Mastercard SPME release
May 2023 → Sep 2023
3 breaking and 63 substantive revisions proposed, affecting 8 policies.
breaking
3 revisions
Merchant Removal from MATCH
The entire content of the 'Merchant Removal from MATCH' section has been removed, deleting previous details on reasons and procedures for removing a Merchant listing from MATCH.
Terminal Security Standards
The section was updated to prohibit declining transactions based on BIN/IIN validation or PAN-related data checks, ensuring no card is disqualified from Interchange System processing due to these validations. It also references PIN security requirements in another section.
Franchise Management Program (FMP) Questionnaire-based Review
The previous content about completing a Coercion Program FMP questionnaire based on identifications was completely removed and replaced by detailed definitions concerning Incomplete, Invalid, or Inappropriate MCCs and criteria for qualifying Brazil-based merchants or operators based on transaction volume and use of such MCCs.
substantive
63 revisions
Connecting to Mastercard—Physical and Logical Security
The updated section emphasizes the requirement for customers and their agents to prove to Mastercard that they have effective physical and logical security controls in place for any device connecting their processing systems to the Mastercard Network, covering all related components.
Minimum Security Requirements
Additional specifications were added clarifying that cabinets housing Service Delivery Point Equipment must be locked both in front and rear at all times, with keys stored securely.
Data Protection
The section was updated to specify that Mastercard and each Customer must comply with applicable data protection laws and Appendix D privacy standards when processing personal data specifically related to account data compromise events and high-risk customer obligations, highlighting legal compliance requirements.
Compliance with Privacy, Data Protection and Information Security Requirements
The section was replaced with new introductory text for Chapter 2 on Cybersecurity Standards and Programs, expanding scope to include all Customers, Merchants, Service Providers, and agents handling payment data, removing prior specific obligations regarding compliance with data protection laws.
Should the responsible Customer cause a PFI to conduct an examination, the responsible
The updated section requires the responsible Customer to notify Mastercard within 24 hours when engaging a PFI for an investigation, with noncompliance penalties for failure. Alternatively, the Customer may investigate themselves if certain criteria are met, and must report findings, containment, and PCI DSS compliance within 20 business days. Mastercard may review and require remediation if risks persist.
Policy Concerning Account Data Compromise Events and Potential Account Data
The updated section clarifies Mastercard's authority over Account Data Compromise (ADC) Events, emphasizing that Mastercard has the final say on ADC occurrences, can impose assessments, recover costs, and enforce standards. It also details how multiple related breaches might be considered a single ADC event and advises customers to seek guidance if uncertain.
Responsibilities in Connection with ADC Events and Potential ADC Events
The section was expanded to clarify that a Customer's failure to cooperate with Mastercard investigations, including withholding information or delaying responses without good cause, may result in adverse inferences against the Customer. Mastercard must notify Customers before doing so and allows opportunities to justify noncompliance. This emphasizes cooperation requirements and potential consequences.
Time-Specific Procedures for ADC Events and Potential ADC Events
The procedures now require the Payment Forensic Investigator (PFI) to submit preliminary and final forensic reports within specified timeframes, prohibit Customers from interfering with the independence and integrity of the investigation, and allow Mastercard to engage a PFI directly at the Customer's expense to expedite investigations.
Ongoing Procedures for ADC Events and Potential ADC Events
The updated section adds a new requirement for entities to consent and cooperate with Mastercard-led investigations if the customer fails in their responsibilities, in addition to the existing obligations for remediation planning and monitoring.
Potential Reduction of Financial Responsibility
The updated section introduces specific criteria for Terminal Servicer-related ADC Events, adding detailed reporting and investigation timing requirements, plus mandatory registration and compliance confirmations. It establishes responsibilities for Terminal Servicers distinct from general customers and emphasizes timely notification and cooperation with Mastercard and law enforcement.
Determination of Fraud Recovery (FR)
The updated text clarifies when Mastercard will not assess fraud recovery for compromised U.S. Merchants using Hybrid POS Terminals, adding an effective date (1 October 2015) and specifying that this applies if certain transaction and event criteria are met. The calculation method for annual transaction count and rules for other regions remain largely unchanged.
Assessments and/or Disqualification for Noncompliance
The updated section adds specific references to sections 10.3 and 10.4, emphasizing ongoing customer obligations to submit required information during investigations. It also states that if a customer fails to provide required documents during the investigation, Mastercard will not consider such information during an appeal.
MATCH Overview
The update expands and clarifies the MATCH system's definition and categorization of possible matches, detailing exact and phonetic match criteria with specific fields and conditions, adds retroactive match procedures, and emphasizes acquirers must include Merchant URL for e-commerce inquiries.
How does MATCH search when conducting an inquiry?
