Mastercard SPME §2.2.5 · Sep 2024 → May 2025
SDP Program Noncompliance Assessments
The section was replaced with a new table detailing financial penalties and additional consequences for failing to comply with the SDP Program, including escalating fines for violations based on merchant or service provider level and potential termination or deregistration. Penalties now also apply for late or missing compliance reporting submissions.
Security Rules and Procedures—Merchant Edition • 6 August 2024
At the conclusion of the forensic investigation, Mastercard will provide a Mastercard Site Data Protection (SDP) Account Data Compromise Information Form for completion by the compromised entity itself, if the compromised entity is a Service Provider, or by its Acquirer, if the compromised entity is a Merchant. The form must be returned by email message to pci_adc@mastercard.com within 30 calendar days of its receipt, and must include:
- The names of the forensic investigator, QSA and the Approved Scanning Vendor (ASV);
- The entity's current level of compliance; and
- A gap analysis providing detailed steps required for the entity to achieve full compliance. PCI DSS Compliance As soon as practical, but no later than the PCI DSS compliance deadline shown in Table 2.3, the compromised entity or its Acquirer must provide evidence of compliance to Mastercard that the compromised entity has achieved full compliance with the PCI DSS. Table 2.3 PCI DSS Compliance Deadlines and Evidence of Compliance for Compromised Entities Classification PCI DSS Compliance Deadline from the Conclusion of the Forensic Investigation Evidence of Compliance Service Providers 90 calendar days Both of the following:
- PCI DSS ROC AOC conducted by a PCI SSC-approved QSA; and
- DESV Supplemental ROC (S-ROC) AOC conducted by a PCI SSC-approved QSA within twelve (12) months from achieving full compliance with the PCI DSS Level 1 or Level 2 Merchants 180 calendar days PCI DSS ROC AOC conducted by a PCI SSC- approved QSA Level 3 or Level 4 Merchants 180 calendar days Either of the following:
- PCI DSS ROC AOC conducted by a PCI SSC-approved QSA; or
- PCI DSS SAQ AOC Evidence of compliance for compromised entities must be submitted to Mastercard by email message to pci_adc@mastercard.com no later than the PCI DSS compliance deadline shown in Table 2.3. Failure to comply with these requirements may result in SDP noncompliance assessments as described in Section 2.2.5. Extension requests for compromised entities that do not meet the PCI DSS compliance deadline shown in Table 2.3 will not be approved by Mastercard. Cybersecurity Standards and Programs
Security Rules and Procedures—Merchant Edition • 11 February 2025
Table 2.2 - Assessments for Noncompliance with the SDP Program Failure of the following to comply with the SDP Program mandate… May result in an assessment of… Classification Violations per calendar year Level 1 and Level 2 Merchants Up to USD 25,000 for the first violation Up to USD 50,000 for the second violation Up to USD 100,000 for the third violation Up to USD 200,000 for the fourth violation Level 3 Merchants Up to USD 10,000 for the first violation Up to USD 20,000 for the second violation Up to USD 40,000 for the third violation Up to USD 80,000 for the fourth violation Level 1 and Level 2 Service Providers Up to USD 25,000 for the first violation Up to USD 50,000 for the second violation Up to USD 100,000 for the third violation Up to USD 200,000 for the fourth violation Noncompliance also may result in Merchant termination; deregistration of a TPP, DSE, BPSP, PF, SDWO, DASP, TSP, TS, AML/Sanctions Service Provider, 3-DSSP, ISP, or MPG as a Service Provider; delisting of a Service Provider from The Mastercard SDP Compliant Registered Service Provider List; or termination of the Issuer or Acquirer as a Customer as provided in Rule 2.1.2 of the Mastercard Rules manual. Late SDP Acquirer Submission and Compliance Status Forms for semiannual merchant compliance reporting submissions or failure to submit the required form(s) may result in an additional assessment to the Customer as described for Category A violations in Rule 2.1.4 of the Mastercard Rules manual.
