grayed ut text bx aut-filled with the Merchant ID #. First Name: text bx aut-filled if the first name exists in the system. Maximum length f characters: 30 First name is a required field. Last Name: text bx aut-filled if the last name exists in the system. Maximum length f characters: 30 Last name is a required field. Email Address: text bx aut-filled if email address exists in the system. Passwrd Instructins t the merchant Old passwrd: editable textbx the merchant needs t enter the temprary passwrd nly if this is the first time lgging int the system. New Passwrd: editable textbx Re-Enter New Passwrd: editable textbx the merchant needs t re-enter the new passwrd. Security Questin: drpdwn list Where were yu brn? What is yur favrite pet s name? What is yur favrite mvie? What is yur favrite city f place? Security Answer: If answer exists then encrypted answer is in the editable text bx. Submit buttn: Frgt Yur Passwrd This functin is used when the merchant frgets his/her passwrd. The merchant must enter the user name, an email address and answer a security validatin questin that is currently n recrd. The system will generate a temprary passwrd and email the passwrd t the merchant. Temprary passwrds expire in 72 hurs. Frgt Passwrd Guidelines Invalid User Name/Email address/answer t Security Validatin Questin The merchant is allwed 2 attempts t enter in the crrect infrmatin. The merchant will get a message t cntact Custmer Service if they are still unsuccessful n the 3 rd attempt.

Welcme Pages The PCI Applicatin Tl is brken ut int 4 different Welcme Pages fr new and returning merchants. An indicatr bar is prvided s the merchant can see their prgress. The titles n the indicatr bars act as a hyperlink t allw the merchants t view/edit a previus page. In additin, an verview f the PCI DSS status, questinnaire status, scan status, and an actin statement will be displayed fr the merchant. Welcme Page (First Cntact) This page is defined as a merchant wh has never lgged int the PCI Applicatin Tl. (See example f screen sht). The merchant will see this page nly ne time unless the Custmer Service Cnsultant resets the merchant t a Nt Started status. A welcme text is displayed t prvide a brief descriptin f the PCI DSS. The 5 basic steps required t cmplete the prcess are utlined. The merchant will prceed t the Merchant Infrmatin page when selecting the cntinue buttn.

Welcme Page (Returning Merchant) This page is defined as a merchant wh has lgged int the PCI Applicatin Tl and prgressed passed the initial Welcme Page. (See example f screen sht) The merchant will see: Welcme Text Overall PCI Cmpliance Status Nn-Cmpliant One f the fllwing Questinnaire Statuses Nt Started In Prgress Nt Signed Nn-Cmpliant One f the fllwing Scan Statuses (C and D) Nt Started In Prgress Pass Fail Questinnaire Due Date Next Scan Date

The merchant will see ne f the fllwing Actin Statements If in the Nt Started psitin. Message Yu have started the prcess please press cntinue. If in the In Prgress/Nn Cmpliant psitin. (A, B, and CVT) Message Press cntinue t cmplete the remaining prtins f yur questinnaire. If in the Nt Signed psitin. (A, B, and CVT) Message Prceed t "Review & Sign" by clicking n the cntinue buttn. If the questinnaire status is In Prgress and the scan status is Nt Started. (C and D) Message Press cntinue t cmplete the remaining prtins f yur questinnaire. If the questinnaire status is Nt Signed and the scan status is Nt Started. (C and D) Message Yu must include a Netwrk Scan t pass the PCI Requirements. Prceed t the scan page by clicking cntinue. If the questinnaire status is Nn Cmpliant and the scan status is Nt Started. (C and D) Message Yu have items that are nt PCI cmpliant please revisit all failed sectins and crrect until yu are PCI Cmpliant. If the questinnaire status is In Prgress and the scan status is In Prgress. (C and D) Message Press cntinue t cmplete the remaining prtins f yur questinnaire. If the questinnaire status is Nt Signed and the scan status is In Prgress. (C and D) Message Yur Netwrk Scan status is still "In Prgress". Please check back within 24-48 hurs t see yur scan results. If this time has lapsed please cntact yur PCI Cmpliance department at xxx-xxx-xxxx. If the questinnaire status is Nn Cmpliant and the scan status is In Prgress. (C and D) Message Yu have items that are nt PCI cmpliant please revisit all failed sectins and crrect until yu are PCI Cmpliant. If the questinnaire status is In Prgress and the scan status is Fail. (C and D) Message Press cntinue t cmplete the remaining prtins f yur questinnaire. If the questinnaire status is Nt Signed and the scan status is Fail. (C and D) Message Yur last Netwrk Scan failed t pass the PCI Requirements. Please review, remediate and re-scan. Or cntact ur PCI Cmpliance department at xxx-xxx-xxxx. If the questinnaire status is Nn Cmpliant and the scan status is Fail. (C and D) Message Yu have items that are nt PCI cmpliant please revisit all failed sectins and crrect until yu are PCI Cmpliant.