The detailed tables and examples explaining exact and phonetic MATCH search criteria were removed. Instead, the section now briefly states that MATCH searches for matches based on data from the past five years and inquires from the past 360 days, covering exact and phonetic matches without specifics.
Certification
The updated section mandates that Acquirers must be officially certified by Mastercard to access and use the MATCH system, detailing the certification process and consequences of noncompliance, including penalties and fees, whereas previously only failure to enter a Merchant into MATCH was addressed.
Inquiring about a Merchant
The updated rule mandates Acquirers to check the MATCH system before signing a Merchant Agreement or enabling transaction acceptance. Failure to do so under the correct Member ID/ICA Number can lead to compliance violations and assessments, emphasizing stricter enforcement and reporting accuracy.
MATCH Reason Codes
The MATCH reason codes have been significantly revised: some previous codes were removed (e.g., Account Data Compromise, CPP, Laundering, Excessive Chargebacks/Fraud), and new codes were added, including Violation of Standards, Merchant Collusion, PCI Data Security Standard Noncompliance, Illegal Transactions, and Identity Theft, expanding the reasons for merchant listing.
Reason Codes for Merchants Listed by the Acquirer
The section replaces general violation reasons with specific, detailed MATCH reason codes including account data compromise, common point of purchase, laundering, excessive chargebacks, excessive fraud, and others, providing defined thresholds for chargebacks and fraud reporting.
Service Provider Risk Management Program
The update extensively revises the Covered Programs Privacy and Data Protection Standards appendix, adding detailed obligations for Customers and the Corporation regarding EU Data Protection Law compliance, data transfer mechanisms, security measures, breach notifications, audits, liabilities, and termination. It clarifies roles, legal bases for processing, data accuracy, and introduces detailed annexes with terms and technical security controls.
Cleared, meaning the Acquirer transferred the Transaction Data within the
The entire section titled 'Cleared, meaning the Acquirer transferred the Transaction Data within the' has been removed in the latest version of the Mastercard SPME document. This appears to be a complete deletion of content rather than an amendment or addition.
Payment Card Industry (PCI) Security Standards
The updated section removes all references to PCI PIN Security Requirements, PIN Transaction Security, Forensic Investigator Program Guide, and focuses solely on PCI Software Security Framework standards, emphasizing compliance and recommendations related only to software security for merchants and service providers.
Mastercard Site Data Protection (SDP) Program
The update defines detailed compliance and reporting responsibilities for Issuers and Acquirers concerning Level 1-4 Merchants and Service Providers under the Mastercard SDP Program, specifying submission deadlines, validation methods like PCI DSS and SAQs, risk management requirements for Acquirers, and potential cost reductions after Account Data Compromise Events.
Merchant Compliance Requirements
The update adds a requirement that Acquirers ensure Merchants transitioning between PCI levels achieve compliance with the new level within one year. It also mandates Level 1-3 Merchants using third-party payment software to validate their software's PCI compliance via the PCI SSC website. Other recommendations remain unchanged.
Mastercard Cybersecurity Incentive Program (CSIP)
The section has been extensively revised to introduce the Mastercard Cybersecurity Incentive Program (CSIP), which offers eligible merchants reduced PCI compliance validation or exemption through secure technologies like EMV, P2PE, or tokenization. It replaces and expands former rules with detailed certification requirements and thresholds based on transaction types and regions.
SDP Program Noncompliance Assessments
The updated section adds detailed requirements for compromised entities to complete a Site Data Protection Account Data Compromise Information Form within 30 days, and sets specific PCI DSS compliance deadlines with required evidence submission to Mastercard by email. It specifies different deadlines and evidence types based on entity classification (Service Provider, Level 1/2 Merchants, Level 3/4 Merchants).
Mandatory Compliance Requirements for Compromised Entities
The update adds that merchants with a confirmed Account Data Compromise (ADC) event may be reclassified as Level 1 and must follow related compliance and noncompliance rules. It clarifies noncompliance consequences for Service Providers, including reclassification and delisting, and states that extension requests for PCI DSS deadlines will not be approved.
Card Production Security Standards
The updated section adds details about the GVCP certification process for vendor facilities, including annual security assessments, issuance of compliance certifications, and a publicly available list of certified vendors. Existing terms about vendor agreements and data safeguarding remain unchanged.
PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
The updated section adds explicit requirements for Acquirers to manage PED and EPP inventories by identifying device types and locations and having trained staff conduct inspections. It also introduces Mastercard’s authority to mandate risk mitigation actions, including device model sunsetting in case of security threats, prohibiting use after a sunset date.
Consumer Device Cardholder Verification Methods
The update adds new requirements for Connected Consumer Devices (requiring consent on the device used), mandates strong device integrity checks during CDCVM use, and allows optional suppression of CDCVM for contactless transit transactions identified via specific MCC codes or authorization message data.
