Mastercard SPME §2.2.2 · May 2023 → Sep 2023

Merchant Compliance Requirements

substantive

The update adds a requirement that Acquirers ensure Merchants transitioning between PCI levels achieve compliance with the new level within one year. It also mandates Level 1-3 Merchants using third-party payment software to validate their software's PCI compliance via the PCI SSC website. Other recommendations remain unchanged.

Sources Mastercard SPME · May 2023 · page 22 PDF Mastercard SPME · Sep 2023 · page 21 PDF KYB Acquirer current
Also in §2.x this release substantive §2 Cleared, meaning the Acquirer transferred the Transaction Data within the substantive §2.1.1 Payment Card Industry (PCI) Security Standards substantive §2.2 Mastercard Site Data Protection (SDP) Program substantive §2.2.4 Mastercard Cybersecurity Incentive Program (CSIP) substantive §2.2.5 SDP Program Noncompliance Assessments substantive §2.2.6 Mandatory Compliance Requirements for Compromised Entities substantive §2.3 Card Production Security Standards substantive §2.4.1 PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
Why these edits? The new requirement explicitly mandates Acquirers ensure Merchants transitioning between PCI levels achieve compliance within one year, expanding Acquirer responsibilities under Merchant KYB obligations.
Mastercard SPME §2.2.2
Security Rules and Procedures—Merchant Edition • 7 February 1 August 2023 means by which a Merchant may validate PCI DSS compliance if implementing secure technologies. The Acquirer must ensure, with respect to each of its Merchants, that “transition” from one PCI level to another (for example, the Merchant transitions from Level 4 to Level 3 due to Transaction volume increases), that such Merchant achieves compliance with the requirements of the applicable PCI level as soon as practical, but in any event not later than one year after the date of the event that results in or causes the Merchant to transition from one PCI level to another. All Level 1, Level 2, and Level 3 Merchants that use any third party-provided payment applications or payment software must validate that each payment application or payment software used is listed on the PCI Security Standards Council (SSC) website at www.pcisecuritystandards.org as compliant with either the Payment Card Industry Payment Application Data Security Standard (PCI PA- ¶ DSSPA-DSS) or the PCI Secure Software Standard, as applicable. Mastercard recommends that Merchants use a Qualified Integrator & Reseller (QIR) listed on the PCI SSC website to implement a PCI PA-DSS-compliant payment application, as applicable. Mastercard recommends that Merchants using third party-provided payment software ensure the payment software vendor complies with the PCI Secure SLC Standard. Mastercard recommends that any Merchant that performs or provides 3-D Secure (3DS) functions as defined in the EMV 3-D Secure Protocol and Core Functions Specification comply with the PCI 3DS Core Security Standard and use approved 3DS Software Development Kits (SDKs) listed on the PCI SSC website, as applicable. Level 1 Merchants A Merchant that meets any one or more of the following criteria is deemed to be a ¶ Level 1 Level 1 Merchant and must validate compliance with the PCI DSS: • Any Merchant having greater than six million total combined Mastercard and Maestro Transactions annually, • Any Merchant meeting the Level 1 criteria of Visa, and • Any Merchant that Mastercard, in its sole discretion, determines should meet ¶ the Level 1 the Level 1 Merchant requirements to minimize risk to the system, which may include any Merchant that has a confirmed ADC Event. To validate compliance, each Level 1 Merchant must successfully undergo an annual PCI DSS assessment resulting in the completion of a ROC conducted by a PCI SSC-approved Qualified Security Assessor (QSA) or PCI SSC-certified Internal Security Assessor (ISA). Level 2 Merchants Unless deemed to be a Level 1 Merchant, the following are deemed to be a Level 2 ¶ Merchant Merchant and must validate compliance with the PCI DSS: • Any Merchant with greater than one million but less than or equal to six million total combined Mastercard and Maestro Transactions annually, and • Any Merchant meeting the Level 2 criteria of Visa. Cybersecurity Standards and Programs Level 1 Merchants Security Rules and Procedures—Merchant Edition • 1 August 2023 To validate compliance, each Level 2 Merchant must successfully complete an annual SAQ. Level 2 Merchants completing SAQ A, SAQ A-EP or SAQ D must additionally engage a PCI SSC-approved SSC- approved QSA or PCI SSC-certified ISA for compliance validation. Level 2 Merchants may alternatively, at their own discretion, engage a PCI SSC- ¶ approved SSC-approved QSA or PCI SSC-certified ISA to complete a ROC instead of performing an SAQ. ¶ Cybersecurity Standards and Programs ¶ Level 1 Merchants ¶ Security Rules and Procedures—Merchant Edition • 7 February 2023 Level 3 Merchants Unless deemed to be a Level 1 or Level 2 Merchant, the following are deemed to be a Level 3 Merchant and must validate compliance with the PCI DSS: • Any Merchant with greater than 20,000 but less than or equal to one million total combined Mastercard and Maestro electronic commerce (e-commerce) Transactions annually, and • Any Merchant meeting the Level 3 criteria of Visa. To validate compliance, each Level 3 Merchant must successfully complete an annual SAQ. Level 3 Merchants may alternatively, at their own discretion, engage a PCI SSC- ¶ approved SSC-approved QSA to complete a ROC instead of performing an SAQ. Level 4 Merchants Any Merchant not deemed to be a Level 1, Level 2, or Level 3 Merchant is deemed to be a Level 4 Merchant. Compliance with the PCI DSS is required for a Level 4 Merchant, although validation of compliance is optional for a Level 4 Merchant. However, a validation of compliance is strongly recommended for Acquirers with respect to each Level 4 Merchant in order to reduce the risk of an ADC Event and for an Acquirer potentially to gain a partial waiver of related assessments. A Level 4 Merchant may validate compliance with the PCI DSS by successfully completing an annual SAQ. Level 4 Merchants may alternatively, at their own discretion, engage a PCI SSC- ¶ approved SSC-approved QSA to complete a ROC instead of performing an SAQ.
Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME 2.1, 11.2.6
+ authority: Mastercard SPME 2.1, 11.2.6, 2.2.2
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
# The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
- # This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.
+ # Acquirers must also ensure that any Merchant transitioning from one PCI DSS compliance level to another (e.g., from Level 4 to Level 3) achieves compliance with the requirements of the new level within one year of the transition event, in accordance with Mastercard SPME 2.2.2.
+ # This expands Acquirer responsibility to actively monitor PCI DSS level transitions and validate timely compliance.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform Know Your Business (KYB) due diligence on merchants before onboarding and on a recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a minimum set of documents for each merchant to establish business legitimacy, confirm beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification reviews. Merchants that fail to supply required documentation within the stipulated period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