If the questinnaire status is In Prgress and the scan status is Pass. (C and D) Message Press cntinue t cmplete the remaining prtins f yur questinnaire. If the questinnaire status is Nt Signed and the scan status is Pass. (C and D) Message Prceed t "Review and Sign" by clicking n the cntinue buttn. If the questinnaire status is Nn Cmpliant and the scan status is Pass. (C and D) Message Yu have items that are nt PCI cmpliant please revisit all failed sectins and crrect until yu are PCI Cmpliant. The merchant will prceed t the Merchant Infrmatin Page when selecting the cntinue buttn. Welcme Re-Assessment Page (Returning Cmpliant Merchant) This page is defined as a merchant wh has previusly cmpleted the PCI Cmpliance prcess and is currently cmpliant. Merchants that need t re-assess, schedule a scan, r btain their PCI Cmpliance reprts will land n this page. (See example f screen sht) The merchant will see: Welcme Text One f the fllwing Overall PCI Cmpliance Statuses Cmpliant Nn-Cmpliant One f the fllwing Questinnaire Statuses Cmpliant Nn-Cmpliant

One f the fllwing Scan Statuses (C and D) Nt Started In Prgress Pass Fail Questinnaire Due Date Next Scan Date Re-Assess Buttn The merchant will prceed t the Merchant Infrmatin Overview Page and start the PCI Cmpliance prcess ver. Schedule Scan Buttn The merchant will prceed t the Netwrk Scan Landing Page 2. Nte: Refer t the Netwrk Scan prcess. Reprts Buttn The merchant will prceed t the Reprts Page. Welcme Page (Offline Merchant) This page is defined as a merchant wh has prvided the necessary dcuments t prve PCI Cmpliance. This merchant was marked as cmpliant thrugh the Admin Offline Merchant tl. This type f merchant will land n this page if they need t re-assess. Merchants wh are a level C r D will land n this page t schedule a scan every 90 days.

The merchant will see: One f the fllwing Questinnaire Statuses Cmpliant Nn-Cmpliant One f the fllwing Scan Statuses (C and D) Nt Started In Prgress Pass Fail Re-Assess Buttn The merchant will prceed t the Merchant Infrmatin Overview Page and start the PCI Cmpliance prcess ver. Schedule Scan Buttn The merchant will prceed t the Netwrk Scan Landing Page 1 if an IP address is nt entered; therwise, they will g t the Netwrk Scan Landing Page 2. Nte: Refer t the Netwrk Scan prcess. Merchant Infrmatin Page The merchant must verify the pre-ppulated infrmatin n Part 1 and cmplete Part 2 and Part 3 befre they select cntinue. (See example f screen sht)

Part 1- Merchant Infrmatin The merchant can cnfirm and/r edit the infrmatin. Part 2 Type f Merchant Business The merchant must check all that apply. Part 3 Relatinships The merchant must answer the tw questins. The merchant must advise if they have relatinships with ne r mre third party service prviders and acquirers. Hlding the muse ver the icn will prvide a tl tip t help answer each questin. Terms & Cnditins The merchant must agree t the terms and cnditins. The merchant will prceed t the Questinnaire Selectin Page when selecting the cntinue buttn. Questinnaire Selectin Page The merchant will be given a chance t select the Questinnaire Wizard. (See example f screen sht). Selecting Yes will take them t the Questinnaire Wizard, which decides the questinnaire level (A, B, C, CVT, C r D) fr them. Nte: Refer t the Questinnaire Wizard prcess. Selecting N will take them t the Questinnaire Selectin page fr the merchant t indicate what questinnaire level (A, B, C, CVT, C r D) they are. Nte: Refer t the Questinnaire Selectin prcess.

