Mastercard SPME §2.2.6 · May 2023 → Sep 2023
Mandatory Compliance Requirements for Compromised Entities
The update adds that merchants with a confirmed Account Data Compromise (ADC) event may be reclassified as Level 1 and must follow related compliance and noncompliance rules. It clarifies noncompliance consequences for Service Providers, including reclassification and delisting, and states that extension requests for PCI DSS deadlines will not be approved.
Security Rules and Procedures—Merchant Edition • 7 February 2023
forensic investigation will be automatically reclassified to become a Level 1 Service Provider. In addition, a Service Provider’s noncompliance will result in the automatic delisting from The Mastercard SDP Compliant Registered Service Provider List. A registered Service Provider may be placed back on the list only after the entity has re- validated compliance with the PCI DSS and has additionally demonstrated compliance with the DESV appendix of the PCI DSS within twelve (12) months from achieving full compliance with the PCI DSS as shown in Table 2.3.
Security Rules and Procedures—Merchant Edition • 1 August 2023
Failure to comply with these requirements may result in SDP noncompliance assessments as described in section 2.2.5. Extension requests for compromised entities that do not meet the PCI DSS compliance deadline shown in Table 2.3 will not be approved by Mastercard. Merchants Any Merchant that has a confirmed ADC Event may be automatically reclassified to become a Level 1 Merchant. All compliance validation requirements and associated SDP noncompliance assessments for Level 1 Merchants will apply. Service Providers Any Service Provider that has a confirmed ADC Event, adverse inference (see section 10.3), and/or noncompliance for failure to cooperate in an ADC Event or forensic investigation will be automatically reclassified to become a Level 1 Service Provider. In addition, a Service Provider’s noncompliance will result in the automatic delisting from The Mastercard SDP Compliant Registered Service Provider List. A registered Service Provider may be placed back on the list only after the entity has re-validated compliance with the PCI DSS and has additionally demonstrated compliance with the DESV appendix of the PCI DSS within twelve (12) months from achieving full compliance with the PCI DSS as shown in Table 2.3.
program: ATO Detection- authority: Mastercard SPME §10.6.2.1+ authority: Mastercard SPME 710.6.2.1, 72.2.6risk_threshold_for_3ds_challenge: 0.5risk_score_range: [0.0, 1.0]signals:- geo_anomaly- device_fingerprint_change- velocity_breach- credential_stuffingchallenge_method: 3ds_v2persistent_risk_escalation_threshold: 3persistent_risk_lookback_days: 7agent_owner: ato_agent- # This policy incorporates the updated Mastercard SPME §10.6.2.1 requirements,- # including extended timelines for Terminal Servicer compliance revalidation- # after an Account Data Compromise Event, emphasizing a 90-day PCI DSS- # revalidation period and an added 12-month DESV appendix compliance.- # It reinforces timely and comprehensive security procedures to mitigate- # Account Takeover risk in line with Mastercard's updated security standards.+ # This policy incorporates the Mastercard SPME updates to section 2.2.6,+ # which now include explicit provisions for reclassifying Merchants with+ # confirmed Account Data Compromise (ADC) Events as Level 1 Merchants.+ # These merchants must comply with Level 1 validation and noncompliance+ # assessments, reinforcing detection and risk management for Account+ # Takeover incidents. The policy also retains requirements for Service+ # Providers, including PCI DSS and DESV compliance timelines following ADC.+ #+ # These revisions align ATO risk mitigation measures with Mastercard's enhanced+ # SDP reclassification and compliance enforcement framework, ensuring prompt+ # risk escalation and comprehensive coverage for both Merchants and Service Providers.
Account-Takeover (ATO) Detection
Account-takeover fraud occurs when a malicious actor gains unauthorized access to
a cardholder's account and initiates transactions without the cardholder's consent.
Halyard Pay implements real-time risk scoring on authentication events and enforces a
mandatory 3DS (3-D Secure) challenge for any session where the computed risk score
meets or exceeds the defined threshold.
Detection signals
The risk model incorporates multiple behavioral signals: geographic anomalies
inconsistent with a cardholder's established pattern, changes to device fingerprint,
transaction velocity breaches, and indicators of credential-stuffing activity.
Required actions
-
Evaluate each authentication event against the defined signal list in real time.
-
Compute a normalized risk score between 0.0 and 1.0.
-
If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before
authorizing the transaction.
-
Log all ATO signals and outcomes in the case management system.
-
Escalate persistent high-risk accounts to the ATO response team for manual review.
-
In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer
involved revalidates PCI DSS compliance within 90 calendar days after the forensic
investigation concludes, and demonstrate compliance with the PCI DSS Data
Encryption and Software Validation (DESV) appendix within 12 months, consistent
with Mastercard requirements (SPME §10.6.2.1).
