Mastercard SPME §2.2.3 · Sep 2023 → Feb 2024

Service Provider Compliance Requirements

substantive

The update removes the transaction volume condition from the definition of Level 1 Service Providers, clarifying that certain service provider types are Level 1 regardless of volume. This change alters the scope of who qualifies as a Level 1 Service Provider, impacting validation requirements.

Sources Mastercard SPME · Sep 2023 · page 23 PDF Mastercard SPME · Feb 2024 · page 22 PDF KYB Acquirer current
Also in §2.x this release breaking §2.1.1 Payment Card Industry (PCI) Security Standards substantive §2.2.1 Customer Compliance Requirements substantive §2.2.5 SDP Program Noncompliance Assessments
Why these edits? The change clarifies that certain service provider types are considered Level 1 regardless of transaction volume, impacting the scope of validation requirements that acquirers must apply under the Mastercard Rules, as cited in section 2.1.
Mastercard SPME §2.2.3
This section describes Level 1 and Level 2 Service Provider criteria, and how a Service Provider may successfully validate compliance with the PCI DSS and all other applicable PCI Security Standards and apply cybersecurity best practices. Mastercard recommends that each Level 1 and Level 2 Service Provider demonstrates to Mastercard its compliance with the Designated Entities Supplemental Validation (DESV) appendix of the PCI DSS. All Level 1 and Level 2 Service Providers that use any third party-provided payment applications or payment software must validate that each payment application or payment software used is listed on the PCI SSC website at www.pcisecuritystandards.org as compliant with either the PCI PA-DSS DSS or the PCI Secure Software Standard, as applicable. Mastercard recommends that Service Providers using third party-provided payment software ensure the payment software vendor complies with the PCI Secure SLC Standard. Cybersecurity Standards and Programs ¶ Level 3 Merchants ¶ Security Rules and Procedures—Merchant Edition • 1 August 2023 ¶ Compliance with the PCI 3DS Core Security Standard is required for any Service Provider that performs or provides 3DS functions as defined in the EMV 3-D Secure Protocol and Core Functions Specification. All Service Providers that use any 3DS SDK must validate that each 3DS SDK used is listed on the PCI SSC website at www.pcisecuritystandards.org as compliant with the PCI 3DS SDK Security Standard, as applicable. Level 1 Service Providers A Level 1 Service Provider is any TPP, MPG, SDWO, DASP, TSP, AML/Sanctions Service Provider, 3-DSSP, or ISP (regardless of volume); and any DSE or PF that stores, transmits, or processes more than 300,000 total combined Mastercard and Maestro Transactions annually. Cybersecurity Standards and Programs Level 4 Merchants Security Rules and Procedures—Merchant Edition • 6 February 2024 Each Level 1 Service Provider must validate compliance with the PCI DSS, and each 3-DSSP must validate compliance with the PCI 3DS Core Security Standard by successfully undergoing an annual PCI assessment resulting in the completion of a ROC conducted by an appropriate PCI SSC-approved QSA. Level 2 Service Providers A Level 2 Service Provider is any DSE or PF that is not deemed a Level 1 Service Provider and that stores, transmits, or processes 300,000 or less total combined Mastercard and Maestro Transactions annually; and any TS. Each Level 2 Service Provider must validate compliance with the PCI DSS by successfully completing an annual SAQ. As an alternative to validating compliance with the PCI DSS, a DSE qualifying as a Level 2 Service Provider may submit a PCI PIN Security Requirements Attestation of Compliance for Onsite Assessments from a PCI SSC-approved Qualified PIN Assessor (QPA) every two years to the Mastercard SDP Department, provided that the DSE does not perform services involving the storage, transmission, or processing of Account, Cardholder, or Transaction Data. As an alternative to validating compliance with the PCI DSS, a TS may submit a completed Terminal Servicer QIR Participation Validation Form to the Mastercard SDP Department, provided that the TS does not perform services involving the storage, transmission, or processing of Account, Cardholder, or Transaction Data, but the TS has access to such Data within the Cardholder Data Environment (CDE) (as the term is defined by the PCI SSC). The Terminal Servicer QIR Participation Validation Form is available on the Service Provider page of the SDP Program website. NOTE: Service Provider classifications (TPPs, DSEs, PFs, SDWOs, DASPs, TSPs, TSs, AML/Sanctions Service Providers, 3-DSSPs, ISPs, and MPGs) are determined by Mastercard. Service Provider registrations with Mastercard will not be deemed complete until the Service Provider’s compliance with the SDP Program is validated. Refer to Chapter 7 of the Mastercard Rules manual for additional Service Provider registration requirements.
Halyard Pay · 2 files
program: Acquirer KYB
authority: Mastercard SPME 2.1, 11.2.3, 11.2.6
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
# Failure to adhere to these requirements may result in noncompliance assessments.
# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
+ # Under Mastercard SPME §2.1, Level 1 Service Provider status includes certain types of service providers regardless of transaction volume, such as TPPs, MPGs, SDWOs, DASPs, TSPs, AML/Sanctions Service Providers, 3-DSSPs, and ISPs, while Level 2 Service Providers comprise others with transaction volumes at or below thresholds, influencing compliance validation requirements.
+ # Acquirers must ensure Level 1 Service Providers complete an annual PCI DSS assessment including ROC by a PCI SSC-approved QSA; Level 2 Service Providers must complete an annual PCI DSS Self-Assessment Questionnaire (SAQ) or approved alternatives, consistent with their classification.
+ # This clarification impacts acquirers’ risk management related to validating service provider compliance with cybersecurity standards as required by Mastercard rules.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

