Mastercard SPME §2.2.1 · Sep 2024 → May 2025

Customer Compliance Requirements

substantive

The updated section adds specific reporting deadlines for submission periods and introduces a requirement for Acquirers to have a risk management program managing payment security risks for Level 3 and Level 4 merchants. It also details potential cost reductions for Customers compliant with the SDP Program impacted by ADC Events, alongside clarifications on service provider validation and submission processes.

Sources Mastercard SPME · Sep 2024 · page 19 PDF Mastercard SPME · May 2025 · page 22 PDF KYB Acquirer current
Also in §2.x this release substantive §2.2 Mastercard Site Data Protection (SDP) Program substantive §2.2.3 Service Provider Compliance Requirements substantive §2.2.5 SDP Program Noncompliance Assessments
Why these edits? The updated Mastercard SPME section 2.2.1 introduces a new obligation requiring Acquirers to have a risk management program for managing payment security risks for Level 3 and Level 4 merchants. This directly impacts the Acquirer KYB (Know Your Business) Obligations policy which cites section 2.1, requiring revision to include these expanded risk management and validation requirements.
Mastercard SPME §2.2.1
This section was substantively restructured between versions (40% text overlap). Compare the texts directly below.
Before · Sep 2024 · page 19

Compliance with the PCI DSS is required for all Issuers and Acquirers, although validation of the Customer's compliance is not required. To ensure compliance with the Mastercard SDP Program, an Issuer must:

  • Communicate the SDP Program requirements to each Level 1 and Level 2 Service Provider, and validate the Service Provider's compliance with the PCI DSS and any other applicable PCI Security Standard by reviewing the Payment Card Industry Self-Assessment Questionnaire (SAQ) or the Report on Compliance (ROC).
  • Submit the annual PCI compliance validation (the PCI Attestation of Compliance [AOC]) for each Level 1 and Level 2 Service Provider by email message to pcireports@mastercard.com, after initial registration with Mastercard and every year thereafter. If a newly registered Service Provider is not yet compliant, the PCI Action Plan available on the Service Provider page of the SDP Program website must be completed and submitted for review. To ensure compliance with the Mastercard SDP Program, an Acquirer must: Cybersecurity Standards and Programs
After · May 2025 · page 22

Security Rules and Procedures—Merchant Edition • 11 February 2025

For this reporting period… Submit the form(s) no later than… 1 October to 31 March 31 March 1 April to 30 September 30 September

  • Validate to Mastercard that the Acquirer has a risk management program in place to identify and manage payment security risk within the Acquirer's Level 3 and Level 4 Merchant portfolios.
  • Communicate the SDP Program requirements to each Level 1 and Level 2 Service Provider, and validate the Service Provider’s compliance with the PCI DSS and any other applicable PCI Security Standard by reviewing the Payment Card Industry Self-assessment Questionnaire and the ROC.
  • Submit annual PCI validation (the PCI Attestation of Compliance [AOC]) for each Level 1 and Level 2 Service Provider by email message to pcireports@mastercard.com after initial registration with Mastercard and every year thereafter. If a newly registered Service Provider is not yet compliant, the PCI Action Plan available on the Service Provider page of the SDP Program website must be completed and submitted for review. A Customer that complies with the SDP Program requirements may qualify for a reduction, partial or total, of certain costs or assessments if the Customer is impacted by an ADC Event, whether caused by the Customer itself, a Merchant, or a Service Provider.
Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1
+ authority: Mastercard SPME 2.1, 2.2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
- # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
- # Failure to adhere to these requirements may result in noncompliance assessments.
- # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
- # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
- # Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution.
- # Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models.
- # These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.
+ # Acquirers must perform a MATCH inquiry prior to entering into a Merchant Agreement or enabling acceptance of transactions, using the correct Member ID/ICA Number for compliance verification, as per Mastercard SPME §11.2.3.
+ # MATCH records must be retained for at least two years following agreement termination, consistent with Mastercard SPME §11.2.6.
+ # Acquirers processing personal data of residents in the EEA, UK, or Switzerland must comply with data protection standards outlined in Appendix D relevant to MATCH activities, per Mastercard SPME §11.7.1.
+ # Per Mastercard SPME §2.4.1, Acquirers must maintain inventories of PED and EPP devices, ensure timely software security patches, perform regular physical inspections for tampering, and discontinue use of devices with expired PCI PTS approvals per Mastercard sunset dates.
+ # In alignment with Mastercard SPME §2.2.1, Acquirers are required to maintain a documented risk management program focused on identifying and managing payment security risks within their Level 3 and Level 4 Merchant portfolios.
+ # Acquirers must validate compliance of all Level 1 and Level 2 Service Providers with PCI DSS and applicable security standards through review of self-assessment questionnaires and reports on compliance, submitting annual PCI Attestation of Compliance documentation to Mastercard.
+ # These combined controls enhance the Acquirer's ability to manage payment security risks effectively and maintain compliance with Mastercard's risk management and PCI compliance mandates.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

