Mastercard SPME §2.2 · May 2023 → Sep 2023
Mastercard Site Data Protection (SDP) Program
The update defines detailed compliance and reporting responsibilities for Issuers and Acquirers concerning Level 1-4 Merchants and Service Providers under the Mastercard SDP Program, specifying submission deadlines, validation methods like PCI DSS and SAQs, risk management requirements for Acquirers, and potential cost reductions after Account Data Compromise Events.
Security Rules and Procedures—Merchant Edition • 7 February 2023
compliance with the PCI Security Standards. The SDP Program is designed to help Customers, Merchants, and Service Providers (Third Party Processors [TPPs], Data Storage Entities [DSEs], Payment Facilitators [PFs], Staged Digital Wallet Operators [SDWOs], Digital Activity Service Providers [DASPs], Token Service Providers [TSPs], Terminal Servicers [TSs], AML/Sanctions Service Providers, 3-D Secure Service Providers [3-DSSPs], Installment Service Providers [ISPs]), and Merchant Payment Gateways [MPGs]) protect against Account Data Compromise (ADC) Events. NOTE: For the purposes of the SDP Program, TPPs, DSEs, PFs, SDWOs, DASPs, TSPs, TSs, AML/Sanctions Service Providers, 3-DSSPs, ISPs, and MPGs are collectively referred to as “Service Providers” in this chapter. Refer to section 10.1 of this manual for the definitions of an Account Data Compromise Event and a Potential Account Data Compromise Event. Compliance with the Payment Card Industry Data Security Standard (PCI DSS) and all other applicable PCI Security Standards is required for all Issuers, Acquirers, Merchants, Service Providers, and any other person or entity that a Customer permits, directly or indirectly, to store, transmit, or process Account Data. Only Merchants and Service Providers must validate their compliance to Mastercard, as set forth in sections 2.2.2 and 2.2.3 respectively, in order to be deemed compliant with the Mastercard SDP Program. Mastercard has sole discretion to interpret and enforce the SDP Program Standards.
Security Rules and Procedures—Merchant Edition • 1 August 2023
To ensure compliance with the Mastercard SDP Program, an Issuer must:
- Communicate the SDP Program requirements to each Level 1 and Level 2 Service Provider, and validate the Service Provider’s compliance with the PCI DSS and any other applicable PCI Security Standard by reviewing the Payment Card Industry Self-Assessment Questionnaire (SAQ) or the Report on Compliance (ROC).
- Submit the annual PCI compliance validation (the PCI Attestation of Compliance [AOC]) for each Level 1 and Level 2 Service Provider by email message to pcireports@mastercard.com, after initial registration with Mastercard and every year thereafter. If a newly registered Service Provider is not yet compliant, the PCI Action Plan available on the Service Provider page of the SDP Program website must be completed and submitted for review. To ensure compliance with the Mastercard SDP Program, an Acquirer must:
- Communicate the SDP Program requirements to each Level 1, Level 2, and Level 3 Merchant, and validate the Merchant’s compliance with the PCI DSS by reviewing the Payment Card Industry Self-Assessment Questionnaire or the ROC.
- Submit the SDP Acquirer Submission and Compliance Status Form available on the Acquirer page of the SDP Program website, for each Level 1, Level 2, and Level 3 Merchant semi- annually by email message to sdp@mastercard.com. For this reporting period… Submit the form(s) no later than… 1 October to 31 March 31 March 1 April to 30 September 30 September
- Validate to Mastercard that the Acquirer has a risk management program in place to identify and manage payment security risk within the Acquirer’s Level 4 Merchant portfolio.
- Communicate the SDP Program requirements to each Level 1 and Level 2 Service Provider, and validate the Service Provider’s compliance with the PCI DSS and any other applicable PCI Security Standard by reviewing the Payment Card Industry Self-assessment Questionnaire and the ROC.
- Submit annual PCI validation (the PCI Attestation of Compliance [AOC]) for each Level 1 and Level 2 Service Provider by email message to pcireports@mastercard.com after initial registration with Mastercard and every year thereafter. If a newly registered Service Provider is not yet compliant, the PCI Action Plan available on the Service Provider page of the SDP Program website must be completed and submitted for review. A Customer that complies with the SDP Program requirements may qualify for a reduction, partial or total, of certain costs or assessments if the Customer is impacted by an ADC Event, whether caused by the Customer itself, a Merchant, or a Service Provider.
program: Acquirer KYB- authority: Mastercard SPME 2.1, 11.2.6+ authority: Mastercard SPME 2.1, 2.2, 11.2.6required_documents:- incorporation- beneficial_ownership- aml_screen- license_verification+ - pci_compliance_validationmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent++ # Acquirers must ensure that all Level 1, Level 2, and Level 3 Merchants under their portfolio comply with PCI DSS requirements by validating PCI compliance documentation such as the SAQ or ROC semi-annually.+ # Acquirers are also required to submit the SDP Acquirer Submission and Compliance Status Form to Mastercard biannually to demonstrate ongoing oversight of merchant security programs.+ # Additionally, Acquirers must implement risk management programs to identify and manage security risks for Level 4 Merchants, ensuring coverage of the entire merchant risk profile.+ # These program requirements enhance the existing KYB obligations to include specific compliance and reporting related to the Mastercard SDP Program, reflecting the updated SPME §2.2 standards.+# The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform ¶ Know Your Business (KYB) due diligence on merchants before onboarding and on a ¶ recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a ¶ minimum set of documents for each merchant to establish business legitimacy, confirm ¶ beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification ¶ reviews. Merchants that fail to supply required documentation within the stipulated ¶ period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
7. As part of compliance with Mastercard's Security Dispersion Program (SDP), ensure validation of PCI DSS compliance from Level 1, 2, and 3 Merchants by reviewing their Self-Assessment Questionnaires or Reports on Compliance.
