Mastercard SPME release
Feb 2024 → Sep 2024
5 breaking and 23 substantive revisions proposed, affecting 8 policies.
breaking
5 revisions
Policy Concerning Account Data Compromise Events and Potential Account Data
The section content has been removed entirely with no replacement text in the August 2024 edition, indicating a full deletion of the previous policy on account data compromise events.
Time-Specific Procedures for ADC Events and Potential ADC Events
The detailed requirements for submitting preliminary and final forensic reports, restrictions on customer conduct during investigations, and responsibilities for investigation costs have been removed from this section.
Ongoing Procedures for ADC Events and Potential ADC Events
The section previously listing specific responsibilities for cooperation with investigations and remediation plans related to ADC Events has been entirely removed without replacement.
Alternative Acquirer Investigation (AAI) Standards
The entire detailed process and penalties related to remediation action plans and repeated ADC events, including timelines and independent examinations, were removed, leaving only a statement that Mastercard retains its rights to require forensic examinations and that other obligations continue as previously set.
Mastercard Commencement of an Investigation
The section on how Mastercard notifies Issuers during QMAP investigations was removed or replaced; previously detailed processes for bust-out and non-bust-out investigations, including specific reporting codes and Brazil-specific procedures, are no longer present in this version.
substantive
23 revisions
Should the responsible Customer cause a PFI to conduct an examination, the responsible
The change adds a new subsection specifically for Card-present Alternative Acquirer Investigations, extending the investigation reporting deadline from 20 to 30 business days and clarifying requirements for responsible Customers choosing to investigate instead of engaging a PFI.
Applicability and Defined Terms
Added new definitions for "Potential Account Data Compromise Event" and "Qualified Forensic Investigator" to clarify roles and events related to account data compromise. Minor formatting changes were made to references for terms in the Definitions appendix.
Responsibilities in Connection with ADC Events and Potential ADC Events
The updated section mandates Customers and Agents to notify Mastercard within 24 hours of any ADC Event or Potential ADC Event and outlines specific immediate actions including thorough investigations, evidence preservation, and timely reporting of compromised PANs. It introduces precise timelines and procedural requirements, reflecting a more prescriptive approach compared to the prior more general guidance.
Forensic Report
The revised section requires the responsible Customer or Agent to ensure the PFI retains all draft forensic reports related to ADC events and provides them to Mastercard upon request. Mastercard may also require a PCI gap analysis included in the final report, and the PFI must submit preliminary and final reports promptly to Mastercard.
Mastercard Determination of ADC Event or Potential ADC Event
The updated section clarifies detailed requirements for terminal servicer compliance and reporting related to ADC events, including PCI DSS validation, timely registration through Mastercard Connect, notification protocols, forensic investigation timing, and measures for reducing financial responsibility. It stresses the need for complete customer contact data and cooperation with investigations.
Potential Reduction of Financial Responsibility
The revised section broadens the scope from specifically terminal servicers to any compromised entity, replacing Terminal Servicer (TS) references with Merchant and clarifying requirements. The compliance demonstration shifts slightly, including updated references to programs and reporting obligations, but obligations to report, cooperate, and remediate remain. Responsibility monitoring via My Company Manager references was removed.
Determination of Operational Reimbursement (OR)
The update adds specific criteria for halving or waiving Operational Reimbursement (OR) amounts for US and Canada merchants affected by Account Data Compromise (ADC) events, based on tokenization rates, ecommerce transaction percentages, absence of prior ADC events, and storage of sensitive authentication data. It also clarifies OR determination for other regions remains unchanged.
Assessments and/or Disqualification for Noncompliance
The updated section introduces a formal appeal process for Customers contesting Mastercard's financial responsibility determinations related to Account Data Compromise Events, including a non-refundable $5,000 fee for review, timing requirements, and conditions for consideration of appeals. It clarifies appeal submission criteria and finality of decisions, plus continued Customer obligations during investigations.