Questinnaire Wizard Prcess The merchant will be asked if they want assistance in chsing their questinnaire. (See example f screen sht) The merchant will g thrugh the Questinnaire Wizard t get their suitable questinnaire. All questins in the wizard will have a tl tip t assist the merchant with answering the questin. The merchant can hld their muse ver the icn fr any questin they need assistance with. The merchant will have t chse an answer that applies t their rganizatin. Card Nt Present Card Present Bth The merchant will be asked a series f questins t guide them t the crrect questinnaire level.

A mdal will appear n levels B, C, CVT, and D. Levels B, C, and D The merchant must prvide the Vendr, Applicatin, and Versin f the sftware their cmpany uses by selecting the drp dwn tab t view the chices. (See example f screen sht) If a Vendr, Applicatin, r Versin is nt listed, than the merchant will select Nt Listed and enter the apprpriate infrmatin in the text bxes.

Level CVT The merchant must prvide the Virtual Service Prvider, Virtual Terminal Slutin and the date last validated. (See example f screen sht) If the Virtual Service Prvider and Virtual Terminal Slutin are nt listed, than the merchant will select Nt Listed and enter the apprpriate infrmatin in the text bxes. The merchant will get a mdal t cnfirm their eligibility t take the apprpriate questinnaire. (See example f screen sht) The merchant can select Agree and cntinue t the Questinnaire Page OR they can select the link t chse a different questinnaire. Nte: Refer t the Questinnaire Page prcess.

Pre-Filled Questins As the merchant is answering the questins in the Questinnaire Wizard, all answers related t Requirement 3 (Prtecting Stred Data) are pre-filled n the questinnaire. This applies nly t levels B, C and CVT. When the merchant selects the start questinnaire buttn they will see an intrductin text explaining why the questins were pre-filled befre they begin the questinnaire. In additin, the pre-filled questins will be nted n the questinnaire reprt with an asterisk. Questinnaire Selectin Prcess The merchant must select the questinnaire that matches their cmpany. (See example f screen sht) The merchant can change their selectin at any time. Nte: The merchant will get a pp-up bx advising them that this will erase all answers that were previusly filled ut.

When the merchant selects cntinue a mdal will appear n levels B, C, CVT, and D. (See example f screen shts in the Questinnaire Wizard prcess sectin) Levels B, C, and D The merchant must prvide the Vendr, Applicatin, and Versin f the sftware their cmpany uses by selecting the drp dwn tab t view the chices. If a Vendr, Applicatin, r Versin is nt listed, than the merchant will select Nt Listed and enter the apprpriate infrmatin in the text bxes. Level CVT The merchant must prvide the Virtual Service Prvider, Virtual Terminal Slutin and the date last validated. If the Virtual Service Prvider and Virtual Terminal Slutin are nt listed, than the merchant will select Nt Listed and enter the apprpriate infrmatin in the text bxes. The merchant will get a mdal t cnfirm their eligibility t take the apprpriate questinnaire. (See example f screen shts in the Questinnaire Wizard prcess sectin) The merchant can select Agree and cntinue t the Questinnaire Page OR they can select the link t chse a different questinnaire. Nte: Refer t the Questinnaire Page prcess. Questinnaire Page All merchants will land n this page whether they cmpleted the Questinnaire Wizard r the Questinnaire Selectin prcess. This page is a sectin verview page shwing the merchant the sectins/requirements that must be cmpleted, which is determined by the questinnaire level chsen. (See example f screen sht)

After the merchant selects the start questinnaire buttn they will see an Intrductin Statement f what that particular sectin will cver, which is determined by the questinnaire level chsen. The Intrductin Statements fr each sectin will be displayed befre the merchant starts that sectin. (See example f screen sht) The system will start at the first questin fr the sectin selected. (See example f screen sht)

The questins will be cycled thrugh ne at a time by answering: YES - the merchant cannt edit answers with a Yes selected. NO the merchant can edit answers with a N selected. N/A the merchant must prvide an explanatin why the questin is nt applicable t their cmpany in the given text bx. The merchant can edit an N/A answer r change the answer t Yes. All questins will have a tl tip icn t assist the merchant with answering the questin. The merchant can hld their muse ver the icn fr any questin they need assistance with. The merchant can view what sectins they have cmpleted r have yet t cmplete by clicking n the plus tggle. (See example f screen sht) View All Sectin (x) Questins Link When the merchant selects the View Sectin Questins link they will see all f the questins fr that sectin/requirement n ne page. (See example f screen shts)

The merchant may g thrugh the prcess by answering the questins frm here if they chse.

