If my organization is not a level 1 merchant, does that mean the only requirement I have to fulfill is obtaining a quarterly external network scan?
No, every organization that transmits, stores or processes credit card data must fulfill all of the requirements enumerated by the PCI DSS. While level 1 merchants are currently the only organizations that are required to perform an annual on-site audit to verify PCI DSS compliance, all merchants are expected to implement the PCI DSS requirements in full.
Related Questions
- If my organization is not a level 1 merchant, does that mean the only requirement I have to fulfill is obtaining a quarterly external network scan?
- The World Health Organization has indicated that the overall level of severity of the pandemic was moderate. What does this mean?
- What is the Level 0 Clinic, and does it fulfill the clinic requirement?