Merchant Compliance Requirements
The update adds that Level 1-3 Merchants must validate all third-party payment applications/software against PCI SSC listings. It clarifies that Level 3 and 4 Merchants' PCI DSS compliance validation to Mastercard is not required unless by law, though completing an SAQ or ROC is still encouraged. Other content remains largely unchanged.
Service Provider Compliance Requirements
The updated section clarifies service provider categories and compliance frequency: 3-DSSP compliance validation with the 3DS Core Security Standard is now required every two years instead of annually, and AML/Sanctions Service Providers are reclassified between Level 1 and Level 2 with adjusted requirements. Minor category order changes also occur.
Mastercard Cybersecurity Incentive Program (CSIP)
The CSIP now explicitly includes MPOS EMV acceptance solutions like SPoC, CPoC, and MPoC among eligible secure technologies. The PCI DSS Risk-based Approach references a new source for milestones. The Exemption Program adds options to qualify via MPOS EMV acceptance solutions and clarifies compliance validation exemptions unless prohibited by law.
SDP Program Noncompliance Assessments
The section was completely revised to replace the previous penalty tier tables with new detailed procedures for forensic investigation follow-up. It mandates submission of a specific form, evidence of PCI DSS compliance within defined deadlines by merchant or service provider category, and states non-approval of extension requests. Noncompliance may lead to assessments under this section.
Mandatory Compliance Requirements for Compromised Entities
The updated rules add that any Merchant with a confirmed ADC Event may be reclassified as Level 1 with all related compliance requirements. For Service Providers, it clarifies that DESV appendix compliance must be validated to Mastercard once, post-forensic investigation, refining re-listing conditions.
Card Production Security Standards
The updated section introduces a requirement for a security assessment and certification of vendor facilities under the GVCP, including annual certification renewal and publication of certified vendors in a Mastercard Announcement, before an Issuer can engage such a vendor for card production services.
Additional Card Production Requirements
New requirements were added stipulating that the issuer must verify card shipment quantities upon receipt, resolve discrepancies immediately, and may audit and reseal cartons. Existing procedures for reporting card loss or theft and disposing of unissued cards remain unchanged.
PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)
The update adds requirements for acquirers to manage PED/EPP devices under a device management system that ensures receipt of security patches and physical management. It also clarifies that devices with expired PCI PTS approvals move to a specific list, enhancing inventory management and device security obligations.
Mastercard Fraud Loss Control Program Standards
The update adds recommended temporary BIN attack mitigation measures for Acquirers in Europe (excluding certain countries), including use of CVC2, CAPTCHA, and merchant blocking. It also introduces enhanced ongoing monitoring guidelines for e-commerce, recurring payments, and Sponsored Merchants, especially in Europe, plus clarifies some wording around attack analysis and monitoring parameters.
Assessments for Noncompliance with Screening Procedures
The updated section adds a recommendation for Crypto Merchants and Digital Wallets to block Crypto purchase and funding transactions if the cardholder's family name differs from the account holder's family name, specifying that merchants should request the exact name from the card as printed. Other wording clarifications and section references were also updated.
ECP Definitions
The definition and explanation of 'Basis Points' in the ECP definitions section was removed entirely, eliminating how basis points are calculated based on chargebacks and transactions.
Questionable Merchant Audit Program (QMAP)
The criteria defining Questionable Merchants for Brazil were revised. Previously, the criteria applied directly, but now, at least three of four specific conditions must be met during the Case Scope Period, aligning Brazil's criteria with the general structure. This change clarifies and formalizes the assessment threshold for Brazil-specific cases.
Chargeback Responsibility
The revised section removes details about the issuer's 120-day period to chargeback fraudulent transactions and the possibility of Mastercard extending the chargeback responsibility period, leaving only the acquirer's responsibility for valid chargebacks using reason code 4849 for one year.
Fraud Recovery
The updated section adds conditions around administrative fees related to the QMAP investigation, specifying when Mastercard may or may not charge fees to Issuer accounts, while retaining the audit fee charge to Acquirers for identifying Questionable Merchants.
Investigation Process
The specified 120 calendar day investigation period around the alleged coercive event has been shortened by removing the explanation that it includes 60 days before and after the event and Mastercard's discretion to expand the period.