End f Questinnaire Page The merchant will land n the End f Questinnaire Page after ging thrugh the entire questinnaire. The merchant can view any sectin and/r they will have the chance t select revisit any sectins that are Failed r still In Prgress t crrect and/r cmplete remaining questins. This will als serve as a landing page fr merchants wh need t prgress t either the Netwrk Scan r Review and Sign Page based n the questinnaire requirement. (See example f screen shts) Example 1 N Scan Required

Example 2 Scan Required The merchant will see a message n the left side f screen indicating their Overall PCI Cmpliance. If all sectins have Passed. Message Yu have successfully cmpleted yur questinnaire. Please prceed t "Review and Sign" by clicking n the cntinue buttn. (A, B, C, CVT, and D) If any sectin is In Prgress. Message Please cntinue thrugh all sectins until cmplete. (A, B, C, CVT, and D) Message Yu have successfully cmpleted yur questinnaire. Cntinue t initiate the Netwrk Scan. (C and D) Message Yu have items that are nt PCI cmpliant please revisit all failed sectins and crrect until yu are PCI Cmpliant. (C and D) Message Yur Netwrk Scan status is still "In Prgress". Please check back within 24-48 hurs t see yur scan results. (C and D)

If any sectin has Failed. Message Yu have items that are nt PCI cmpliant please revisit all failed sectins and crrect until yu are PCI Cmpliant. (A, B, C, CVT, and D) Message Yur last Netwrk Scan failed t pass the PCI Requirements. Please review, remediate and re-scan. (C and D) Once the merchant has successfully cmpleted their questinnaire and netwrk scan, they will prceed t the "Review and Sign" Page. Review and Sign Page The merchant will advance t the Review and Sign Page under the fllwing cnditins. (See example f screen sht) Questinnaire A, B, and CVT merchants Pass all questinnaire sectins by answering Yes r N/A. Questinnaire C and D merchants Pass all questinnaire sectins by answering Yes r N/A. Have a passing netwrk scan.

Merchant Infrmatin The infrmatin is ppulated frm the input n the Merchant Infrmatin page. (A, B, C, CVT, and D) Type f Merchant Business The infrmatin is ppulated frm the input n the Merchant Infrmatin page. (A, B, C, CVT, and D) Relatinships The infrmatin is ppulated frm the input n the Merchant Infrmatin page. (A, B, C, CVT, and D) Transactin Prcessing The merchant is verifying the infrmatin f hw they prcess/transmit transactins. (B, C, CVT, and D) Eligibility t Cmplete The merchant is attesting t the hw their cmpany envirnment is set up. Cnfirmatin f Cmpliance The infrmatin will be ppulated frm the input frm the Eligibility f Cnfirmatin page. PCI DSS Validatin The merchant is required t prvide an e-signature t validate their PCI Cmpliance.

Reprts Page The merchant can view their cmpleted PCI dcuments. (See example f screen sht) Includes Questinnaire Answer Sheet Signed Attestatin f Cmpliance Frm Certificatin f Validatin. View/Print r E-mail PCI Dcuments Current Reprts Previus Reprts (the last 2 years) Once PCI dcuments are btained the merchant may simply lg ff frm the PCI Applicatin Tl. Nte: The merchant can revisit this page at any time t btain the reprts if needed by lgging back int the system and selecting the reprts buttn. Please refer t screen sht prvided in the Welcme Page fr Returning Merchants sectin.

Netwrk Scan Landing Page 1 If the merchant is a level C r D they are required t cmplete a Netwrk Scan and are tested by an apprved scanning vendr (ASV). The merchant will need t select the Cntinue t Netwrk Scan buttn t get t the Netwrk Scan Landing Page 1. (See example f screen shts)

Netwrk Scan Landing Page 1 Landing Page 1 will prvide detailed instructins n: Scheduling a test f the IP address (es) prvided. Hw t btain the merchant s IP address (es) t cmplete the scan. Submitting quarterly scans per the PCI DSS requirements. The timeframe t cmplete a scan. Hw t view the technical reprt when a scan fails. Advising the merchant t cmpleting the Review and Sign Page nce a scan passes. First time merchants will enter an IP address (es) n this page. The merchant can enter up t 5 IP addresses by selecting the Add additinal IP address (es) link. The merchant will site jump t the ASV s website when they select the Cntinue t Netwrk Scan buttn.

