Our experts make PCI compliance simple



  • The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements designed to ensure that ALL companies that process, store or transmit credit card information maintain a secure environment. Essentially any merchant that has a Merchant ID (MID).
  • This set of 12 requirements was developed by the founding payment brands of the PCI Security Standards Council (American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International) to facilitate the adoption of consistent data security measures globally. The PCI DSS includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures intended to proactively protect customer account data.
  • Important point to note is that the payment brands and acquirers are responsible for enforcing compliance, not the PCI council. So if Payleaf works with Elavon for payment processing, then Elavon requires all its merchant account holders to submit quarterly & annual proofs of PCI compliance. Else, they levy a non-compliance fee.
  • Payleaf provides a simple process for completing the PCI DSS Compliance questionnaire and certifying compliance with the PCI DSS standards requirement. Our portal to register for PCI compliance services is located at http://pci-compliance.osms.biz/.
  • Once the merchants sign-up on this link, we help them individually with completing their SAQs and scans and then uploading them onto the acquirer's portal.
  • The PCI compliance program requires merchants to complete one or both of the below activities:
    • A self-assessment Questionnaire and certification of compliance (Annually)
    • A quarterly network vulnerability scan (if applicable)
      • Payleaf being a Level 1 PCI compliant service provider , is one of the few providers
        whose merchant customers don't need to submit any quarterly scans.
        They only need to submit an annual SAQ for compliance.
  • Do let us know, if you have any questions or concerns send_quick_message
  • For additional information on the PCI DSS or the individual card brands' data security requirements and programs, please visit the following links:
    • PCI Security Standards Council site (http://www.pcisecuritystandards.org)
    • VISA CISP (http://www.visa.com/cisp)
    • MasterCard SDP (http://www.mastercard.com/sdp)
    • Discover DISC (http://www.discovernetwork.com/resources/data/data_security_overview.html)
Premium SSL Certificate