Mastercard SPME §2.2.5 · Feb 2024 → Sep 2024

SDP Program Noncompliance Assessments

substantive

The section was completely revised to replace the previous penalty tier tables with new detailed procedures for forensic investigation follow-up. It mandates submission of a specific form, evidence of PCI DSS compliance within defined deadlines by merchant or service provider category, and states non-approval of extension requests. Noncompliance may lead to assessments under this section.

Sources Mastercard SPME · Feb 2024 · page 25 PDF Mastercard SPME · Sep 2024 · page 26 PDF KYB Acquirer current
Also in §2.x this release substantive §2.2.2 Merchant Compliance Requirements substantive §2.2.3 Service Provider Compliance Requirements substantive §2.2.4 Mastercard Cybersecurity Incentive Program (CSIP) substantive §2.2.6 Mandatory Compliance Requirements for Compromised Entities substantive §2.3 Card Production Security Standards substantive §2.3.2 Additional Card Production Requirements substantive §2.4.1 PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
Why these edits? The updated section 2.2.5 imposes new obligations on Acquirers to submit specific forensic investigation follow-up forms and evidence of PCI DSS compliance within strict deadlines, with no allowance for extensions, which impacts Acquirer Know Your Business (KYB) compliance procedures.
Mastercard SPME §2.2.5
This section was substantively restructured between versions (4% text overlap). Compare the texts directly below.
Before · Feb 2024 · page 25

Security Rules and Procedures—Merchant Edition • 6 February 2024

Table 2.2—Assessments for Noncompliance with the SDP Program Failure of the following to comply with the SDP Program mandate... May result in an assessment of... Classification Violations per calendar year Level 1 and Level 2 Merchants Up to USD 25,000 for the first violation Up to USD 50,000 for the second violation Up to USD 100,000 for the third violation Up to USD 200,000 for the fourth violation Level 3 Merchants Up to USD 10,000 for the first violation Up to USD 20,000 for the second violation Up to USD 40,000 for the third violation Up to USD 80,000 for the fourth violation Level 1 and Level 2 Service Providers Up to USD 25,000 for the first violation Up to USD 50,000 for the second violation Up to USD 100,000 for the third violation Up to USD 200,000 for the fourth violation Noncompliance also may result in Merchant termination; deregistration of a TPP, DSE, PF, SDWO, DASP, TSP, TS, AML/Sanctions Service Provider, 3-DSSP, ISP, or MPG as a Service Provider; delisting of a Service Provider from The Mastercard SDP Compliant Registered Service Provider List; or termination of the Issuer or Acquirer as a Customer as provided in Rule 2.1.2 of the Mastercard Rules manual. Late SDP Acquirer Submission and Compliance Status Forms for semi-annual merchant compliance reporting submissions or failure to submit the required form(s) may result in an additional assessment to the Customer as described for Category A violations in Rule 2.1.4 of the Mastercard Rules manual.

After · Sep 2024 · page 26

Security Rules and Procedures—Merchant Edition • 6 August 2024

At the conclusion of the forensic investigation, Mastercard will provide a Mastercard Site Data Protection (SDP) Account Data Compromise Information Form for completion by the compromised entity itself, if the compromised entity is a Service Provider, or by its Acquirer, if the compromised entity is a Merchant. The form must be returned by email message to pci_adc@mastercard.com within 30 calendar days of its receipt, and must include:

