Mastercard SPME §2.2 · Sep 2024 → May 2025
Mastercard Site Data Protection (SDP) Program
The updated section broadens the scope to include more types of Service Providers under the SDP Program, requires compliance with PCI DSS or ISO/IEC 27001 for Issuers and Acquirers, and clarifies that Mastercard has sole discretion over enforcing the program. Level 1 and 2 Merchants and all Service Providers must validate compliance to be deemed compliant.
Security Rules and Procedures—Merchant Edition • 6 August 2024
- Communicate the SDP Program requirements to each Level 1, Level 2, and Level 3 Merchant, and validate the Merchant's compliance with the PCI DSS by reviewing the Payment Card Industry Self-Assessment Questionnaire or the ROC.
- Submit the SDP Acquirer Submission and Compliance Status Form available on the Acquirer page of the SDP Program website, for each Level 1 and Level 2 Merchant semiannually by email message to sdp@mastercard.com. Where required by applicable laws, regulations or a regulator, the Acquirer must submit the SDP Acquirer Submission and Compliance Status Form available on the Acquirer page of the SDP Program website for each Level 3 Merchant to sdp@mastercard.com upon request by Mastercard. For this reporting period… Submit the form(s) no later than… 1 October to 31 March 31 March 1 April to 30 September 30 September
- Validate to Mastercard that the Acquirer has a risk management program in place to identify and manage payment security risk within the Acquirer's Level 3 and Level 4 Merchant portfolios.
- Communicate the SDP Program requirements to each Level 1 and Level 2 Service Provider, and validate the Service Provider’s compliance with the PCI DSS and any other applicable PCI Security Standard by reviewing the Payment Card Industry Self-assessment Questionnaire and the ROC.
- Submit annual PCI validation (the PCI Attestation of Compliance [AOC]) for each Level 1 and Level 2 Service Provider by email message to pcireports@mastercard.com after initial registration with Mastercard and every year thereafter. If a newly registered Service Provider is not yet compliant, the PCI Action Plan available on the Service Provider page of the SDP Program website must be completed and submitted for review. A Customer that complies with the SDP Program requirements may qualify for a reduction, partial or total, of certain costs or assessments if the Customer is impacted by an ADC Event, whether caused by the Customer itself, a Merchant, or a Service Provider.
Security Rules and Procedures—Merchant Edition • 11 February 2025
Service Providers [ISPs]), and Merchant Payment Gateways [MPGs]) protect against Account Data Compromise (ADC) Events. NOTE: For the purposes of the SDP Program, TPPs, DSEs, PFs, BPSPs, SDWOs, DASPs, TSPs, TSs, AML/Sanctions Service Providers, 3-DSSPs, ISPs, and MPGs are collectively referred to as "Service Providers" in this chapter. Refer to Section 10.1 of this manual for the definitions of an Account Data Compromise Event and a Potential Account Data Compromise Event. Compliance with the Payment Card Industry Data Security Standard (PCI DSS) and all other applicable PCI Security Standards is required for all Issuers, Acquirers, Merchants, Service Providers, and any other person or entity that a Customer permits, directly or indirectly, to store, transmit, or process Account Data. Only Level 1 and Level 2 Merchants and all Service Providers must validate their compliance to Mastercard, as set forth in Sections 2.2.2 and 2.2.3 respectively, in order to be deemed compliant with the Mastercard SDP Program. Issuers and Acquirers may alternatively comply with ISO/IEC 27001 instead of the PCI DSS. Mastercard has sole discretion to interpret and enforce the SDP Program Standards.
program: Acquirer KYB- authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1+ authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.2, 2.4.1required_documents:- incorporation- beneficial_ownership- aml_screen- license_verificationmin_review_cycle_days: 365suspension_trigger: document_collection_failurerecord_retention_years: 7aml_watchlist_sources:- ofac_sdn- eu_consolidatedagent_owner: kyb_agent# Acquirers must perform a MATCH inquiry prior to entering into any Merchant Agreement or enabling a Merchant to accept transactions, as detailed in Mastercard SPME §11.2.3. This inquiry must be conducted using the correct Member ID/ICA Number associated with the Merchant to ensure proper compliance reporting.# Failure to adhere to these requirements may result in noncompliance assessments.# The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6.# Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1.+ # Per Mastercard SPME §2.2, Acquirers must ensure compliance with the Mastercard Secure Data Processing (SDP) Program, which requires validation of PCI DSS compliance or, alternatively, ISO/IEC 27001 certification for risk management, covering all merchant levels and service providers in their portfolio.# Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution.# Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models.# These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.
When this policy applies
This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.
Required actions
-
Collect all KYB documentation needed at onboarding.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule full re-verification at least annually.
-
Document verification outcomes and maintain records for audit.
-
Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
-
Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
-
For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
-
Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.
10. Ensure compliance with the Mastercard Secure Delivery Program (SDP) requirements by communicating PCI DSS or alternative ISO/IEC 27001 standards compliance obligations to merchants and service providers as applicable. Submit all required SDP compliance attestations and reports for Level 1 and Level 2 Merchants and Service Providers on schedule, and validate risk management programs for payment security within merchant portfolios.
