Mastercard SPME §2.2.4 · Feb 2024 → Sep 2024

Mastercard Cybersecurity Incentive Program (CSIP)

substantive

The CSIP now explicitly includes MPOS EMV acceptance solutions like SPoC, CPoC, and MPoC among eligible secure technologies. The PCI DSS Risk-based Approach references a new source for milestones. The Exemption Program adds options to qualify via MPOS EMV acceptance solutions and clarifies compliance validation exemptions unless prohibited by law.

Sources Mastercard SPME · Feb 2024 · page 23 PDF Mastercard SPME · Sep 2024 · page 23 PDF KYB Acquirer current
Also in §2.x this release substantive §2.2.2 Merchant Compliance Requirements substantive §2.2.3 Service Provider Compliance Requirements substantive §2.2.5 SDP Program Noncompliance Assessments substantive §2.2.6 Mandatory Compliance Requirements for Compromised Entities substantive §2.3 Card Production Security Standards substantive §2.3.2 Additional Card Production Requirements substantive §2.4.1 PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
Why these edits? The updated SPME section 2.2.4 expands the Mastercard Cybersecurity Incentive Program to explicitly include MPOS EMV acceptance solutions like SPoC, CPoC, and MPoC among eligible secure technologies. This changes acquirer obligations around certifying merchant participation and compliance under the PCI DSS Compliance Validation Exemption Program, impacting the acquirer's Know Your Business (KYB) policy enforcement.
Mastercard SPME §2.2.4
The Mastercard Cybersecurity Incentive Program (CSIP) provides eligible Merchants using secure technologies such as EMV chip technology, a PCI-listed point-to-point encryption (P2PE) solution, an MPOS EMV acceptance solution such as SPoC, CPoC or MPoC, or EMV payment tokenization increased flexibility within the SDP Standards. The CSIP is a component of the SDP Program and is optional for Merchants. The CSIP incentivizes Merchant participation by either reducing PCI compliance validation requirements or by eliminating the requirement to annually validate compliance with the PCI DSS. Cybersecurity Standards and Programs Level 1 Service Providers Security Rules and Procedures—Merchant Edition • 6 August 2024 Mastercard PCI DSS Risk-based Approach A qualifying Level 1 or Level 2 Merchant located outside of the U.S. Region may use the Mastercard PCI DSS Risk-based Approach, which reduces a Merchant’s Merchant's compliance requirements to validating compliance with the first two of the six total milestones set forth in the PCI DSS The Prioritized Approach, Approach to Pursue PCI DSS Compliance, as follows: ¶ Cybersecurity Standards and Programs ¶ Level 2 Service Providers ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024 • A Level 1 Merchant must validate compliance through a PCI DSS assessment resulting in the completion of a ROC conducted by a PCI SSC-approved QSA or PCI SSC-certified ISA; • A Level 2 Merchant must validate compliance through an SAQ. Level 2 Merchants completing SAQ A, SAQ A-EP or SAQ D must additionally engage a PCI SSC-approved QSA or PCI SSC- certified ISA for compliance validation; and • Each Level 1 and Level 2 Merchant must annually re-validate compliance with milestones one and two using an SAQ. To qualify as compliant with the Mastercard PCI DSS Risk-based Approach, a Merchant must satisfy all of the following: • The Merchant must certify that it is not storing Sensitive Authentication Data. • On a continuous basis, the Merchant must keep fully segregated the “Card-not-present” "Card-not-present" Transaction environment from the “face-to-face” "face-to-face" Transaction environment. A face-to-face Transaction requires the Card, the Cardholder, and the Merchant to all be present together at the time and place of the Transaction. • For a Merchant located in the Europe Region, at least 95 percent of the Merchant’s Merchant's annual total count of Card-present Mastercard and Maestro Transactions must occur at Hybrid POS Terminals. • For a Merchant located in the Asia/Pacific Region, Canada Region, Latin America and the Caribbean Region, or Middle East/Africa Region, at least 75 percent of the Merchant’s annual total count of Card-present Mastercard and Maestro Transactions must occur at Hybrid POS Terminals. • The Merchant must not have experienced an ADC Event or Potential ADC Event within the last 3 years, including but not limited to outstanding liabilities or actions preventing complete closure of ADC Event. At the discretion of Mastercard, this and other criteria may be waived if the Merchant validated full PCI DSS compliance at the time of the ADC Event or Potential ADC Event. • The Merchant must establish and annually test an ADC Event incident response plan. Information For information about the PCI DSS Prioritized Approach, refer to The Prioritized Approach to Pursue PCI DSS Compliance, which is available at: ¶ https://www.pcisecuritystandards.org/document_library on the PCI SSC website from the Document Library page. Mastercard PCI DSS Compliance Validation Exemption Program All qualifying Merchants may participate in the Mastercard PCI DSS Compliance Validation Exemption Program (Exemption Program), which exempts the Merchant from annually validating its compliance with the PCI DSS. DSS, unless a Merchant's participation conflicts with applicable law or regulation requiring such validation. Cybersecurity Standards and Programs Mastercard PCI DSS Risk-based Approach Security Rules and Procedures—Merchant Edition • 6 August 2024 To qualify or remain qualified to participate in the Exemption Program, a duly authorized and empowered officer of the Merchant must certify to the Merchant’s Merchant's Acquirer in writing that the Merchant has satisfied all of the following: 1. The Merchant does not store Sensitive Authentication Data. The Acquirer must notify Mastercard through compliance validation reporting of the status of Merchant storage of Sensitive Authentication Data; ¶ Cybersecurity Standards and Programs ¶ Mastercard PCI DSS Compliance Validation Exemption Program ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024 2. The Merchant has not been identified by Mastercard as having experienced an ADC Event or Potential ADC Event during the prior three years, including but not limited to outstanding liabilities or actions preventing complete closure of ADC Event; 3. The Merchant has established and annually tests an ADC Event incident response plan in accordance with PCI DSS requirements; and 4. The Merchant has satisfied one of the following: a. At least 75 percent of the Merchant’s Merchant's annual total acquired Mastercard and Maestro Transaction count is processed through Hybrid POS Terminals, as determined based on the Merchant’s Merchant's transactions processed during the previous twelve (12) months through the Global Clearing Management System (GCMS) and/or Single Message System. Transactions that were not processed by Mastercard may be included in the annual acquired Transaction count if the data is readily available to Mastercard; b. The Merchant has implemented a P2PE solution listed on the PCI SSC website; c. The Merchant has implemented an MPOS EMV acceptance solution, such as SPoC, CPoC, or MPoC, listed on the PCI SSC website; OR c. d. At least 75 percent of the Merchant’s Merchant's annual total acquired Mastercard and Maestro Transaction count is processed using Mastercard Tokens from TSPs compliant with the Token Service Provider Standards. As a best practice, qualifying Merchants participating in the Exemption Program are recommended to validate compliance with the PCI DSS within the previous twelve (12) months of entering the Exemption Program. An Acquirer must retain all Merchant certifications of eligibility for the Exemption Program for a minimum of five (5) years. Upon request by Mastercard, the Acquirer must provide a Merchant’s Merchant's certification of eligibility for the Exemption Program and any documentation and/or other information applicable to such certification. An Acquirer is responsible for ensuring that each Exemption Program certification is truthful and accurate. A Merchant that does not satisfy the Exemption Program’s Program's eligibility criteria, including any Merchant whose Transaction volume is primarily from e-commerce that does not utilize EMV Payment Tokenization and Mail Order/Telephone Order (MO/TO) acceptance channels, must continue to validate its PCI DSS compliance in accordance with section Section 2.2.2. All Merchants must maintain ongoing compliance with the PCI DSS regardless of whether annual compliance validation is a requirement. Cybersecurity Standards and Programs Mastercard PCI DSS Compliance Validation Exemption Program Security Rules and Procedures—Merchant Edition • 6 August 2024
Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1
+ authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.2.4
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
- # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
+ # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3.
+ # This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
# Failure to adhere to these requirements may result in noncompliance assessments.
# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
+ # In accordance with Mastercard SPME §2.2.4, the Acquirer must recognize that the Mastercard Cybersecurity Incentive Program (CSIP) now explicitly includes secure technologies such as EMV chip technology, PCI-listed point-to-point encryption (P2PE), EMV payment tokenization, and mobile point-of-sale (MPOS) EMV acceptance solutions including SPoC, CPoC, and MPoC.
+ # This affects the acquirer's role in certifying merchants' participation in the PCI DSS Compliance Validation Exemption Program, requiring updated validation and documentation standards to ensure merchant eligibility and compliance.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

