Mastercard SPME §2.2.4 · May 2023 → Sep 2023
Mastercard Cybersecurity Incentive Program (CSIP)
The section has been extensively revised to introduce the Mastercard Cybersecurity Incentive Program (CSIP), which offers eligible merchants reduced PCI compliance validation or exemption through secure technologies like EMV, P2PE, or tokenization. It replaces and expands former rules with detailed certification requirements and thresholds based on transaction types and regions.
Security Rules and Procedures—Merchant Edition • 7 February 2023
Mastercard, this and other criteria may be waived if the Merchant validated full PCI DSS compliance at the time of the ADC Event or Potential ADC Event.
- The Merchant must establish and annually test an ADC Event incident response plan. Information about the PCI DSS Prioritized Approach is available at: https://www.pcisecuritystandards.org/document_library Mastercard PCI DSS Compliance Validation Exemption Program All qualifying Merchants may participate in the Mastercard PCI DSS Compliance Validation Exemption Program (Exemption Program), which exempts the Merchant from annually validating its compliance with the PCI DSS. To qualify or remain qualified to participate in the Exemption Program, a duly authorized and empowered officer of the Merchant must certify to the Merchant’s Acquirer in writing that the Merchant has satisfied all of the following:
The Mastercard Cybersecurity Incentive Program (CSIP) provides eligible Merchants using secure technologies such as EMV chip technology, a PCI-listed point-to-point encryption (P2PE) Cybersecurity Standards and Programs Level 1 Service Providers Security Rules and Procedures—Merchant Edition • 1 August 2023
solution, or EMV payment tokenization increased flexibility within the SDP Standards. The CSIP is a component of the SDP Program and is optional for Merchants. The CSIP incentivizes Merchant participation by either reducing PCI compliance validation requirements or by eliminating the requirement to annually validate compliance with the PCI DSS. Mastercard PCI DSS Risk-based Approach A qualifying Level 1 or Level 2 Merchant located outside of the U.S. Region may use the Mastercard PCI DSS Risk-based Approach, which reduces a Merchant’s compliance requirements to validating compliance with the first two of the six total milestones set forth in the PCI DSS Prioritized Approach, as follows:
- A Level 1 Merchant must validate compliance through a PCI DSS assessment resulting in the completion of a ROC conducted by a PCI SSC-approved QSA or PCI SSC-certified ISA;
- A Level 2 Merchant must validate compliance through an SAQ. Level 2 Merchants completing SAQ A, SAQ A-EP or SAQ D must additionally engage a PCI SSC-approved QSA or PCI SSC- certified ISA for compliance validation; and
- Each Level 1 and Level 2 Merchant must annually re-validate compliance with milestones one and two using an SAQ. To qualify as compliant with the Mastercard PCI DSS Risk-based Approach, a Merchant must satisfy all of the following:
- The Merchant must certify that it is not storing Sensitive Authentication Data.
- On a continuous basis, the Merchant must keep fully segregated the “Card-not-present” Transaction environment from the “face-to-face” Transaction environment. A face-to-face Transaction requires the Card, the Cardholder, and the Merchant to all be present together at the time and place of the Transaction.
- For a Merchant located in the Europe Region, at least 95 percent of the Merchant’s annual total count of Card-present Mastercard and Maestro Transactions must occur at Hybrid POS Terminals.
- For a Merchant located in the Asia/Pacific Region, Canada Region, Latin America and the Caribbean Region, or Middle East/Africa Region, at least 75 percent of the Merchant’s annual total count of Card-present Mastercard and Maestro Transactions must occur at Hybrid POS Terminals.
- The Merchant must not have experienced an ADC Event or Potential ADC Event within the last 3 years, including but not limited to outstanding liabilities or actions preventing complete closure of ADC Event. At the discretion of Mastercard, this and other criteria may be waived if the Merchant validated full PCI DSS compliance at the time of the ADC Event or Potential ADC Event.
