ABOUT PA-DSS
To help preserve the validity of payment processing systems, the Payment Card Industry's Security Standards Council (PCI SSC) established the Payment Application Data Security Standard. These regulations aim to guide software vendors to develop secure, certified payment applications that also support a merchant’s ability to comply with PCI DSS.
Because PA-DSS validated systems are tested for vulnerabilities, they are considered safe for payment processing, whereas non-validated payment applications typically retain full magnetic stripe data, CVV/CVV2 or PIN data after authorization, which can leave a business at risk of data theft. If you aren’t sure about your system’s compliance with PA-DSS, contact Merchant Warehouse and we will gladly help you.
DEVELOPER REQUIREMENTS UNDER THE PA-DSS
If you develop any payment applications that are sold, distributed or licensed to third parties and are installed "off-the-shelf" without much customization for your clients, you are subject to the PA-DSS requirements.
WHAT SOFTWARE DEVELOPERS NEED TO KNOW
A system that is PA-DSS compliant does not ensure PCI DSS compliance. Also, it is important to note that the validation for payment applications only applies to the specific version certified and not necessarily an older version of the same software. In order for any product or version of a product to be listed on the PA-DSS validated list, software vendors must consult a PCI SSC-qualified Payment Applications Qualified Security Assessor (PA-QSA) to conduct the audit.
PA-DSS AUDITS
In partnership with Trustwave®, you can validate your payment applications at less of an expense! Learn more:
Download the PA-DSS Compliance ChecklistReview the PA-DSS Validated Applications
Learn more about how you can eliminate PA-DSS audits and avoid certification fees with Merchantware TransPort
« Back