9. Recognize the Mastercard Cybersecurity Incentive Program (CSIP), which now includes MPOS EMV acceptance solutions such as SPoC, CPoC, or MPoC, among eligible secure technologies. Halyard Pay must incorporate these provisions into merchant PCI DSS compliance validation and certification processes where applicable, including assessment under the PCI DSS Compliance Validation Exemption Program.

Source authority: Mastercard SPME §§2.1, 2.2.4, 7.1, 11.2.3, 11.2.6, 11.7.1.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

9. Recognize the Mastercard Cybersecurity Incentive Program (CSIP), which now includes MPOS EMV acceptance solutions such as SPoC, CPoC, or MPoC, among eligible secure technologies. Halyard Pay must incorporate these provisions into merchant PCI DSS compliance validation and certification processes where applicable, including assessment under the PCI DSS Compliance Validation Exemption Program.

Source authority: Mastercard SPME §§2.1, 2.2.4, 7.1, 11.2.3, 11.2.6, 11.7.1.

Source authority: Mastercard SPME §2.2.4.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1
+authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.2.4
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -12,7 +12,10 @@
   - ofac_sdn
   - eu_consolidated
 agent_owner: kyb_agent
-# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
+# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3.
+# This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
 # Failure to adhere to these requirements may result in noncompliance assessments.
 # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
 # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
+# In accordance with Mastercard SPME §2.2.4, the Acquirer must recognize that the Mastercard Cybersecurity Incentive Program (CSIP) now explicitly includes secure technologies such as EMV chip technology, PCI-listed point-to-point encryption (P2PE), EMV payment tokenization, and mobile point-of-sale (MPOS) EMV acceptance solutions including SPoC, CPoC, and MPoC.
+# This affects the acquirer's role in certifying merchants' participation in the PCI DSS Compliance Validation Exemption Program, requiring updated validation and documentation standards to ensure merchant eligibility and compliance.

--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -16,5 +16,6 @@
 6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
 7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
 8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
+9. Recognize the Mastercard Cybersecurity Incentive Program (CSIP), which now includes MPOS EMV acceptance solutions such as SPoC, CPoC, or MPoC, among eligible secure technologies. Halyard Pay must incorporate these provisions into merchant PCI DSS compliance validation and certification processes where applicable, including assessment under the PCI DSS Compliance Validation Exemption Program.
 
-Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6, 11.7.1.+Source authority: Mastercard SPME §§2.1, 2.2.4, 7.1, 11.2.3, 11.2.6, 11.7.1.