PCI Resources

Cardholder Data Security — Internet Processing

What is the PCI DSS Self-Assessment Questionnaire?

Multiple-choice questions about the merchant's card acceptance and processing environment. Used to identify your risk level and assess your compliance with the requirements of all card associations regarding your cardholder data policies, procedures, administrative controls, access controls, and physical security measures.

What is a quarterly network scan?

Conducted by a third-party vendor of the merchant's external-facing IPs. Identifies systems that are not secure, or that could be open to a security breach or data compromise.

How do I comply?

To be deemed compliant with PCI DSS, a merchant must pass both the scan and the questionnaire.

If deemed non-compliant, a remediation plan will be necessary to address the areas of weakness, risk, and vulnerability. You will be provided with solutions necessary to become PCI compliant, protect cardholder data, and reduce your risk.

What happens if I am not PCI DSS Compliant?

If you are non-compliant, you are subject to fines from the card associations. If your security is compromised because of your non-compliance, you risk financial loss, additional fines, loss of business, damage to your brand's reputation, and other loss of critical systems.


If you have any questions or concerns, please contact the Innovative Merchant Solutions Customer Service Center at