How long have these requirements been in place and how do I find out which companies offer products validated against the Payment Application Data Security Standard?
The first set of requirements for payment applications were introduced in April 1, 2000 by Visa and were commonly known as the Cardholder Information Security Program (CISP). In 2004, Aloha POS was the first restaurant POS product to be certified against the CISP requirements. Since then, various other restaurant POS system vendors have also had their applications validated and a list can be found at https://www.pcisecuritystandards.org/security_standards/vpa/.
Related Questions
- What is the relationship between the PCI Data Security Standard and the Payment Application Data Security Standard (PA-DSS) and PIN Transaction Security (PTS) Device requirements?
- Does installing a PA-DSS validated payment processing application satisfy all of the PCI-DSS requirements?
- How do I know if my application requires a PA-DSS (Payment Application Data Security Standard) Assessment?