Wednesday, July 08, 2009

Trick Question: Can PCI DSS Apply If …

a merchant does NOT store, process, or transmit any cardholder data on merchant premises?

The answer is “Of course!”

Simply if you accept cards, but process them somewhere else. SAQ A (doc) is small, but decidedly not empty.

Just a thought inspired by Trey here.

Dr Anton Chuvakin