Landing Page 2 The merchant will see Landing Page 2 when they re-visit the PCI Applicatin Tl t check their scan results. (See example f screen sht) Landing Page 2 cnsists f: Intrductin text Number f IP addresses entered. Date f last scan. One f the fllwing Statuses Incmplete = Nt Started r In Prgress Cmplete = Pass r Fail One f the fllwing Scan Statuses Nt Started In Prgress Pass Fail Cntinue t Netwrk Scan buttn. Cntinue t Review and Sign Page. This will be enabled when the questinnaire status and scan status have Passed.

Additinal Infrmatin/Prcesses Resurce Library This has resurces and tls the merchant can use t assist them during the PCI prcess and is lcated at the bttm f the screen displaying the resurce library icn. Resurces & Tls Include (See example f screen sht) Educatin Educatinal PCI Vide Manuals Merchant Guides FAQ s Frequently asked questins Dcuments Security Plicy Template Questinnaire Dcuments Glssary PCI terms PCI Links Helpful PCI links Cntact Us This is where the clients cntact infrmatin is and allws the merchant t email their client and is lcated at the bttm f the screen displaying the cntact us icn.

Chained Merchants The purpse is fr merchants t have the ptin t apply their PCI Cmpliance validatin t mre than ne Merchant ID accunt that has the same Federal Tax ID number. Master Merchant Is defined as the Merchant ID that the merchant used t cmplete the PCI prcess fr all MID s they are assciated with. Assciated Merchant Is defined as a Merchant ID that has been assciated t the Master Merchant in the PCI prcess. Once the Master Merchant accepts the Terms & Cnditins they will see a pp-up screen that will ask them if they have ther accunts they want t assciate with their PCI Cmpliance validatin. (See example f screen sht)

Answering NO will take them thrugh the existing prcess. Answering YES will take them t a screen that will shw all MID s having the same Federal Tax Id number. (See example f screen sht) This screen will shw Merchant ID number Merchant Name City State Zip Edit Add/Delete The master merchant will have the ptin t add r delete MID numbers frm the list. The master merchant will select the cntinue buttn when finished with editing the assciated merchant list. All MID # s prvided will be marked with the same SAQ status, Scan Status and Overall PCI status as the Master MID number. The master merchant is required t g thrugh the Questinnaire Wizard, which decides the questinnaire level (A, B, C, CVT, C r D) fr them. Nte: Refer t the Questinnaire Wizard prcess. The merchant will prceed t the payment applicatin selectin page. The merchant will have the ptin t list mre than ne payment applicatin. (See example f screen sht)

If level B,C r D The merchant must prvide the Vendr, Applicatin, and Versin f the sftware their cmpany uses by selecting the drp dwn tab t view the chices. If a Vendr, Applicatin, r Versin is nt listed, than the merchant will select Nt Listed and enter the apprpriate infrmatin in the text bxes. If level CVT The merchant must prvide the Virtual Service Prvider, Virtual Terminal Slutin and the date last validated. If the Virtual Service Prvider and Virtual Terminal Slutin are nt listed, than the merchant will select Nt Listed and enter the apprpriate infrmatin in the text bxes. All infrmatin listed will ppulate in Sectin 2B Transactin Prcessing n the Review & Sign Page. The merchant will get a mdal t cnfirm their eligibility t take the apprpriate questinnaire. The merchant will land n the Questinnaire Page and cntinue thrugh the PCI Applicatin Tl as nrmal. Nte: Refer t the Questinnaire Page prcess. Returning Master Merchant Prcess The returning Master Merchant will remain in the nrmal prcess but will see the fllwing infrmatin n all returning Welcme Pages. (See example f screen sht)

Returning Assciated Merchant Prcess An assciated merchant will nt be able t mve past the Welcme Page. They will be given a message t lg in as the Master Merchant. (See example f screen sht) Re-Assessing While In A Cmpliant Status The purpse is t allw the merchant t remain in a Cmpliant status if they chse t re-assess the questinnaire/scan befre their anniversary date has arrived. During the time it takes the merchant t cmplete the PCI Applicatin Tl, the merchant will stay Cmpliant until their anniversary date passes. Exceptins: Answering N t any questin will trigger a Nn-Cmpliant status. Having a Failed scan will trigger a Nn-Cmpliant status. The system will update the merchant s anniversary date nce they have passed the PCI DSS requirements and an e-signature is prvided n the Review & Sign Page.