  • The names of the forensic investigator, QSA and the Approved Scanning Vendor (ASV);
  • The entity's current level of compliance; and
  • A gap analysis providing detailed steps required for the entity to achieve full compliance. PCI DSS Compliance As soon as practical, but no later than the PCI DSS compliance deadline shown in Table 2.3, the compromised entity or its Acquirer must provide evidence of compliance to Mastercard that the compromised entity has achieved full compliance with the PCI DSS. Table 2.3 PCI DSS Compliance Deadlines and Evidence of Compliance for Compromised Entities Classification PCI DSS Compliance Deadline from the Conclusion of the Forensic Investigation Evidence of Compliance Service Providers 90 calendar days Both of the following:
  • PCI DSS ROC AOC conducted by a PCI SSC-approved QSA; and
  • DESV Supplemental ROC (S-ROC) AOC conducted by a PCI SSC-approved QSA within twelve (12) months from achieving full compliance with the PCI DSS Level 1 or Level 2 Merchants 180 calendar days PCI DSS ROC AOC conducted by a PCI SSC- approved QSA Level 3 or Level 4 Merchants 180 calendar days Either of the following:
  • PCI DSS ROC AOC conducted by a PCI SSC-approved QSA; or
  • PCI DSS SAQ AOC Evidence of compliance for compromised entities must be submitted to Mastercard by email message to pci_adc@mastercard.com no later than the PCI DSS compliance deadline shown in Table 2.3. Failure to comply with these requirements may result in SDP noncompliance assessments as described in Section 2.2.5. Extension requests for compromised entities that do not meet the PCI DSS compliance deadline shown in Table 2.3 will not be approved by Mastercard. Cybersecurity Standards and Programs
Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1
+ authority: Mastercard SPME 2.1, 2.2.5, 11.2.3, 11.2.6, 11.7.1
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
# Failure to adhere to these requirements may result in noncompliance assessments.
# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
+ # Following a forensic investigation involving a compromised entity, Acquirers must ensure submission of a completed Mastercard SDP Account Data Compromise Information Form and evidence of PCI DSS compliance within mandated deadlines, in compliance with Mastercard SPME §2.2.5. Extensions are not permitted, and failure to comply may lead to assessments or penalties.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

9. In cases of data compromises involving Merchants or Service Providers, Halyard Pay must comply with Mastercard's forensic investigation requirements. This includes submitting the Site Data Protection (SDP) Account Data Compromise Information Form within 30 calendar days of receipt and providing evidence of PCI DSS compliance by specified deadlines, aligned with the entity's classification. No extensions for compliance deadlines will be accepted, underscoring the importance of timely response and remediation efforts.

Source authority: Mastercard SPME §§2.1, 2.2.5, 7.1, 11.2.3, 11.2.6, 11.7.1.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

9. In cases of data compromises involving Merchants or Service Providers, Halyard Pay must comply with Mastercard's forensic investigation requirements. This includes submitting the Site Data Protection (SDP) Account Data Compromise Information Form within 30 calendar days of receipt and providing evidence of PCI DSS compliance by specified deadlines, aligned with the entity's classification. No extensions for compliance deadlines will be accepted, underscoring the importance of timely response and remediation efforts.

Source authority: Mastercard SPME §§2.1, 2.2.5, 7.1, 11.2.3, 11.2.6, 11.7.1.

Source authority: Mastercard SPME §2.2.5.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1
+authority: Mastercard SPME 2.1, 2.2.5, 11.2.3, 11.2.6, 11.7.1
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -16,3 +16,4 @@
 # Failure to adhere to these requirements may result in noncompliance assessments.
 # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
 # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
+# Following a forensic investigation involving a compromised entity, Acquirers must ensure submission of a completed Mastercard SDP Account Data Compromise Information Form and evidence of PCI DSS compliance within mandated deadlines, in compliance with Mastercard SPME §2.2.5. Extensions are not permitted, and failure to comply may lead to assessments or penalties.

--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -16,5 +16,6 @@
 6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
 7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
 8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
+9. In cases of data compromises involving Merchants or Service Providers, Halyard Pay must comply with Mastercard's forensic investigation requirements. This includes submitting the Site Data Protection (SDP) Account Data Compromise Information Form within 30 calendar days of receipt and providing evidence of PCI DSS compliance by specified deadlines, aligned with the entity's classification. No extensions for compliance deadlines will be accepted, underscoring the importance of timely response and remediation efforts.
 
-Source authority: Mastercard SPME §§2.1, 7.1, 11.2.3, 11.2.6, 11.7.1.+Source authority: Mastercard SPME §§2.1, 2.2.5, 7.1, 11.2.3, 11.2.6, 11.7.1.