7. Ensure that if a Merchant transitions from one PCI compliance level to another (for example, from Level 4 to Level 3) due to transaction volume or other criteria changes, the Merchant achieves compliance with the new level's requirements as soon as practical and no later than one year after the transition event.

Source authority: Mastercard SPME ��������2.1, §2.1, 2.2.2, 11.2.6.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform Know Your Business (KYB) due diligence on merchants before onboarding and on a recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a minimum set of documents for each merchant to establish business legitimacy, confirm beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification reviews. Merchants that fail to supply required documentation within the stipulated period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

7. Ensure that if a Merchant transitions from one PCI compliance level to another (for example, from Level 4 to Level 3) due to transaction volume or other criteria changes, the Merchant achieves compliance with the new level's requirements as soon as practical and no later than one year after the transition event.

Source authority: Mastercard SPME ��������2.1, §2.1, 2.2.2, 11.2.6.

Source authority: Mastercard SPME §2.2.2.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME 2.1, 11.2.6
+authority: Mastercard SPME 2.1, 11.2.6, 2.2.2
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -13,4 +13,5 @@
   - eu_consolidated
 agent_owner: kyb_agent
 # The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
-# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+# Acquirers must also ensure that any Merchant transitioning from one PCI DSS compliance level to another (e.g., from Level 4 to Level 3) achieves compliance with the requirements of the new level within one year of the transition event, in accordance with Mastercard SPME 2.2.2.
+# This expands Acquirer responsibility to actively monitor PCI DSS level transitions and validate timely compliance.

--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -1,16 +1,10 @@
 # Acquirer KYB (Know Your Business) Obligations
 
-Acquirers processing transactions on the Mastercard network are required to perform
-Know Your Business (KYB) due diligence on merchants before onboarding and on a
-recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
-minimum set of documents for each merchant to establish business legitimacy, confirm
-beneficial ownership, and satisfy anti-money laundering screening requirements.
+Acquirers processing transactions on the Mastercard network are required to perform Know Your Business (KYB) due diligence on merchants before onboarding and on a recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a minimum set of documents for each merchant to establish business legitimacy, confirm beneficial ownership, and satisfy anti-money laundering screening requirements.
 
 ## When this policy applies
 
-This policy applies to all new merchant onboarding and to all periodic re-verification
-reviews. Merchants that fail to supply required documentation within the stipulated
-period must be suspended from processing until compliance is restored.
+This policy applies to all new merchant onboarding and to all periodic re-verification reviews. Merchants that fail to supply required documentation within the stipulated period must be suspended from processing until compliance is restored.
 
 ## Required actions
 
@@ -20,5 +14,6 @@
 4. Schedule a full re-verification review at least once every 365 days.
 5. Document all verification outcomes and retain records for audit purposes.
 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
+7. Ensure that if a Merchant transitions from one PCI compliance level to another (for example, from Level 4 to Level 3) due to transaction volume or other criteria changes, the Merchant achieves compliance with the new level's requirements as soon as practical and no later than one year after the transition event.
 
-Source authority: Mastercard SPME 2.1, 11.2.6.+Source authority: Mastercard SPME §2.1, 2.2.2, 11.2.6.