Mastercard SPME §2.2.5 · May 2023 → Sep 2023

SDP Program Noncompliance Assessments

substantive

The updated section adds detailed requirements for compromised entities to complete a Site Data Protection Account Data Compromise Information Form within 30 days, and sets specific PCI DSS compliance deadlines with required evidence submission to Mastercard by email. It specifies different deadlines and evidence types based on entity classification (Service Provider, Level 1/2 Merchants, Level 3/4 Merchants).

Sources Mastercard SPME · May 2023 · page 28 PDF Mastercard SPME · Sep 2023 · page 27 PDF KYB Acquirer current
Also in §2.x this release substantive §2 Cleared, meaning the Acquirer transferred the Transaction Data within the substantive §2.1.1 Payment Card Industry (PCI) Security Standards substantive §2.2 Mastercard Site Data Protection (SDP) Program substantive §2.2.2 Merchant Compliance Requirements substantive §2.2.4 Mastercard Cybersecurity Incentive Program (CSIP) substantive §2.2.6 Mandatory Compliance Requirements for Compromised Entities substantive §2.3 Card Production Security Standards substantive §2.4.1 PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
Why these edits? The updated requirements for compromised entities to submit PCI DSS compliance evidence and Site Data Protection Account Data Compromise Information Forms involve specific obligations for Acquirers to ensure compliance and timely submission of these forms and evidence, aligning with KYB (Know Your Business) obligations for Acquirers.
Mastercard SPME §2.2.5
This section was substantively restructured between versions (6% text overlap). Compare the texts directly below.
Before · May 2023 · page 28

Security Rules and Procedures—Merchant Edition • 7 February 2023

SDP Compliant Registered Service Provider List; or termination of the Issuer or Acquirer as a Customer as provided in Rule 2.1.2 of the Mastercard Rules manual. Late SDP Acquirer Submission and Compliance Status Forms for semi-annual merchant compliance reporting submissions or failure to submit the required form(s) may result in an additional assessment to the Customer as described for Category A violations in Rule 2.1.4 of the Mastercard Rules manual.

After · Sep 2023 · page 27

Security Rules and Procedures—Merchant Edition • 1 August 2023

At the conclusion of the forensic investigation, Mastercard will provide a Mastercard Site Data Protection (SDP) Account Data Compromise Information Form for completion by the compromised entity itself, if the compromised entity is a Service Provider, or by its Acquirer, if the compromised entity is a Merchant. The form must be returned by email message to pci_adc@mastercard.com within 30 calendar days of its receipt, and must include:

  • The names of the forensic investigator, QSA and the Approved Scanning Vendor (ASV);
  • The entity’s current level of compliance; and
  • A gap analysis providing detailed steps required for the entity to achieve full compliance. PCI DSS Compliance As soon as practical, but no later than the PCI DSS compliance deadline shown in Table 2.3, the compromised entity or its Acquirer must provide evidence of compliance to Mastercard that the compromised entity has achieved full compliance with the PCI DSS. Table 2.3 PCI DSS Compliance Deadlines and Evidence of Compliance for Compromised Entities Classification PCI DSS Compliance deadline from the Conclusion of the Forensic Investigation Evidence of Compliance Service Providers 90 calendar days Both of the following:
  • PCI DSS ROC AOC conducted by a PCI SSC-approved QSA; and
  • DESV Supplemental ROC (S- ROC) AOC conducted by a PCI SSC-approved QSA within twelve (12) months from achieving full compliance with the PCI DSS Level 1 or Level 2 Merchants 180 calendar days PCI DSS ROC AOC conducted by a PCI SSC-approved QSA Level 3 or Level 4 Merchants 180 calendar days Either of the following:
  • PCI DSS ROC AOC conducted by a PCI SSC-approved QSA; or
  • PCI DSS SAQ AOC Evidence of compliance for compromised entities must be submitted to Mastercard by email message to pci_adc@mastercard.com no later than the PCI DSS compliance deadline shown in Table 2.3. Cybersecurity Standards and Programs
Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME 2.1, 11.2.6
+ authority: Mastercard SPME 2.1, 11.2.6, 2.2.5
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
# The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
- # This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.
+ # Following updates in Mastercard SPME 2.2.5, Acquirers are also required to ensure submission of a Site Data Protection Account Data Compromise Information Form after a forensic investigation relating to a compromised entity, along with evidence of PCI DSS compliance within specified timeframes.
+ # These obligations support KYB program integrity by reinforcing Acquirer accountability for managing compromised Merchants and Service Providers in compliance with Mastercard expectations.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

7. In the event of a data compromise involving a merchant or service provider, ensure timely completion and submission of the Mastercard Site Data Protection (SDP) Account Data Compromise Information Form to Mastercard within 30 calendar days.

8. Oversee that compromised entities achieve and provide evidence of full PCI DSS compliance within specified deadlines based on entity classification, as outlined by Mastercard, forwarding such evidence to Mastercard accordingly.

Source authority: Mastercard SPME ��������2.1, §§2.1, 2.2.5, 11.2.6.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

7. In the event of a data compromise involving a merchant or service provider, ensure timely completion and submission of the Mastercard Site Data Protection (SDP) Account Data Compromise Information Form to Mastercard within 30 calendar days.

8. Oversee that compromised entities achieve and provide evidence of full PCI DSS compliance within specified deadlines based on entity classification, as outlined by Mastercard, forwarding such evidence to Mastercard accordingly.

Source authority: Mastercard SPME ��������2.1, §§2.1, 2.2.5, 11.2.6.

Source authority: Mastercard SPME §2.2.5.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME 2.1, 11.2.6
+authority: Mastercard SPME 2.1, 11.2.6, 2.2.5
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -13,4 +13,5 @@
   - eu_consolidated
 agent_owner: kyb_agent
 # The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
-# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+# Following updates in Mastercard SPME 2.2.5, Acquirers are also required to ensure submission of a Site Data Protection Account Data Compromise Information Form after a forensic investigation relating to a compromised entity, along with evidence of PCI DSS compliance within specified timeframes.
+# These obligations support KYB program integrity by reinforcing Acquirer accountability for managing compromised Merchants and Service Providers in compliance with Mastercard expectations.

--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -20,5 +20,7 @@
 4. Schedule a full re-verification review at least once every 365 days.
 5. Document all verification outcomes and retain records for audit purposes.
 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
+7. In the event of a data compromise involving a merchant or service provider, ensure timely completion and submission of the Mastercard Site Data Protection (SDP) Account Data Compromise Information Form to Mastercard within 30 calendar days.
+8. Oversee that compromised entities achieve and provide evidence of full PCI DSS compliance within specified deadlines based on entity classification, as outlined by Mastercard, forwarding such evidence to Mastercard accordingly.
 
-Source authority: Mastercard SPME 2.1, 11.2.6.+Source authority: Mastercard SPME §§2.1, 2.2.5, 11.2.6.