- The Merchant must establish and annually test an ADC Event incident response plan. Information about the PCI DSS Prioritized Approach is available at: https://www.pcisecuritystandards.org/document_library Cybersecurity Standards and Programs Mastercard PCI DSS Risk-based Approach Security Rules and Procedures—Merchant Edition • 1 August 2023 Mastercard PCI DSS Compliance Validation Exemption Program All qualifying Merchants may participate in the Mastercard PCI DSS Compliance Validation Exemption Program (Exemption Program), which exempts the Merchant from annually validating its compliance with the PCI DSS. To qualify or remain qualified to participate in the Exemption Program, a duly authorized and empowered officer of the Merchant must certify to the Merchant’s Acquirer in writing that the Merchant has satisfied all of the following:
- The Merchant does not store Sensitive Authentication Data. The Acquirer must notify Mastercard through compliance validation reporting of the status of Merchant storage of Sensitive Authentication Data;
- The Merchant has not been identified by Mastercard as having experienced an ADC Event or Potential ADC Event during the prior three years, including but not limited to outstanding liabilities or actions preventing complete closure of ADC Event;
- The Merchant has established and annually tests an ADC Event incident response plan in accordance with PCI DSS requirements; and
- The Merchant has satisfied one of the following:
- At least 75 percent of the Merchant’s annual total acquired Mastercard and Maestro Transaction count is processed through Hybrid POS Terminals, as determined based on the Merchant’s transactions processed during the previous twelve (12) months through the Global Clearing Management System (GCMS) and/or Single Message System. Transactions that were not processed by Mastercard may be included in the annual acquired Transaction count if the data is readily available to Mastercard;
- The Merchant has implemented a P2PE solution listed on the PCI SSC website; OR
- At least 75 percent of the Merchant’s annual total acquired Mastercard and Maestro Transaction count is processed using Mastercard Tokens from TSPs compliant with the Token Service Provider Standards. As a best practice, qualifying Merchants participating in the Exemption Program are recommended to validate compliance with the PCI DSS within the previous twelve (12) months of entering the Exemption Program. An Acquirer must retain all Merchant certifications of eligibility for the Exemption Program for a minimum of five (5) years. Upon request by Mastercard, the Acquirer must provide a Merchant’s certification of eligibility for the Exemption Program and any documentation and/or other information applicable to such certification. An Acquirer is responsible for ensuring that each Exemption Program certification is truthful and accurate. A Merchant that does not satisfy the Exemption Program’s eligibility criteria, including any Merchant whose Transaction volume is primarily from e-commerce that does not utilize EMV Payment Tokenization and Mail Order/Telephone Order (MO/TO) acceptance channels, must continue to validate its PCI DSS compliance in accordance with section 2.2.2. All Merchants must maintain ongoing compliance with the PCI DSS regardless of whether annual compliance validation is a requirement. Cybersecurity Standards and Programs Mastercard PCI DSS Compliance Validation Exemption Program Security Rules and Procedures—Merchant Edition • 1 August 2023
program: Acquirer KYB- authority: Mastercard SPME 2.1, 11.2.6+ authority: Mastercard SPME 2.1, 2.2.4, 11.2.6required_documents:- incorporation- beneficial_ownership- aml_screen- license_verification+ - pci_dss_certification # Added to reflect compliance validation reporting related to PCI DSSmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent- # The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.- # This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+ # Acquirers must collect and retain Merchant certifications of PCI DSS compliance or+ # eligibility for programs like the Cybersecurity Incentive Program (CSIP), which allows+ # for reduced or exempted annual PCI DSS validation for Merchants using secure+ # technologies such as EMV chip, P2PE, or Mastercard Tokenization, as outlined in+ # Mastercard SPME §2.2.4.+ #+ # Merchants must certify the absence of Sensitive Authentication Data storage, the+ # establishment and annual testing of an ADC Event incident response plan, and meet+ # transaction thresholds for Hybrid POS Terminals or use approved P2PE/tokenization.+ # The Acquirer is responsible for notifying Mastercard of Merchant status per compliance+ # validation reporting and retaining these certifications for a minimum of five years.+ #+ # Other obligations per SPME 11.2.6 remain unchanged, including retention of MATCH records+ # for two years following agreement termination or expiration.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
## New Compliance Validation Obligations Related to PCI DSS
Mastercard has introduced the Cybersecurity Incentive Program (CSIP), an optional program designed to encourage merchants to adopt enhanced security technologies, including EMV chip, PCI-listed point-to-point encryption (P2PE), and EMV payment tokenization. Under this program, qualifying Merchants may reduce or eliminate the annual PCI DSS compliance validation requirement by certifying adherence to specified security standards.
Halyard Pay, as an acquirer, must ensure that Level 1 and Level 2 Merchants utilize the Mastercard PCI DSS Risk-based Approach or participate in the PCI DSS Compliance Validation Exemption Program where applicable. This includes verifying that Merchants:
- Maintain segregation between Card-not-present and face-to-face transaction environments.
- Meet regional thresholds for transactions processed via Hybrid POS Terminals or implement approved P2PE or tokenization solutions.
- Have not experienced an Account Data Compromise (ADC) Event within the past three years, or have otherwise met exemptions.
- Establish and annually test an ADC Event incident response plan.
Acquirers must collect and retain written certifications from Merchants confirming eligibility for the Exemption Program and provide supporting documentation upon Mastercard's request. These certifications should be retained for a minimum of five years.
