Mastercard SPME §2.2.2 · Feb 2024 → Sep 2024

Merchant Compliance Requirements

substantive

The update adds that Level 1-3 Merchants must validate all third-party payment applications/software against PCI SSC listings. It clarifies that Level 3 and 4 Merchants' PCI DSS compliance validation to Mastercard is not required unless by law, though completing an SAQ or ROC is still encouraged. Other content remains largely unchanged.

Sources Mastercard SPME · Feb 2024 · page 20 PDF Mastercard SPME · Sep 2024 · page 20 PDF KYB Acquirer current
Also in §2.x this release substantive §2.2.3 Service Provider Compliance Requirements substantive §2.2.4 Mastercard Cybersecurity Incentive Program (CSIP) substantive §2.2.5 SDP Program Noncompliance Assessments substantive §2.2.6 Mandatory Compliance Requirements for Compromised Entities substantive §2.3 Card Production Security Standards substantive §2.3.2 Additional Card Production Requirements substantive §2.4.1 PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
Why these edits? The update introduces a new explicit obligation for Level 1-3 Merchants to validate that all third-party payment applications are listed on the PCI Security Standards Council website, which implies stronger requirements for merchant compliance validation.
Mastercard SPME §2.2.2
Security Rules and Procedures—Merchant Edition • 6 February August 2024 All Level 1, Level 2, and Level 3 Merchants that use any third party-provided payment applications or payment software must validate that each payment application or payment software used is listed on the PCI Security Standards Council (SSC) website at www.pcisecuritystandards.org as compliant with either the Payment Card Industry Payment Application Data Security Standard (PCI PA-DSS) or the PCI Secure Software Standard, as applicable. Mastercard recommends that Merchants use a Qualified Integrator & Reseller (QIR) listed on the PCI SSC website to implement a PCI PA-DSS-compliant payment application, as applicable. Mastercard recommends that Merchants using third party-provided payment software ensure the payment software vendor complies with the PCI Secure SLC Standard. Mastercard recommends that any Merchant that performs or provides 3-D Secure (3DS) functions as defined in the EMV 3-D Secure Protocol and Core Functions Specification comply with the PCI 3DS Core Security Standard and use approved 3DS Software Development Kits (SDKs) listed on the PCI SSC website, as applicable. Level 1 Merchants A Merchant that meets any one or more of the following criteria is deemed to be a Level 1 Merchant and must validate compliance with the PCI DSS: • Any Merchant having greater than six million total combined Mastercard and Maestro Transactions annually, • Any Merchant meeting the Level 1 criteria of Visa, and • Any Merchant that Mastercard, in its sole discretion, determines should meet the Level 1 Merchant requirements to minimize risk to the system, which may include any Merchant that has a confirmed ADC Event. To validate compliance, compliance with the PCI DSS, each Level 1 Merchant must successfully undergo an annual PCI DSS assessment resulting in the completion of a ROC conducted by a PCI SSC-approved SSC- approved Qualified Security Assessor (QSA) or PCI SSC-certified Internal Security Assessor (ISA). Level 2 Merchants Unless deemed to be a Level 1 Merchant, the following are deemed to be a Level 2 Merchant and must validate compliance with the PCI DSS: • Any Merchant with greater than one million but less than or equal to six million total combined Mastercard and Maestro Transactions annually, and • Any Merchant meeting the Level 2 criteria of Visa. To validate compliance, compliance with the PCI DSS, each Level 2 Merchant must successfully complete an annual SAQ. Level 2 Merchants completing SAQ A, SAQ A-EP or SAQ D must additionally engage a PCI SSC- ¶ approved SSC-approved QSA or PCI SSC-certified ISA for compliance validation. Level 2 Merchants may alternatively, at their own discretion, engage a PCI SSC-approved QSA or PCI SSC-certified ISA to complete a ROC instead of performing an SAQ. Cybersecurity Standards and Programs Level 1 Merchants Security Rules and Procedures—Merchant Edition • 6 August 2024 Level 3 Merchants Unless deemed to be a Level 1 or Level 2 Merchant, the following are deemed to be a Level 3 Merchant and must validate compliance with the PCI DSS: ¶ Cybersecurity Standards and Programs ¶ Level 1 Merchants ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024 • Any Merchant with greater than 20,000 but less than or equal to one million total combined Mastercard and Maestro electronic commerce (e-commerce) Transactions annually, and • Any Merchant meeting the Level 3 criteria of Visa. To validate compliance, compliance with the PCI DSS, each Level 3 Merchant must successfully complete an annual SAQ. SAQ, although validation of compliance to Mastercard is not required for a Level 3 Merchant. Level 3 Merchants may alternatively, at their own discretion, engage a PCI SSC-approved QSA to complete a ROC instead of performing an SAQ. Level 4 Merchants Any Merchant not deemed to be a Level 1, Level 2, or Level 3 Merchant is deemed to be a Level 4 Merchant. Compliance with the PCI DSS is required for a Level 4 Merchant, although validation of compliance to Mastercard is optional not required for a Level 4 Merchant. However, a validation of compliance is strongly ¶ recommended for Acquirers with respect to each Level 4 Merchant in order to reduce the risk of ¶ an ADC Event and for an Acquirer potentially to gain a partial waiver of related assessments. Merchant, except as required by applicable law or regulation. A Level 4 Merchant may validate compliance with the PCI DSS by successfully completing an annual SAQ. Level 4 Merchants may alternatively, at their own discretion, engage a PCI SSC-approved QSA to complete a ROC instead of performing an SAQ.
Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1
+ authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.2.2
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
- # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
- # Failure to adhere to these requirements may result in noncompliance assessments.
- # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
- # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
+ # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, using the correct Member ID/ICA Number, to ensure compliance as per Mastercard SPME §11.2.3.
+ # MATCH records related to Merchants, Sponsored Merchants, or ATM owners must be retained for at least two years following agreement termination, according to Mastercard SPME §11.2.6.
+ # For Acquirers handling personal data of EEA, UK, or Switzerland residents, adherence to the Europe Region standards in Appendix D concerning MATCH activity is mandatory in line with Mastercard SPME §11.7.1.
+ # In alignment with Mastercard SPME §2.2.2, Acquirers must ensure that Level 1, 2, and 3 Merchants validate that any third party-provided payment applications or software they use are listed as compliant on the PCI Security Standards Council website, reflecting enhanced compliance validation requirements.
+ # This includes confirming PCI PA-DSS or PCI Secure Software Standard compliance for payment applications and adherence to PCI Secure SLC Standard for payment software vendors.
+ # These updates strengthen Merchant compliance oversight and risk mitigation related to payment application security.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

