What should you look for in a PCI program and how will you know which PCI program is right for you?
If you're an Acquirer or ISO in the market for a PCI program, you may feel like there are limited choices, especially since many of the PCI program providers have consolidated into VikingCloud.
The good news is that there are still alternatives to VikingCloud. This blog is designed to help you ask the right questions about PCI programs and compare your options in the PCI program market to make sure you’re spending your money on the best possible option for your organization.
*Note that the author of this post is SecurityMetrics. We think we’re pretty good (okay, okay, the best) at PCI compliance.
A PCI program is a system that acquirers use to keep track of their merchants’ PCI compliance. It also provides merchants with the training and tools they need to achieve PCI compliance and remain PCI compliant.
Ensuring that your PCI program has each of these options will significantly decrease the frustrations of merchants and acquirers.
Since there are two different entities who use PCI programs, it’s important to understand the frustrations of both. That way you can choose a PCI program that will benefit merchants and acquirers and increase the likelihood that all parties will reach compliance.
Now that you have some background on what to look for in a PCI program, let’s get into questions to ask when comparing PCI programs.
Simplicity is an essential to a successful PCI program. Remember, the goal of a PCI program is to help merchants become compliant to avoid breaches, fees, lawsuits, and going out of business, and maintain customer trust and loyalty. Making it easier for merchants to be PCI compliant rather than taking the risk of a data breach because compliance is too complicated should be a top priority when choosing a PCI program.
Here are some questions you can ask to find out whether the PCI program will be simple:
One of SecurityMetrics' features in their PCI program is FastPass, a service that reduces questions and pre-fills answers based on what payment technology a merchant may be using.
Additionally, with SecurityMetrics’ PCI program, acquirers can track their merchants’ compliance in one place and can report on over 100 fields of data. This gives you the option to stay shallow or drill down deep. It's up to you and your needs.
SecurityMetrics makes PCI compliance simple for acquirers and merchants by offering a full-service team of experts (QSA, ASV, PFI, SSF) that allows them to help their partners with all levels of merchants and service providers.
We’re a managed Security provider with over 20 years of data security experience and PCI certified.
SecurityMetrics also has a streamlined way to care for L1 and L2 merchants that is similar to L4 merchants, as well as a way to report information to them.
If you recall the most common frustrations of merchants and acquirers, you’ll notice that a majority of these can be eliminated through a simple program and quality support.
Some merchants may choose to deal with the consequences of a data breach rather than waste time with poor support. On the other hand, if a PCI program offers top-notch assistance, it will become worthwhile to merchants to avoid the risk of a data breach and maintain their PCI compliance.
When a merchant needs help, they should be able to easily get in contact with qualified support staff through the phone, email, or a live chat.
Here are some questions you should ask about the support in the PCI program:
SecurityMetrics offers award-winning support. SecurityMetrics support agents are available 24/7, along with live chat, email support, and a self-serve merchant portal. Merchant calls are answered in less than 15 seconds, on average.
Each of the support agents is a qualified expert who can help you with your questions and concerns.
In addition, a quality PCI program will offer education and training so that merchants and acquirers can find their own answers and solutions. SecurityMetrics has numerous educational resources for their clients that include webinars, blogs, podcasts, a free security academy, and training options.
There are many cost factors to consider when purchasing security. Here are some questions to consider as you decide which PCI program to invest in.
Perhaps the most important question to ask is “what do I want out of a PCI program?” If you’re looking for a high-quality program that will help merchants achieve and maintain compliance in the simplest way possible, it will cost you more than a program that is selling mediocre support and resources.
Other important cost questions include:
If you are looking for the cheapest option, other providers may come at a lower cost.
But if you're looking for premium support, products, and services, SecurityMetrics is the best choice.
Not to mention that SecurityMetrics offers additional products that can increase your revenue and add value to your merchants, such as:
While some PCI programs are attractive because of their low cost, they may ultimately not help acquirers and merchants with their goal of becoming PCI compliant.
SecurityMetrics offers a high-quality, robust program because their objective is to get all merchants to achieve and maintain PCI compliance. Currently, 93.6% of SecurityMetrics customers that started their SAQ have achieved a passing status within an average of 20.33 days.
If you decide that SecurityMetrics is the best solution for you and your company, you can get more detailed information about their PCI Programs here.