Ongoing compliance with PCI DSS remains mandatory for all Merchants, regardless of exemption status.
Source authority: Mastercard SPME ��������2.1, §§2.1, 2.2.4, 11.2.6.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
## New Compliance Validation Obligations Related to PCI DSS
Mastercard has introduced the Cybersecurity Incentive Program (CSIP), an optional program designed to encourage merchants to adopt enhanced security technologies, including EMV chip, PCI-listed point-to-point encryption (P2PE), and EMV payment tokenization. Under this program, qualifying Merchants may reduce or eliminate the annual PCI DSS compliance validation requirement by certifying adherence to specified security standards.
Halyard Pay, as an acquirer, must ensure that Level 1 and Level 2 Merchants utilize the Mastercard PCI DSS Risk-based Approach or participate in the PCI DSS Compliance Validation Exemption Program where applicable. This includes verifying that Merchants:
- Maintain segregation between Card-not-present and face-to-face transaction environments.
- Meet regional thresholds for transactions processed via Hybrid POS Terminals or implement approved P2PE or tokenization solutions.
- Have not experienced an Account Data Compromise (ADC) Event within the past three years, or have otherwise met exemptions.
- Establish and annually test an ADC Event incident response plan.
Acquirers must collect and retain written certifications from Merchants confirming eligibility for the Exemption Program and provide supporting documentation upon Mastercard's request. These certifications should be retained for a minimum of five years.
Ongoing compliance with PCI DSS remains mandatory for all Merchants, regardless of exemption status.
Source authority: Mastercard SPME ��������2.1, §§2.1, 2.2.4, 11.2.6.
Source authority: Mastercard SPME §2.2.4.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -1,10 +1,11 @@ program: Acquirer KYB -authority: Mastercard SPME 2.1, 11.2.6 +authority: Mastercard SPME 2.1, 2.2.4, 11.2.6 required_documents: - incorporation - beneficial_ownership - aml_screen - license_verification + - pci_dss_certification # Added to reflect compliance validation reporting related to PCI DSS min_review_cycle_days: 365 suspension_trigger: document_collection_failure record_retention_years: 7 @@ -12,5 +13,17 @@ - ofac_sdn - eu_consolidated agent_owner: kyb_agent -# The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6. -# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+# Acquirers must collect and retain Merchant certifications of PCI DSS compliance or +# eligibility for programs like the Cybersecurity Incentive Program (CSIP), which allows +# for reduced or exempted annual PCI DSS validation for Merchants using secure +# technologies such as EMV chip, P2PE, or Mastercard Tokenization, as outlined in +# Mastercard SPME §2.2.4. +# +# Merchants must certify the absence of Sensitive Authentication Data storage, the +# establishment and annual testing of an ADC Event incident response plan, and meet +# transaction thresholds for Hybrid POS Terminals or use approved P2PE/tokenization. +# The Acquirer is responsible for notifying Mastercard of Merchant status per compliance +# validation reporting and retaining these certifications for a minimum of five years. +# +# Other obligations per SPME 11.2.6 remain unchanged, including retention of MATCH records +# for two years following agreement termination or expiration. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -21,4 +21,19 @@ 5. Document all verification outcomes and retain records for audit purposes. 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements. -Source authority: Mastercard SPME 2.1, 11.2.6.+## New Compliance Validation Obligations Related to PCI DSS + +Mastercard has introduced the Cybersecurity Incentive Program (CSIP), an optional program designed to encourage merchants to adopt enhanced security technologies, including EMV chip, PCI-listed point-to-point encryption (P2PE), and EMV payment tokenization. Under this program, qualifying Merchants may reduce or eliminate the annual PCI DSS compliance validation requirement by certifying adherence to specified security standards. + +Halyard Pay, as an acquirer, must ensure that Level 1 and Level 2 Merchants utilize the Mastercard PCI DSS Risk-based Approach or participate in the PCI DSS Compliance Validation Exemption Program where applicable. This includes verifying that Merchants: + +- Maintain segregation between Card-not-present and face-to-face transaction environments. +- Meet regional thresholds for transactions processed via Hybrid POS Terminals or implement approved P2PE or tokenization solutions. +- Have not experienced an Account Data Compromise (ADC) Event within the past three years, or have otherwise met exemptions. +- Establish and annually test an ADC Event incident response plan. + +Acquirers must collect and retain written certifications from Merchants confirming eligibility for the Exemption Program and provide supporting documentation upon Mastercard's request. These certifications should be retained for a minimum of five years. + +Ongoing compliance with PCI DSS remains mandatory for all Merchants, regardless of exemption status. + +Source authority: Mastercard SPME §§2.1, 2.2.4, 11.2.6.