program: Acquirer KYB- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1+ authority: Mastercard SPME 2.1, 2.2.5, 11.2.3, 11.2.6, 11.7.1, 2.4.1required_documents:- incorporation- beneficial_ownership- aml_screen- license_verificationmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent- # Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.- # Failure to adhere to these requirements may result in noncompliance assessments.- # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.- # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.- # Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution.- # Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models.- # These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.+ # Acquirers are required to perform a MATCH inquiry before establishing Merchant Agreements to ensure compliance, and must retain MATCH records for at least two years post-termination, per Mastercard SPME §11.2.3 and §11.2.6.+ # European data protection standards apply to MATCH activities in the Europe Region, following Mastercard SPME §11.7.1.+ # Acquirers must maintain strict control over their PIN Entry Devices and Encrypting PIN Pads, including inventory management, timely security patching, and physical inspections, as mandated by Mastercard SPME §2.4.1.+ # Devices with expired PCI PTS approval must be managed appropriately and removed from active use as directed.+ # Following the updated Mastercard SPME §2.2.5, Acquirers must submit timely and complete SDP Acquirer Submission and Compliance Status Forms to Mastercard; failure to comply may result in financial penalties and other sanctions impacting the acquirer's standing as detailed in the SDP program guidelines.+ # These measures reinforce Mastercard's risk management framework and the acquirer's accountability for maintaining program compliance.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.
When this policy applies
This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.
Required actions
-
Collect all KYB documentation needed at onboarding.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule full re-verification at least annually.
-
Document verification outcomes and maintain records for audit.
-
Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
-
Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
-
For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
-
Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.
10. Ensure timely submission of all required SDP (Site Data Protection) compliance and status forms for merchants, as mandated by Mastercard, to avoid financial penalties and potential service consequences, including assessments up to USD 200,000 for repeated violations and possible termination of merchant accounts or service provider relationships.
Source authority: Mastercard SPME §§2.1, 2.2.5, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.
When this policy applies
This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.
Required actions
-
Collect all KYB documentation needed at onboarding.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule full re-verification at least annually.
-
Document verification outcomes and maintain records for audit.
-
Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
-
Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
-
For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
-
Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.
10. Ensure timely submission of all required SDP (Site Data Protection) compliance and status forms for merchants, as mandated by Mastercard, to avoid financial penalties and potential service consequences, including assessments up to USD 200,000 for repeated violations and possible termination of merchant accounts or service provider relationships.
Source authority: Mastercard SPME §§2.1, 2.2.5, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.
Source authority: Mastercard SPME §2.2.5.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -1,5 +1,5 @@ program: Acquirer KYB -authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1 +authority: Mastercard SPME 2.1, 2.2.5, 11.2.3, 11.2.6, 11.7.1, 2.4.1 required_documents: - incorporation - beneficial_ownership @@ -12,10 +12,9 @@ - ofac_sdn - eu_consolidated agent_owner: kyb_agent -# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting. -# Failure to adhere to these requirements may result in noncompliance assessments. -# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6. -# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1. -# Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution. -# Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models. -# These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.+# Acquirers are required to perform a MATCH inquiry before establishing Merchant Agreements to ensure compliance, and must retain MATCH records for at least two years post-termination, per Mastercard SPME §11.2.3 and §11.2.6. +# European data protection standards apply to MATCH activities in the Europe Region, following Mastercard SPME §11.7.1. +# Acquirers must maintain strict control over their PIN Entry Devices and Encrypting PIN Pads, including inventory management, timely security patching, and physical inspections, as mandated by Mastercard SPME §2.4.1. +# Devices with expired PCI PTS approval must be managed appropriately and removed from active use as directed. +# Following the updated Mastercard SPME §2.2.5, Acquirers must submit timely and complete SDP Acquirer Submission and Compliance Status Forms to Mastercard; failure to comply may result in financial penalties and other sanctions impacting the acquirer's standing as detailed in the SDP program guidelines. +# These measures reinforce Mastercard's risk management framework and the acquirer's accountability for maintaining program compliance. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -17,5 +17,6 @@ 7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments. 8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region. 9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline. +10. Ensure timely submission of all required SDP (Site Data Protection) compliance and status forms for merchants, as mandated by Mastercard, to avoid financial penalties and potential service consequences, including assessments up to USD 200,000 for repeated violations and possible termination of merchant accounts or service provider relationships. -Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1. +Source authority: Mastercard SPME §§2.1, 2.2.5, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.