Persistent Authentication
The updated section now explicitly requires the device used in persistent authentication to prompt the cardholder for explicit consent before a transaction, and mandates compliance with Mastercard Standards for consumer authentication technology, adding specific compliance and consent obligations.
Use of a Vendor
The text has changed from detailing specific transaction authentication requirements to emphasizing that any agreement with a vendor providing CDCVM services must ensure the vendor agrees to protect personal information and comply with all relevant standards.
Acquirer Information
The section now requires acquirers to ensure Hybrid Terminals do not reject transactions solely due to service codes on the magnetic stripe, with specific conditions for certain codes and regions. Authorization must be obtained for magnetic stripe-read transactions in Europe when certain service codes are present.
Personal Identification Numbers (PINs)
The updated section removes the initial general compliance statement and adds explicit requirements that all PIN encryption, translation, and decryption must be performed using hardware encryption only, prohibiting software-based methods. Additionally, it advises Issuers to consult Issuer PIN Security Guidelines for comprehensive PIN management practices.
Multi-Factor Authentication Methods for Remote Commerce Token Transactions
The updated section adds requirements for security evaluation and qualification of MFA methods as high or low assurance, mandates Mastercard approval for low assurance methods, and specifies audit requirements under PSD2 RTS and UK Standards, impacting issuer reliance on fraud deterrence.
Multi-Factor Authentication Method Functionality
The updated section expands MFA requirements by mandating that both authentication and explicit consent occur before a transaction, details timing options for authentication, adds requirements for device integrity protections, and specifies measures for failed authentication attempts, including limits, blocks, notification, and re-verification processes.
Prolonged Authentication
The requirement that a successful Prolonged Authentication depends on an initial MFA authentication before cardholder access to stored credentials has been removed, focusing the rules solely on testing consent, authentication factor, and a five-minute open period.
Triple DES Standards
The section was extensively rewritten to mandate Triple DES encryption for all newly installed payment entry devices (PEDs) and host systems, require compliance for ATM encrypting PIN pads (EPPs), and transactions routed to Interchange. It also allows Mastercard-approved alternate encryption methods, replacing prior unrelated text on authentication factors.
Card Retention by Merchants
The updated section adds detailed procedures for returning recovered cards, including mandatory destruction of the card by cutting it vertically, a five-day return deadline with an accompanying recovery form, and specific handling instructions for cards inadvertently left by cardholders or counterfeit cards.
ATM Card Retention
The section adds detailed procedures for handling retained ATM cards, including logging, destruction, optional retention of suspected fraudulent cards, and conditions for returning cards to cardholders. It introduces explicit requirements on documentation, security, notifications to issuers, and prohibits fees to issuers for card retention or return.
Payment of Rewards
The section changed from a general statement about optional reward payments to detailed rules about administrative fees for processing captured cards, specific fee amounts for USD and EUR zones, procedures for fee reimbursement using Fee Collection messages, and conditions for reward payment chargebacks.
of the Mastercard Rules manual (“the Illegal or Brand-damaging Transactions Rule”).
The section 5.11.7 was added to the manual, introducing content about Mastercard's Illegal or Brand-damaging Transactions Rule where there was none before.
Mastercard Fraud Loss Control Program Standards
The update clarifies that several fraud control measures are recommended but not always mandatory. It introduces specific thresholds and detailed monitoring requirements, especially regarding BIN attacks, ATM fraud, negative option billing, 3-D Secure monitoring, and ongoing fraud and transaction monitoring. Additional recommended tools and policies for acquirers are also detailed.
Acquirer Fraud Loss Control Programs
The section updates the title and adds a new requirement effective 13 October 2023 for Europe Region Acquirers (with specific country exclusions) mandating strong authentication (EMV 3DS authentication or equivalent SCA) at Credential storage, wallet/token creation, or the first post Card-add transaction.
Assessments for Noncompliance with Screening Procedures
The revised section adds a recommendation for Acquirers in specific European countries to ensure wallets detect fraud signals, such as many top-ups or cryptocurrency purchases, and limit the number of cards that can top-up an account. The existing requirements for re-performing onboarding screening procedures remain unchanged.
Ongoing Monitoring
The updated section adds requirements for Acquirers to regularly review e-commerce Merchants' websites and business activities to ensure compliance with Standards and recommends using monitoring solutions to prevent illegal or harmful transactions. It also clarifies that monitoring includes fraud loss controls related to deposits and authorizations per section 6.2.2.
Additional ECM and HECM Requirements
The updated section removes the detailed criteria for defining linked accounts and Questionable Merchants, replacing it with a new provision allowing Mastercard to advise Acquirers on risk mitigation or require a Franchise Management Program Customer Risk Review after a Merchant has been classified as ECM/HECM for six months.
