Mastercard SPME §2.1.1 · May 2023 → Sep 2023

Payment Card Industry (PCI) Security Standards

substantive

The updated section removes all references to PCI PIN Security Requirements, PIN Transaction Security, Forensic Investigator Program Guide, and focuses solely on PCI Software Security Framework standards, emphasizing compliance and recommendations related only to software security for merchants and service providers.

Sources Mastercard SPME · May 2023 · page 17 PDF Mastercard SPME · Sep 2023 · page 17 PDF KYB Acquirer current
Also in §2.x this release substantive §2 Cleared, meaning the Acquirer transferred the Transaction Data within the substantive §2.2 Mastercard Site Data Protection (SDP) Program substantive §2.2.2 Merchant Compliance Requirements substantive §2.2.4 Mastercard Cybersecurity Incentive Program (CSIP) substantive §2.2.5 SDP Program Noncompliance Assessments substantive §2.2.6 Mandatory Compliance Requirements for Compromised Entities substantive §2.3 Card Production Security Standards substantive §2.4.1 PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
Why these edits? The updated SPME section 2.1.1 removes the PCI PIN Security and Forensic Investigator requirements, focusing solely on PCI Software Security Framework standards, which shifts compliance obligations relating to acquirer responsibilities for software security rather than hardware or forensic investigations.
Mastercard SPME §2.1.1
Security Rules and Procedures—Merchant Edition • 7 February 1 August 2023 PCI Security Standard Compliance Requirements and Recommendations ¶ PCI PIN Security Requirements ¶ PCI PIN Transaction Security (PTS) Point of ¶ Interaction (POI) Modular Security ¶ Requirements ¶ PCI PIN Transaction Security (PTS) ¶ Hardware Security Module (HSM) Security ¶ Requirements ¶ PCI PIN Transaction Security (PTS) Device ¶ Testing and Approval Program Guide and PCI ¶ Approved PTS Devices list ¶ PCI Software-based PIN Entry on COTS ¶ (SPoC)™ Security Requirements ¶ Compliance is required for all Customers ¶ and their agents performing PIN ¶ encipherment or any other aspect of PIN ¶ processing involving PIN entry by means of ¶ a: ¶ • ¶ PIN entry device (PED) or encrypting PIN ¶ pad (EPP) on a Terminal (including a ¶ Mobile Point-of-Sale [MPOS] Terminal); ¶ or ¶ • ¶ PIN Cardholder Verification Method ¶ (CVM) Application for software-based ¶ PIN entry on a Commercial Off-The-Shelf ¶ (COTS) device (“SPoC Solution”). ¶ Refer to section 2.4 for more information; ¶ also see Chapter 4 for additional PIN- ¶ related requirements. ¶ PCI Forensic Investigator Program Guide ¶ (“PFI Program Guide”) ¶ Compliance is required for any Acquirer that ¶ engages the services of a PCI SSC Forensic ¶ Investigator (PFI) to conduct an ¶ independent forensic investigation in order ¶ to assess the cause, scope, magnitude, ¶ duration, and effects of an ADC Event or ¶ Potential ADC Event. PCI Software Security Framework (SSF)—PCI PCI Secure Software Requirements and Assessment Assessment Procedures (“PCI Secure Software Standard”) Compliance is required for all Merchants and and Service Providers that use eligible third party- party-provided provided payment software. Refer to the PCI Secure Software Program Guide for information information about the applicability of the PCI Secure Software Standard to third party-provided payment software. PCI Software Security Framework (SSF)—PCI PCI Secure Software Lifecycle (Secure SLC) Requirements and Assessment Procedures (“PCI Secure SLC Standard”) Compliance is strongly recommended for any any Merchant or Service Provider that uses third party- third party-provided provided payment software.
Halyard Pay · 2 files
program: Acquirer KYB
authority: Mastercard SPME 2.1, 11.2.6
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
# The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.
+ # Updated Mastercard SPME 2.1.1 simplifies PCI compliance obligations relevant to software security standards, removing references to PIN and forensic requirements, thus emphasizing adherence to the PCI Secure Software Standard and Secure SLC Standard only.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

Note: Recent updates to Mastercard SPME §2.1.1 emphasize compliance focus on software security standards under the PCI Software Security Framework, superseding prior hardware-focused and forensic investigation requirements. This shift reinforces the importance of software security for merchants and service providers using third-party payment software.

Source authority: Mastercard SPME ��������2.1, 11.2.6.§§2.1, 11.2.6, 2.1.1.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

Note: Recent updates to Mastercard SPME §2.1.1 emphasize compliance focus on software security standards under the PCI Software Security Framework, superseding prior hardware-focused and forensic investigation requirements. This shift reinforces the importance of software security for merchants and service providers using third-party payment software.

Source authority: Mastercard SPME ��������2.1, 11.2.6.§§2.1, 11.2.6, 2.1.1.

Source authority: Mastercard SPME §2.1.1.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -13,4 +13,5 @@
   - eu_consolidated
 agent_owner: kyb_agent
 # The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
-# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.
+# Updated Mastercard SPME 2.1.1 simplifies PCI compliance obligations relevant to software security standards, removing references to PIN and forensic requirements, thus emphasizing adherence to the PCI Secure Software Standard and Secure SLC Standard only.

--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -21,4 +21,6 @@
 5. Document all verification outcomes and retain records for audit purposes.
 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
 
-Source authority: Mastercard SPME 2.1, 11.2.6.+Note: Recent updates to Mastercard SPME §2.1.1 emphasize compliance focus on software security standards under the PCI Software Security Framework, superseding prior hardware-focused and forensic investigation requirements. This shift reinforces the importance of software security for merchants and service providers using third-party payment software.
+
+Source authority: Mastercard SPME §§2.1, 11.2.6, 2.1.1.