Source authority: Mastercard SPME §§2.1, 2.2, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.
Acquirer KYB (Know Your Business) Obligations
Acquirers processing transactions on the Mastercard network must perform Know Your Business (KYB) due diligence on merchants prior to onboarding and on a recurring basis. Halyard Pay is responsible for collecting and verifying required documentation to confirm business legitimacy, vet beneficial ownership, and satisfy anti-money laundering (AML) screening.
When this policy applies
This policy applies at initial merchant onboarding and during periodic re-verification reviews. Merchants that do not provide required documentation within set timelines must be suspended until compliance is restored.
Required actions
-
Collect all KYB documentation needed at onboarding.
-
Conduct AML screening against applicable watchlists before approval.
-
Verify business licenses for regulated merchant categories.
-
Schedule full re-verification at least annually.
-
Document verification outcomes and maintain records for audit.
-
Retain MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for at least two years after contract termination or expiration, to meet Mastercard record retention requirements.
-
Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments.
-
For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region.
-
Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline.
10. Ensure compliance with the Mastercard Secure Delivery Program (SDP) requirements by communicating PCI DSS or alternative ISO/IEC 27001 standards compliance obligations to merchants and service providers as applicable. Submit all required SDP compliance attestations and reports for Level 1 and Level 2 Merchants and Service Providers on schedule, and validate risk management programs for payment security within merchant portfolios.
Source authority: Mastercard SPME §§2.1, 2.2, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.
Source authority: Mastercard SPME §2.2.
--- a/policies/kyb_acquirer/rules.yaml +++ b/policies/kyb_acquirer/rules.yaml @@ -1,5 +1,5 @@ program: Acquirer KYB -authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.4.1 +authority: Mastercard SPME 2.1, 11.2.3, 11.2.6, 11.7.1, 2.2, 2.4.1 required_documents: - incorporation - beneficial_ownership @@ -16,6 +16,7 @@ # Failure to adhere to these requirements may result in noncompliance assessments. # The Acquirer is also required to retain all MATCH records related to any Merchant, Sponsored Merchant, or ATM owner for a minimum of two years post-agreement termination, as per Mastercard SPME §11.2.6. # Additionally, Acquirers that store, transmit, or process personal data of residents in the European Economic Area (EEA), the UK, or Switzerland—or are otherwise subject to EU Data Protection Law—must comply with the standards specified in Appendix D concerning MATCH activity within the Europe Region, consistent with Mastercard SPME §11.7.1. +# Per Mastercard SPME §2.2, Acquirers must ensure compliance with the Mastercard Secure Data Processing (SDP) Program, which requires validation of PCI DSS compliance or, alternatively, ISO/IEC 27001 certification for risk management, covering all merchant levels and service providers in their portfolio. # Per the updated Mastercard SPME §2.4.1, Acquirers are required to properly manage their PIN Entry Device (PED) and Encrypting PIN Pad (EPP) inventories. This includes maintaining an up-to-date inventory of device types and locations, ensuring devices receive timely software security patches distributed by vendors, and conducting regular physical inspections by trained staff to detect tampering or substitution. # Acquirers must also manage devices whose PCI PTS approvals have expired by moving them from approved lists to appropriate expired approval lists and ceasing their use for processing transactions if Mastercard issues a sunset date for specific device models. -# These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises.+# These controls strengthen the security posture of Acquirers in line with Mastercard's risk management directives, helping to prevent device-related compromises. --- a/policies/kyb_acquirer/policy.md +++ b/policies/kyb_acquirer/policy.md @@ -17,5 +17,6 @@ 7. Before Merchant Agreement execution or enabling transactions, conduct a MATCH inquiry using Halyard Pay's Member ID/ICA Number to ensure compliance; failure may lead to Mastercard assessments. 8. For merchants whose personal data pertains to residents of the European Economic Area, the UK, or Switzerland, Halyard Pay must comply with EU Data Protection Laws as specified in Appendix D of the Mastercard SPME manual concerning MATCH activities in the Europe Region. 9. Maintain proper management of PED and EPP device inventories, ensuring devices receive timely software security patches and are physically tracked and inspected regularly for tampering or substitution. This includes keeping an accurate inventory of device types and locations, and training staff to conduct these inspections. Any device model sunset announcements by Mastercard must be adhered to, including ceasing use of such devices by the specified deadline. +10. Ensure compliance with the Mastercard Secure Delivery Program (SDP) requirements by communicating PCI DSS or alternative ISO/IEC 27001 standards compliance obligations to merchants and service providers as applicable. Submit all required SDP compliance attestations and reports for Level 1 and Level 2 Merchants and Service Providers on schedule, and validate risk management programs for payment security within merchant portfolios. -Source authority: Mastercard SPME §§2.1, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1. +Source authority: Mastercard SPME §§2.1, 2.2, 2.4.1, 7.1, 11.2.3, 11.2.6, 11.7.1.