Mastercard SPME §2.2.3 · Sep 2024 → May 2025

Service Provider Compliance Requirements

substantive

Added BPSP category to Level 1 and Level 2 Service Provider lists, with updated service provider classifications note. Minor formatting changes occurred, but no changes to validation requirements or thresholds.

Sources Mastercard SPME · Sep 2024 · page 22 PDF Mastercard SPME · May 2025 · page 25 PDF KYB Acquirer current
Also in §2.x this release substantive §2.2 Mastercard Site Data Protection (SDP) Program substantive §2.2.1 Customer Compliance Requirements substantive §2.2.5 SDP Program Noncompliance Assessments
Why these edits? The addition of the BPSP category to Level 1 and Level 2 Service Provider lists changes service provider classifications, impacting compliance validation requirements relevant to Acquirer KYB obligations outlined in section 2.1.
Mastercard SPME §2.2.3
This section describes Level 1 and Level 2 Service Provider criteria, and how a Service Provider may successfully validate compliance with the PCI DSS and all other applicable PCI Security Standards and apply cybersecurity best practices. Mastercard recommends that each Level 1 and Level 2 Service Provider demonstrates to Mastercard its compliance with the Designated Entities Supplemental Validation (DESV) appendix of the PCI DSS. All Level 1 and Level 2 Service Providers that use any third party-provided payment applications or payment software must validate that each payment application or payment software used is listed on the PCI SSC website at www.pcisecuritystandards.org as compliant with either the PCI PA-DSS DSS or the PCI Secure Software Standard, as applicable. Mastercard recommends that Service Providers using third party-provided payment software ensure the payment software vendor complies with the PCI Secure SLC Standard. Compliance with the PCI 3DS Core Security Standard is required for any Service Provider that performs or provides 3DS functions as defined in the EMV 3-D Secure Protocol and Core Functions Specification. All Service Providers that use any 3DS SDK must validate that each 3DS SDK used is listed on the PCI SSC website at www.pcisecuritystandards.org as compliant with the PCI 3DS SDK Security Standard, as applicable. Cybersecurity Standards and Programs ¶ Level 3 Merchants ¶ Security Rules and Procedures—Merchant Edition • 6 August 2024 ¶ Level 1 Service Providers A Level 1 Service Provider is any TPP, MPG, SDWO, DASP, TSP, 3-DSSP, BPSP, or ISP (regardless of ¶ of volume); and any AML/Sanctions Service Provider, DSE, or PF that stores, transmits, or processes more than 300,000 total combined Mastercard and Maestro Transactions annually. Each Level 1 Service Provider must validate compliance with the PCI DSS annually, and each 3- DSSP must validate compliance with the PCI 3DS Core Security Standard every two years by Cybersecurity Standards and Programs Level 4 Merchants Security Rules and Procedures—Merchant Edition • 11 February 2025 successfully undergoing a PCI assessment resulting in the completion of a ROC conducted by an appropriate PCI SSC-approved QSA. Level 2 Service Providers A Level 2 Service Provider is any AML/Sanctions Service Provider, DSE, or PF that is not deemed a Level 1 Service Provider and that stores, transmits, or processes 300,000 or less total combined Mastercard and Maestro Transactions annually; and any TS. Each Level 2 Service Provider must validate compliance with the PCI DSS by successfully completing an annual SAQ. As an alternative to validating compliance with the PCI DSS, a DSE qualifying as a Level 2 Service Provider may submit a PCI PIN Security Requirements Attestation of Compliance for Onsite Assessments from a PCI SSC-approved Qualified PIN Assessor (QPA) every two years to the Mastercard SDP Department, provided that the DSE does not perform services involving the storage, transmission, or processing of Account, Cardholder, or Transaction Data. As an alternative to validating compliance with the PCI DSS, a TS may submit a completed Terminal Servicer QIR Participation Validation Form to the Mastercard SDP Department, provided that the TS does not perform services involving the storage, transmission, or processing of Account, Cardholder, or Transaction Data, but the TS has access to such Data within the Cardholder Data Environment (CDE) (as the term is defined by the PCI SSC). The Terminal Servicer QIR Participation Validation Form is available on the Service Provider page of the SDP Program website. NOTE: Service Provider classifications (TPPs, DSEs, BPSPs, PFs, SDWOs, DASPs, TSPs, TSs, AML/Sanctions ¶ AML/ Sanctions Service Providers, 3-DSSPs, ISPs, and MPGs) are determined by Mastercard. Service Provider ¶ Provider registrations with Mastercard will not be deemed complete until the Service Provider’s compliance ¶ Provider's compliance with the SDP Program is validated. Refer to Chapter 7 of the Mastercard Rules manual for additional Service Provider registration requirements.
Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1
+ authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1, 2.2.3
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.
# Failure to adhere to these requirements may result in noncompliance assessments.
# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.
# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
# Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution.
# Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models.
# These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.
+ # Mastercard's updated Service Provider classification in §2.2.3 includes Business Process Service Providers (BPSP) as a Level 1 Service Provider category, and also recognizes BPSPs in Level 2 classifications. Acquirers must incorporate this revised classification into their KYB compliance reviews where applicable, ensuring that such entities are subject to the appropriate compliance validation and PCI DSS standards as specified by Mastercard.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

  9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.

10. Recognize that service provider classifications now include Business Process Service Providers (BPSP) as Level 1 entities; compliance validation requirements applicable to Level 1 service providers thereby extend to BPSPs, affecting KYB risk assessment and due diligence obligations.

Source authority: Mastercard SPME §§2.1, 2.2.3, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.

When this policy applies

This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.

Required actions

  1. Collect all KYB documentation needed at onboarding.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule full re-verification at least annually.

  5. Document verification outcomes and maintain records for audit.

  6. Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.

  7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.

  8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.

  9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.

10. Recognize that service provider classifications now include Business Process Service Providers (BPSP) as Level 1 entities; compliance validation requirements applicable to Level 1 service providers thereby extend to BPSPs, affecting KYB risk assessment and due diligence obligations.

Source authority: Mastercard SPME §§2.1, 2.2.3, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.

Source authority: Mastercard SPME §2.2.3.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1
+authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1, 2.2.3
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -18,4 +18,5 @@
 # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.
 # Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution.
 # Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models.
-# These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.+# These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.
+# Mastercard's updated Service Provider classification in §2.2.3 includes Business Process Service Providers (BPSP) as a Level 1 Service Provider category, and also recognizes BPSPs in Level 2 classifications. Acquirers must incorporate this revised classification into their KYB compliance reviews where applicable, ensuring that such entities are subject to the appropriate compliance validation and PCI DSS standards as specified by Mastercard.
--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -17,5 +17,6 @@
 7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
 8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
 9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.
+10. Recognize that service provider classifications now include Business Process Service Providers (BPSP) as Level 1 entities; compliance validation requirements applicable to Level 1 service providers thereby extend to BPSPs, affecting KYB risk assessment and due diligence obligations.
 
-Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.
+Source authority: Mastercard SPME §§2.1, 2.2.3, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.