7. Acknowledge that merchants with confirmed ADC events may be reclassified as Level 1
Merchants and must comply with all associated validation and compliance requirements,
reflecting Mastercard's updated compliance and noncompliance measures (SPME §2.2.6).
Source authority: Mastercard SPME §6.2, §10.6.2.1.§10.6.2.1, §2.2.6.
program: BRAM- authority: Mastercard SPME §8.6.2, §10.2+ authority: Mastercard SPME 2.2.6, 10.2response_window_days: 180required_evidence:- transaction_monitoring_records- corrective_action_plan- - police_report # Added requirement for police report according to updated SPME §8.6.2+ - police_report # Retain police report requirementhalt_actions:- halt_new_merchant_onboardinginternal_notification_hours: 24agent_owner: bram_response_agent- # Updated to reflect the extended discretionary investigation period and mandatory police report inclusion for at least one coercion claim as specified in Mastercard SPME §8.6.2.+ # Updated to include clarified noncompliance consequences for Service Providers with ADC Events, reclassification, and delisting per Mastercard SPME 2.2.6.+ # This affects BRAM investigation response obligations as referenced in section 10.2.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation ¶ notice for one of our merchants, the acquirer must halt new merchant onboarding ¶ immediately and submit an evidence package within one hundred eighty (180) days ¶ of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day ¶ investigation period at its discretion. At least one claim must include a police report from the Cardholder. ¶ Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, ¶ though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the ¶ merchant within the investigation period to prompt claim submissions.
## Compliance Implications for Service Providers and Merchants
A confirmed Account Data Compromise (ADC) Event can trigger mandatory reclassification and escalated compliance obligations. Specifically:
- Any Service Provider experiencing a confirmed ADC Event, adverse inference, or noncooperation in forensic investigations will be reclassified as a Level 1 Service Provider and automatically removed from the Mastercard SDP Compliant Registered Service Provider List. Reinstatement requires revalidation of full PCI DSS compliance including the DESV appendix within twelve (12) months of compliance achievement.
- Similarly, any Merchant with a confirmed ADC Event may be reclassified to Level 1 Merchant status and must comply with all validation and noncompliance requirements for that level.
These measures underscore the critical need for full cooperation and timely remediation in BRAM investigations.
Source authority: Mastercard SPME §8.6.2, §10.2.§10.2, §2.2.6.
Account-Takeover (ATO) Detection
Account-takeover fraud occurs when a malicious actor gains unauthorized access to
a cardholder's account and initiates transactions without the cardholder's consent.
Halyard Pay implements real-time risk scoring on authentication events and enforces a
mandatory 3DS (3-D Secure) challenge for any session where the computed risk score
meets or exceeds the defined threshold.
Detection signals
The risk model incorporates multiple behavioral signals: geographic anomalies
inconsistent with a cardholder's established pattern, changes to device fingerprint,
transaction velocity breaches, and indicators of credential-stuffing activity.
Required actions
-
Evaluate each authentication event against the defined signal list in real time.
-
Compute a normalized risk score between 0.0 and 1.0.
-
If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before
authorizing the transaction.
-
Log all ATO signals and outcomes in the case management system.
-
Escalate persistent high-risk accounts to the ATO response team for manual review.
-
In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer
involved revalidates PCI DSS compliance within 90 calendar days after the forensic
investigation concludes, and demonstrate compliance with the PCI DSS Data
Encryption and Software Validation (DESV) appendix within 12 months, consistent
with Mastercard requirements (SPME §10.6.2.1).
7. Acknowledge that merchants with confirmed ADC events may be reclassified as Level 1
Merchants and must comply with all associated validation and compliance requirements,
reflecting Mastercard's updated compliance and noncompliance measures (SPME §2.2.6).
Source authority: Mastercard SPME §6.2, §10.6.2.1.§10.6.2.1, §2.2.6.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation ¶ notice for one of our merchants, the acquirer must halt new merchant onboarding ¶ immediately and submit an evidence package within one hundred eighty (180) days ¶ of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day ¶ investigation period at its discretion. At least one claim must include a police report from the Cardholder. ¶ Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, ¶ though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the ¶ merchant within the investigation period to prompt claim submissions.
## Compliance Implications for Service Providers and Merchants
A confirmed Account Data Compromise (ADC) Event can trigger mandatory reclassification and escalated compliance obligations. Specifically:
- Any Service Provider experiencing a confirmed ADC Event, adverse inference, or noncooperation in forensic investigations will be reclassified as a Level 1 Service Provider and automatically removed from the Mastercard SDP Compliant Registered Service Provider List. Reinstatement requires revalidation of full PCI DSS compliance including the DESV appendix within twelve (12) months of compliance achievement.
- Similarly, any Merchant with a confirmed ADC Event may be reclassified to Level 1 Merchant status and must comply with all validation and noncompliance requirements for that level.
These measures underscore the critical need for full cooperation and timely remediation in BRAM investigations.