Questionable Merchant Audit Program (QMAP)
The updated QMAP section replaces the previous general description with specific, detailed criteria to identify a Questionable Merchant, including transaction volume thresholds, number of transactions, and detailed fraud metrics. It defines the Case Scope Period and clarifies Mastercard's sole discretion in designating a merchant as questionable.
QMAP Definitions
The section changed from describing general criteria for identifying a Questionable Merchant to providing detailed definitions of 'Cardholder bust-out account' including specific conditions and indicators linking accounts to potential fraud and merchant investigation triggers.
Mastercard Commencement of an Investigation
The updated section specifies procedures for Issuers to notify Mastercard via a web-based form if a Merchant is deemed questionable, detailing required information to be provided. It also introduces the possibility of a filing fee for Issuer notifications and requires Acquirers to promptly notify Mastercard if acquiring for a Questionable Merchant.
Mastercard Notification to Acquirers
Mastercard will notify Acquirers by email if a Merchant meets criteria as a Questionable Merchant based on fraud reports. Acquirers have 15 days to contest and must provide supplemental information. Mastercard may audit Acquirer records and request additional information. Documentation must be submitted via a specified email.
Mastercard Determination
The section was expanded to specify conditions under which Mastercard evaluates fraudulent transactions at Questionable Merchants, detailing thresholds for issuer fraud volume, recovery through existing remedies, and card functionality. It also clarifies Mastercard's rights regarding information requests, payment limits, and the processing of fraud recoveries between Acquirers and Issuers.
Chargeback Responsibility
The updated rules specify that when Mastercard identifies a Questionable Merchant, the Acquirer is responsible for valid chargebacks with reason code 4849 for at least one year after announcement. Issuers have 120 days from the announcement to charge back fraudulent transactions within this period, and Mastercard may extend this responsibility period.
Investigation Process
The updated text adds a requirement that issuers must notify cardholders within 10 days of notification to provide a police report or explanation if unavailable, enhancing issuer follow-up procedures in alleged coercion investigations.
MATCH Reporting
The rules now specify that merchants meeting the Coercion Program criteria are added to MATCH under reason code 24 (Illegal Transactions). Subsequent coercion claims within 12 months lead to updating or deleting MATCH records based on claim confirmation.
Mastercard Notification to Acquirers
The section was replaced with detailed tables outlining non-performance assessments for acquirers based on Brazil GCMS domestic transaction volume and the number of violations within twelve months. It also added mitigation options for assessments and introduced issuer interchange recovery procedures related to MCC miscoding cases.
Mastercard Determination
The notification from Mastercard to issuers and acquirers now specifies whether the issuer's claim was substantiated or not, including details on associated fees and recovery amounts, rather than only stating that the investigation is closed and the issuer's claim status.
Assessments, Recovery Amounts, and Fees
The section was revised to remove detailed penalty tiers for acquirers and mitigation guidelines, replacing them with a high-level overview of three fee components and adding a new issuer filing fee for unsubstantiated claims. It simplifies and restructures the content, eliminating specific penalty amounts and procedures for assessments and recovery.
General Registration Requirements
The updated rules introduce financial penalties for Acquirers who fail to register Merchants or Sponsored Merchants as required, including initial fines up to $10,000 and escalating monthly fines for continued non-compliance after a 10-day notice period, emphasizing prompt correction and adherence to Mastercard rules.
General Monitoring Requirements
The revised section replaces general monitoring rules for risky transactions with detailed registration and content control requirements specifically for adult content merchants, including agreements with content providers, verification of age and identity, content review, and complaint handling processes.
Non-face-to-face Adult Content and Services Merchants
The updated rules require Merchants to allow individuals depicted in content to appeal for its removal and establish consent. Merchants must report flagged content and complaints monthly to Acquirers, who share with Mastercard. Merchants must not use illegal adult content to attract users, implement anti-trafficking policies, and provide Acquirers temporary site access for review upon request.
Skill Games Merchants
The update emphasizes that the Acquirer must explicitly confirm it will not submit Restricted Transactions from the Merchant and requires Mastercard approval before processing any skill games transactions for the Merchant or related entities.
High-Risk Securities Merchants
The updated rules require Acquirers to ensure Merchants maintain lawful status, keep permits valid, provide third-party certification on system controls, promptly notify Mastercard of changes, and affirm they won't submit restricted transactions. Additionally, certain regulated non-face-to-face securities activities must be registered as gambling merchants.
Cryptocurrency Merchants
The updated section adds requirements for Acquirers to identify cryptocurrency transactions with specific codes and mandates verification of full compliance with all relevant laws, supported by legal opinions or third-party accreditation, upon registering crypto merchants. The original requirement to maintain such verification and provide documentation upon request remains.