  9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.

10. Implement and maintain a risk management program to identify and manage payment security risks within the Acquirer's Level 3 and Level 4 merchant portfolios, including ongoing validation of compliance with PCI DSS and other applicable PCI Security Standards for Level 1 and Level 2 Service Providers related to these merchant levels. Submit required annual PCI compliance validations and maintain communication of SDP Program requirements to all applicable Service Providers.

Source authority: Mastercard SPME §§2.1, 2.2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

  9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.

10. Implement and maintain a risk management program to identify and manage payment security risks within the Acquirer's Level 3 and Level 4 merchant portfolios, including ongoing validation of compliance with PCI DSS and other applicable PCI Security Standards for Level 1 and Level 2 Service Providers related to these merchant levels. Submit required annual PCI compliance validations and maintain communication of SDP Program requirements to all applicable Service Providers.

Source authority: Mastercard SPME §§2.1, 2.2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.

Source authority: Mastercard SPME §2.2.1.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1
+authority: Mastercard SPME 2.1, 2.2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -12,10 +12,10 @@
   - ofac_sdn
   - eu_consolidated
 agent_owner: kyb_agent
-# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
-# Failure to adhere to these requirements may result in noncompliance assessments.
-# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
-# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
-# Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution.
-# Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models.
-# These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.+# Acquirers must perform a MATCH inquiry prior to entering into a Merchant Agreement or enabling acceptance of transactions, using the correct Member ID/ICA Number for compliance verification, as per Mastercard SPME §11.2.3.
+# MATCH records must be retained for at least two years following agreement termination, consistent with Mastercard SPME §11.2.6.
+# Acquirers processing personal data of residents in the EEA, UK, or Switzerland must comply with data protection standards outlined in Appendix D relevant to MATCH activities, per Mastercard SPME §11.7.1.
+# Per Mastercard SPME §2.4.1, Acquirers must maintain inventories of PED and EPP devices, ensure timely software security patches, perform regular physical inspections for tampering, and discontinue use of devices with expired PCI PTS approvals per Mastercard sunset dates.
+# In alignment with Mastercard SPME §2.2.1, Acquirers are required to maintain a documented risk management program focused on identifying and managing payment security risks within their Level 3 and Level 4 Merchant portfolios.
+# Acquirers must validate compliance of all Level 1 and Level 2 Service Providers with PCI DSS and applicable security standards through review of self-assessment questionnaires and reports on compliance, submitting annual PCI Attestation of Compliance documentation to Mastercard.
+# These combined controls enhance the Acquirer's ability to manage payment security risks effectively and maintain compliance with Mastercard's risk management and PCI compliance mandates.
--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -17,5 +17,6 @@
 7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
 8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
 9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.
+10. Implement and maintain a risk management program to identify and manage payment security risks within the Acquirer's Level 3 and Level 4 merchant portfolios, including ongoing validation of compliance with PCI DSS and other applicable PCI Security Standards for Level 1 and Level 2 Service Providers related to these merchant levels. Submit required annual PCI compliance validations and maintain communication of SDP Program requirements to all applicable Service Providers.
 
-Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.
+Source authority: Mastercard SPME §§2.1, 2.2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.