9. Ensure that Level 1, Level 2, and Level 3 Merchants validate that all third-party payment applications or software used are listed as compliant on the PCI Security Standards Council (SSC) website to meet updated Mastercard requirements for cybersecurity controls.

Source authority: Mastercard SPME §§2.1, 2.2.2, 7.1, 11.2.3, 11.2.6, 11.7.1.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

9. Ensure that Level 1, Level 2, and Level 3 Merchants validate that all third-party payment applications or software used are listed as compliant on the PCI Security Standards Council (SSC) website to meet updated Mastercard requirements for cybersecurity controls.

Source authority: Mastercard SPME §§2.1, 2.2.2, 7.1, 11.2.3, 11.2.6, 11.7.1.

Source authority: Mastercard SPME §2.2.2.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1
+authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.2.2
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -12,7 +12,9 @@
   - ofac_sdn
   - eu_consolidated
 agent_owner: kyb_agent
-# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
-# Failure to adhere to these requirements may result in noncompliance assessments.
-# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
-# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
+# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, using the correct Member ID/ICA Number, to ensure compliance as per Mastercard SPME §11.2.3.
+# MATCH records related to Merchants, Sponsored Merchants, or ATM owners must be retained for at least two years following agreement termination, according to Mastercard SPME §11.2.6.
+# For Acquirers handling personal data of EEA, UK, or Switzerland residents, adherence to the Europe Region standards in Appendix D concerning MATCH activity is mandatory in line with Mastercard SPME §11.7.1.
+# In alignment with Mastercard SPME §2.2.2, Acquirers must ensure that Level 1, 2, and 3 Merchants validate that any third party-provided payment applications or software they use are listed as compliant on the PCI Security Standards Council website, reflecting enhanced compliance validation requirements.
+# This includes confirming PCI PA-DSS or PCI Secure Software Standard compliance for payment applications and adherence to PCI Secure SLC Standard for payment software vendors.
+# These updates strengthen Merchant compliance oversight and risk mitigation related to payment application security.
--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -16,5 +16,6 @@
 6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
 7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
 8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
+9. Ensure that Level 1, Level 2, and Level 3 Merchants validate that all third-party payment applications or software used are listed as compliant on the PCI Security Standards Council (SSC) website to meet updated Mastercard requirements for cybersecurity controls.
 
-Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6, 11.7.1.+Source authority: Mastercard SPME §§2.1, 2.2.2, 7.1, 11.2.3, 11.2.6, 11.7.1.