Mastercard SPME §2.2.5 · May 2023 → Sep 2023
SDP Program Noncompliance Assessments
The updated section adds detailed requirements for compromised entities to complete a Site Data Protection Account Data Compromise Information Form within 30 days, and sets specific PCI DSS compliance deadlines with required evidence submission to Mastercard by email. It specifies different deadlines and evidence types based on entity classification (Service Provider, Level 1/2 Merchants, Level 3/4 Merchants).
Security Rules and Procedures—Merchant Edition • 7 February 2023
SDP Compliant Registered Service Provider List; or termination of the Issuer or Acquirer as a Customer as provided in Rule 2.1.2 of the Mastercard Rules manual. Late SDP Acquirer Submission and Compliance Status Forms for semi-annual merchant compliance reporting submissions or failure to submit the required form(s) may result in an additional assessment to the Customer as described for Category A violations in Rule 2.1.4 of the Mastercard Rules manual.
Security Rules and Procedures—Merchant Edition • 1 August 2023
At the conclusion of the forensic investigation, Mastercard will provide a Mastercard Site Data Protection (SDP) Account Data Compromise Information Form for completion by the compromised entity itself, if the compromised entity is a Service Provider, or by its Acquirer, if the compromised entity is a Merchant. The form must be returned by email message to pci_adc@mastercard.com within 30 calendar days of its receipt, and must include:
- The names of the forensic investigator, QSA and the Approved Scanning Vendor (ASV);
- The entity’s current level of compliance; and
- A gap analysis providing detailed steps required for the entity to achieve full compliance. PCI DSS Compliance As soon as practical, but no later than the PCI DSS compliance deadline shown in Table 2.3, the compromised entity or its Acquirer must provide evidence of compliance to Mastercard that the compromised entity has achieved full compliance with the PCI DSS. Table 2.3 PCI DSS Compliance Deadlines and Evidence of Compliance for Compromised Entities Classification PCI DSS Compliance deadline from the Conclusion of the Forensic Investigation Evidence of Compliance Service Providers 90 calendar days Both of the following:
- PCI DSS ROC AOC conducted by a PCI SSC-approved QSA; and
- DESV Supplemental ROC (S- ROC) AOC conducted by a PCI SSC-approved QSA within twelve (12) months from achieving full compliance with the PCI DSS Level 1 or Level 2 Merchants 180 calendar days PCI DSS ROC AOC conducted by a PCI SSC-approved QSA Level 3 or Level 4 Merchants 180 calendar days Either of the following:
- PCI DSS ROC AOC conducted by a PCI SSC-approved QSA; or
- PCI DSS SAQ AOC Evidence of compliance for compromised entities must be submitted to Mastercard by email message to pci_adc@mastercard.com no later than the PCI DSS compliance deadline shown in Table 2.3. Cybersecurity Standards and Programs
program: Acquirer KYB- authority: Mastercard SPME 2.1, 11.2.6+ authority: Mastercard SPME 2.1, 11.2.6, 2.2.5required_documents:- incorporation- beneficial_ownership- aml_screen- license_verificationmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent# The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.- # This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+ # Following updates in Mastercard SPME 2.2.5, Acquirers are also required to ensure submission of a Site Data Protection Account Data Compromise Information Form after a forensic investigation relating to a compromised entity, along with evidence of PCI DSS compliance within specified timeframes.+ # These obligations support KYB program integrity by reinforcing Acquirer accountability for managing compromised Merchants and Service Providers in compliance with Mastercard expectations.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
7. In the event of a data compromise involving a merchant or service provider, ensure timely completion and submission of the Mastercard Site Data Protection (SDP) Account Data Compromise Information Form to Mastercard within 30 calendar days.
8. Oversee that compromised entities achieve and provide evidence of full PCI DSS compliance within specified deadlines based on entity classification, as outlined by Mastercard, forwarding such evidence to Mastercard accordingly.
Source authority: Mastercard SPME ��������2.1, §§2.1, 2.2.5, 11.2.6.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform
Know Your Business (KYB) due diligence on merchants before onboarding and on a
recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a
minimum set of documents for each merchant to establish business legitimacy, confirm
beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification
reviews. Merchants that fail to supply required documentation within the stipulated
period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
7. In the event of a data compromise involving a merchant or service provider, ensure timely completion and submission of the Mastercard Site Data Protection (SDP) Account Data Compromise Information Form to Mastercard within 30 calendar days.
8. Oversee that compromised entities achieve and provide evidence of full PCI DSS compliance within specified deadlines based on entity classification, as outlined by Mastercard, forwarding such evidence to Mastercard accordingly.
Source authority: Mastercard SPME ��������2.1, §§2.1, 2.2.5, 11.2.6.
Source authority: Mastercard SPME §2.2.5.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -1,5 +1,5 @@ program: Acquirer KYB -authority: Mastercard SPME 2.1, 11.2.6 +authority: Mastercard SPME 2.1, 11.2.6, 2.2.5 required_documents: - incorporation - beneficial_ownership @@ -13,4 +13,5 @@ - eu_consolidated agent_owner: kyb_agent # The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6. -# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+# Following updates in Mastercard SPME 2.2.5, Acquirers are also required to ensure submission of a Site Data Protection Account Data Compromise Information Form after a forensic investigation relating to a compromised entity, along with evidence of PCI DSS compliance within specified timeframes. +# These obligations support KYB program integrity by reinforcing Acquirer accountability for managing compromised Merchants and Service Providers in compliance with Mastercard expectations. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -20,5 +20,7 @@ 4. Schedule a full re-verification review at least once every 365 days. 5. Document all verification outcomes and retain records for audit purposes. 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements. +7. In the event of a data compromise involving a merchant or service provider, ensure timely completion and submission of the Mastercard Site Data Protection (SDP) Account Data Compromise Information Form to Mastercard within 30 calendar days. +8. Oversee that compromised entities achieve and provide evidence of full PCI DSS compliance within specified deadlines based on entity classification, as outlined by Mastercard, forwarding such evidence to Mastercard accordingly. -Source authority: Mastercard SPME 2.1, 11.2.6.+Source authority: Mastercard SPME §§2.1, 2.2.5, 11.2.6.