  7. Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.

## Compliance with Service Provider Levels

Halyard Pay recognizes that Mastercard has updated its classification of Service Providers. Specifically, certain types of providers (e.g., Third Party Processors, Managed Payment Gateways, and others) are classified as Level 1 Service Providers regardless of transaction volume. As such, these entities must validate compliance with PCI DSS annually through a Report on Compliance (ROC) completed by a Qualified Security Assessor (QSA).

Other Service Providers categorized as Level 2 must validate PCI DSS compliance annually via a Self-Assessment Questionnaire (SAQ) or approved alternatives such as a Qualified PIN Assessor attestation or Terminal Servicer QIR validation, depending on their functions and access to cardholder data.

These classifications impact the scope of PCI compliance validations that Halyard Pay requires from its Service Providers and acquirer partners.

Source authority: Mastercard SPME §§2.1, 2.2.3, 7.1, 11.2.3, 11.2.6.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

  7. Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.

## Compliance with Service Provider Levels

Halyard Pay recognizes that Mastercard has updated its classification of Service Providers. Specifically, certain types of providers (e.g., Third Party Processors, Managed Payment Gateways, and others) are classified as Level 1 Service Providers regardless of transaction volume. As such, these entities must validate compliance with PCI DSS annually through a Report on Compliance (ROC) completed by a Qualified Security Assessor (QSA).

Other Service Providers categorized as Level 2 must validate PCI DSS compliance annually via a Self-Assessment Questionnaire (SAQ) or approved alternatives such as a Qualified PIN Assessor attestation or Terminal Servicer QIR validation, depending on their functions and access to cardholder data.

These classifications impact the scope of PCI compliance validations that Halyard Pay requires from its Service Providers and acquirer partners.

Source authority: Mastercard SPME §§2.1, 2.2.3, 7.1, 11.2.3, 11.2.6.

Source authority: Mastercard SPME §2.2.3.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -15,3 +15,6 @@
 # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
 # Failure to adhere to these requirements may result in noncompliance assessments.
 # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
+# Under Mastercard SPME §2.1, Level 1 Service Provider status includes certain types of service providers regardless of transaction volume, such as TPPs, MPGs, SDWOs, DASPs, TSPs, AML/Sanctions Service Providers, 3-DSSPs, and ISPs, while Level 2 Service Providers comprise others with transaction volumes at or below thresholds, influencing compliance validation requirements.
+# Acquirers must ensure Level 1 Service Providers complete an annual PCI DSS assessment including ROC by a PCI SSC-approved QSA; Level 2 Service Providers must complete an annual PCI DSS Self-Assessment Questionnaire (SAQ) or approved alternatives, consistent with their classification.
+# This clarification impacts acquirers’ risk management related to validating service provider compliance with cybersecurity standards as required by Mastercard rules.
--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -22,4 +22,12 @@
 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
 7. Before entering into a Merchant Agreement or enabling a Merchant to accept transactions, Halyard Pay must conduct a MATCH inquiry using the proper Member ID/ICA Number assigned to Halyard Pay to ensure compliance. Failure to perform this check or to use the correct Member ID/ICA may result in noncompliance and assessments by Mastercard.
 
-Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6.+## Compliance with Service Provider Levels
+
+Halyard Pay recognizes that Mastercard has updated its classification of Service Providers. Specifically, certain types of providers (e.g., Third Party Processors, Managed Payment Gateways, and others) are classified as Level 1 Service Providers regardless of transaction volume. As such, these entities must validate compliance with PCI DSS annually through a Report on Compliance (ROC) completed by a Qualified Security Assessor (QSA).
+
+Other Service Providers categorized as Level 2 must validate PCI DSS compliance annually via a Self-Assessment Questionnaire (SAQ) or approved alternatives such as a Qualified PIN Assessor attestation or Terminal Servicer QIR validation, depending on their functions and access to cardholder data.
+
+These classifications impact the scope of PCI compliance validations that Halyard Pay requires from its Service Providers and acquirer partners.
+
+Source authority: Mastercard SPME §§2.1, 2.2.3, 7.1, 11.2.3, 11.2.6.