Post by rrgon11 » Mon May 15, 2017 7:04 pm

Hello Guys!
Is open cart PCI compliant? I have heard that PCI Data Security Standard compliance is extremely important in protecting customers credit card data. I have hosted my website in godaddy and my website is secured with SSL certificate provided by godaddy.
How can I assure if everything is compliant and safe? What else should I do to make it more secure? What all are needed to obtain the PCI certification? If I obtain the certification, how long will it be valid for?

Newbie

Posts

Joined
Mon May 15, 2017 7:02 pm

Post by MrPhil » Mon May 15, 2017 9:06 pm

PCI-DSS compliance is more than just having SSL. First of all, unless customer credit card data actually flows through your site (as opposed to being submitted directly to a Third Party payment system such as PayPal), you don't need PCI. On the other hand, if you accept credit card data onto your site, even if you don't store it, you must meet PCI standards. This applies to most payment gateway/merchant account setups, including manually entering the credit card into your store POS system, or mailing the credit card number (encrypted or not) to one or more addresses (the latter two probably violate your merchant account agreement). To be PCI compliant you will have to be audited, which can be fairly expensive. Auditors will not only check for adequate SSL encryption strength, but also physical and network intrusion security at the data center, who gets access to customer data, what internal safeguards you have, how sensitive data is stored (including encryption), etc.

User avatar
Active Member

Posts

Joined
Wed May 10, 2017 11:52 pm

Post by JWire » Mon May 22, 2017 10:39 am

Look into Stripe extensions to accept credit cards on your site. It's PCI compliant and easy to implement last I checked.

Newbie

Posts

Joined
Mon Feb 02, 2015 6:54 am

Post by web-project » Sat Jun 03, 2017 9:29 pm

to be PCI compliant you need be sure the following:
- you don't store the card details anywhere in database if you are on shared server
- make sure that CVV is not store anywhere
- transactions are processed real time
- customer details should be transmitted via secure protocol only

The stripe is ideal payment gateway as the card details are processed and stored on stripe servers and nothing to do with your website.

New member

Posts

Joined
Tue Sep 06, 2016 9:06 pm
Location - Stevenage, UK
Who is online

Users browsing this forum: No registered users and 17 guests