Visa has shaken many U.S. businesses with its latest announcement declaring that it’s moving to EMV chip-based technology, which will replace the magnetic strips used on most U.S. cards. The company will also provide incentives to merchants adopting the technology.
Visa has stated that any merchant whose transactions are at least 75 percent EMV will not need to VALIDATE its PCI compliance. In other words, if a Level 1 merchant who previously had to submit a ROC to VISA proving that he was PCI compliant starts taking EMV payments, he can avoid paying a QSA for a ROC.
Merchants are not off the hook for PCI; quite the contrary. They must still be completely PCI compliant. The only difference is that they do not need to prove it. The concern many security experts have with this plan from Visa is that if merchants do not need to prove their compliance, then what is the chance that they will maintain secure systems? PCI came out in 2004, and sensitive card data is still being stolen at an alarming rate. Many of the recent breaches, such as Sony and Citi, would not have been prevented with EMV technology. They still had vulnerable systems, and that was before the reduction in reporting requirements contemplated by Visa.
The other card brands have not made a statement confirming or denying that they will follow the same path as Visa, so it’s unclear if ROCs will shortly be a thing of the past for merchants. It is possible that all merchants will eventually be facing the same dilemma as small merchants do today. No one will ask about your PCI compliance until you have a breach. At that point, you will need to produce everything that PCI demands. If you cannot, your guilt in the matter is concluded automatically. (The card brands will still try to determine a root cause, but quite often we have seen that the lack of PCI compliance is usually the “catch all” used for blame.)
We applaud Visa for implementing stronger security and trying to find a way to give merchants an incentive to follow suit. However, eliminating the ROC seems to be a rash decision. It would simply make more sense to eliminate the parts of the ROC that are no longer applicable for those merchants. Much of the ROC would still remain, such as the physical security, implemented procedures , business processes or even electronic storage components that are not protected by an EMV implementation. PCI validation is much more than electronic storage, and to eliminate the need to validate proper security seems like going a step too far.
562
http://global.networldalliance.com/new/images/slideshows/show562_thumb8595.jpg
Order up: EMN8's self-order tech at Domino's, KFC India
Order up: EMN8's self-order tech at Domino's, KFC India
559
http://global.networldalliance.com/new/images/slideshows/show559_thumb8515.jpg
Naked Pizza thrives in Dubai
Naked Pizza thrives in Dubai
542
http://global.networldalliance.com/new/images/slideshows/show542_thumb8207.gif
Minsky's Pizza turns 37
Minsky's Pizza turns 37
537
http://global.networldalliance.com/new/images/slideshows/show537_thumb8119.gif
NAFEM 2013
NAFEM 2013
531
http://global.networldalliance.com/new/images/slideshows/show531_thumb8031.gif
Pizza chains' LTOs kick off 2013
Pizza chains' LTOs kick off 2013
512
http://global.networldalliance.com/new/images/slideshows/show512_thumb7713.gif
The Loop Pizza Grill new restaurant prototype
The Loop Pizza Grill new restaurant prototype
506
http://global.networldalliance.com/new/images/slideshows/show506_thumb7615.gif
Patxi's Pizza's new menu items
Patxi's Pizza's new menu items
505
http://global.networldalliance.com/new/images/slideshows/show505_thumb7583.jpg
4 technologies gaining ground in restaurant industry
4 technologies gaining ground in restaurant industry
495
http://global.networldalliance.com/new/images/slideshows/show495_thumb7351.gif
Boston Pizza's new menu
Boston Pizza's new menu
492
http://global.networldalliance.com/new/images/slideshows/show492_thumb7311.gif
September pizza launches
September pizza launches
Restaurant technology news, trends & best practices
http://global.networldalliance.com/new/images/products/5079.png
5079/Restaurant-technology-news-trends-best-practices
Put your menu in your customers' pocket
http://global.networldalliance.com/new/images/products/1293.png
1293/Put-your-menu-in-your-customers-pocket
Quote decoder: how to compare restaurant POS systems
http://global.networldalliance.com/new/images/products/1290.png
1290/Quote-decoder-how-to-compare-restaurant-POS-systems
Financial Through-the-Wall ATM
http://global.networldalliance.com/new/images/products/FT5000_100_0708.gif
536/Financial-Through-the-Wall-ATM
DriverAdvisor Fleet Monitoring
http://global.networldalliance.com/new/images/products/DriverAdvisor_iix.gif
1425/DriverAdvisor-Fleet-Monitoring
Leapfrog POS App
http://global.networldalliance.com/new/images/products/4559.png
4559/Leapfrog-POS-App
Mexican Style Meats and Taco Filling | Burke Corporation |
http://global.networldalliance.com/new/images/products/Chorizo100.jpg
1298/Mexican-Style-Meats-and-Taco-Filling-Burke-Corporation
Features
http://global.networldalliance.com/new/images/products/4541.png
4541/Features
Call Center Ordering
http://global.networldalliance.com/new/images/products/5939.png
5939/Call-Center-Ordering
DiamondTouch Point-of-Sale
http://global.networldalliance.com/new/images/products/4283.png
4283/DiamondTouch-Point-of-Sale
|
Inside Networld Media Group Network QSRWeb
|
Popular on Networld Media Group | Other Networld Media Group Sites | Global Partners |
User Comments