Source authority: Mastercard SPME §8.6.2, §10.2.§10.2, §2.2.6.
Source authority: Mastercard SPME §2.2.6.
--- a/policies/ato_detection/rules.yaml
+++ b/policies/ato_detection/rules.yaml
@@ -1,5 +1,5 @@
program: ATO Detection
-authority: Mastercard SPME §10.6.2.1
+authority: Mastercard SPME 710.6.2.1, 72.2.6
risk_threshold_for_3ds_challenge: 0.5
risk_score_range: [0.0, 1.0]
signals:
@@ -12,9 +12,14 @@
persistent_risk_lookback_days: 7
agent_owner: ato_agent
-# This policy incorporates the updated Mastercard SPME §10.6.2.1 requirements,
-# including extended timelines for Terminal Servicer compliance revalidation
-# after an Account Data Compromise Event, emphasizing a 90-day PCI DSS
-# revalidation period and an added 12-month DESV appendix compliance.
-# It reinforces timely and comprehensive security procedures to mitigate
-# Account Takeover risk in line with Mastercard's updated security standards.+# This policy incorporates the Mastercard SPME updates to section 2.2.6,
+# which now include explicit provisions for reclassifying Merchants with
+# confirmed Account Data Compromise (ADC) Events as Level 1 Merchants.
+# These merchants must comply with Level 1 validation and noncompliance
+# assessments, reinforcing detection and risk management for Account
+# Takeover incidents. The policy also retains requirements for Service
+# Providers, including PCI DSS and DESV compliance timelines following ADC.
+#
+# These revisions align ATO risk mitigation measures with Mastercard's enhanced
+# SDP reclassification and compliance enforcement framework, ensuring prompt
+# risk escalation and comprehensive coverage for both Merchants and Service Providers.
--- a/policies/ato_detection/policy.md
+++ b/policies/ato_detection/policy.md
@@ -25,5 +25,8 @@
investigation concludes, and demonstrate compliance with the PCI DSS Data
Encryption and Software Validation (DESV) appendix within 12 months, consistent
with Mastercard requirements (SPME §10.6.2.1).
+7. Acknowledge that merchants with confirmed ADC events may be reclassified as Level 1
+ Merchants and must comply with all associated validation and compliance requirements,
+ reflecting Mastercard's updated compliance and noncompliance measures (SPME §2.2.6).
-Source authority: Mastercard SPME §6.2, §10.6.2.1.+Source authority: Mastercard SPME §6.2, §10.6.2.1, §2.2.6.
--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -1,13 +1,14 @@
program: BRAM
-authority: Mastercard SPME §8.6.2, §10.2
+authority: Mastercard SPME 2.2.6, 10.2
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- - police_report # Added requirement for police report according to updated SPME §8.6.2
+ - police_report # Retain police report requirement
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
agent_owner: bram_response_agent
-# Updated to reflect the extended discretionary investigation period and mandatory police report inclusion for at least one coercion claim as specified in Mastercard SPME §8.6.2.+# Updated to include clarified noncompliance consequences for Service Providers with ADC Events, reclassification, and delisting per Mastercard SPME 2.2.6.
+# This affects BRAM investigation response obligations as referenced in section 10.2.
--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -1,9 +1,6 @@
# BRAM Investigation Response
-When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
-notice for one of our merchants, the acquirer must halt new merchant onboarding
-immediately and submit an evidence package within one hundred eighty (180) days
-of receipt of the notice.
+When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation notice for one of our merchants, the acquirer must halt new merchant onboarding immediately and submit an evidence package within one hundred eighty (180) days of receipt of the notice.
## Required actions
@@ -16,10 +13,16 @@
## Additional Considerations for Coercion Claims
-When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
-investigation period at its discretion. At least one claim must include a police report from the Cardholder.
-Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
-though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
-merchant within the investigation period to prompt claim submissions.
+When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day investigation period at its discretion. At least one claim must include a police report from the Cardholder. Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions.
-Source authority: Mastercard SPME §8.6.2, §10.2.
+## Compliance Implications for Service Providers and Merchants
+
+A confirmed Account Data Compromise (ADC) Event can trigger mandatory reclassification and escalated compliance obligations. Specifically:
+
+- Any Service Provider experiencing a confirmed ADC Event, adverse inference, or noncooperation in forensic investigations will be reclassified as a Level 1 Service Provider and automatically removed from the Mastercard SDP Compliant Registered Service Provider List. Reinstatement requires revalidation of full PCI DSS compliance including the DESV appendix within twelve (12) months of compliance achievement.
+
+- Similarly, any Merchant with a confirmed ADC Event may be reclassified to Level 1 Merchant status and must comply with all validation and noncompliance requirements for that level.
+
+These measures underscore the critical need for full cooperation and timely remediation in BRAM investigations.
+
+Source authority: Mastercard SPME §8.6.2, §10.2, §2.2.6.