8. Submit the SDP Acquirer Submission and Compliance Status Form semi-annually to Mastercard for all Level 1-3 Merchants.
9. Maintain and demonstrate a risk management program to monitor payment security risk within the Level 4 Merchant portfolio.
10. Communicate SDP Program compliance requirements and collect PCI validation from Level 1 and 2 Service Providers, submitting annual PCI Attestations of Compliance to Mastercard.
Source authority: Mastercard SPME ��������2.1, §§2.1, 2.2, 11.2.6.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network are required to perform ¶ Know Your Business (KYB) due diligence on merchants before onboarding and on a ¶ recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a ¶ minimum set of documents for each merchant to establish business legitimacy, confirm ¶ beneficial ownership, and satisfy anti-money laundering screening requirements.
When this policy applies
This policy applies to all new merchant onboarding and to all periodic re-verification ¶ reviews. Merchants that fail to supply required documentation within the stipulated ¶ period must be suspended from processing until compliance is restored.
Required actions
-
Collect all required KYB documents at onboarding prior to approval.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule a full re-verification review at least once every 365 days.
-
Document all verification outcomes and retain records for audit purposes.
-
Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
7. As part of compliance with Mastercard's Security Dispersion Program (SDP), ensure validation of PCI DSS compliance from Level 1, 2, and 3 Merchants by reviewing their Self-Assessment Questionnaires or Reports on Compliance.
8. Submit the SDP Acquirer Submission and Compliance Status Form semi-annually to Mastercard for all Level 1-3 Merchants.
9. Maintain and demonstrate a risk management program to monitor payment security risk within the Level 4 Merchant portfolio.
10. Communicate SDP Program compliance requirements and collect PCI validation from Level 1 and 2 Service Providers, submitting annual PCI Attestations of Compliance to Mastercard.
Source authority: Mastercard SPME ��������2.1, §§2.1, 2.2, 11.2.6.
Source authority: Mastercard SPME §2.2.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -1,10 +1,11 @@ program: Acquirer KYB -authority: Mastercard SPME 2.1, 11.2.6 +authority: Mastercard SPME 2.1, 2.2, 11.2.6 required_documents: - incorporation - beneficial_ownership - aml_screen - license_verification + - pci_compliance_validation min_review_cycle_days: 365 suspension_trigger: document_collection_failure record_retention_years: 7 @@ -12,5 +13,11 @@ - ofac_sdn - eu_consolidated agent_owner: kyb_agent + +# Acquirers must ensure that all Level 1, Level 2, and Level 3 Merchants under their portfolio comply with PCI DSS requirements by validating PCI compliance documentation such as the SAQ or ROC semi-annually. +# Acquirers are also required to submit the SDP Acquirer Submission and Compliance Status Form to Mastercard biannually to demonstrate ongoing oversight of merchant security programs. +# Additionally, Acquirers must implement risk management programs to identify and manage security risks for Level 4 Merchants, ensuring coverage of the entire merchant risk profile. +# These program requirements enhance the existing KYB obligations to include specific compliance and reporting related to the Mastercard SDP Program, reflecting the updated SPME §2.2 standards. + # The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6. -# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -1,16 +1,10 @@ # Acquirer KYB (Know Your Business) Obligations -Acquirers processing transactions on the Mastercard network are required to perform -Know Your Business (KYB) due diligence on merchants before onboarding and on a -recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a -minimum set of documents for each merchant to establish business legitimacy, confirm -beneficial ownership, and satisfy anti-money laundering screening requirements. +Acquirers processing transactions on the Mastercard network are required to perform Know Your Business (KYB) due diligence on merchants before onboarding and on a recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a minimum set of documents for each merchant to establish business legitimacy, confirm beneficial ownership, and satisfy anti-money laundering screening requirements. ## When this policy applies -This policy applies to all new merchant onboarding and to all periodic re-verification -reviews. Merchants that fail to supply required documentation within the stipulated -period must be suspended from processing until compliance is restored. +This policy applies to all new merchant onboarding and to all periodic re-verification reviews. Merchants that fail to supply required documentation within the stipulated period must be suspended from processing until compliance is restored. ## Required actions @@ -20,5 +14,9 @@ 4. Schedule a full re-verification review at least once every 365 days. 5. Document all verification outcomes and retain records for audit purposes. 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements. +7. As part of compliance with Mastercard's Security Dispersion Program (SDP), ensure validation of PCI DSS compliance from Level 1, 2, and 3 Merchants by reviewing their Self-Assessment Questionnaires or Reports on Compliance. +8. Submit the SDP Acquirer Submission and Compliance Status Form semi-annually to Mastercard for all Level 1-3 Merchants. +9. Maintain and demonstrate a risk management program to monitor payment security risk within the Level 4 Merchant portfolio. +10. Communicate SDP Program compliance requirements and collect PCI validation from Level 1 and 2 Service Providers, submitting annual PCI Attestations of Compliance to Mastercard. -Source authority: Mastercard SPME 2.1, 11.2.6.+Source authority: Mastercard SPME §§2.1, 2.2, 11.2.6.