What usually happens to a Merchant who has been designated as a CPP?
The Payment Brand and/or Acquiring Bank will usually require a forensic investigation be conducted by a QSA to detect and mitigate the cause(s) of the compromise. If the Merchant is determined to be out of compliance with the PCI-DSS during this investigation, the Merchant will also usually incur fines, penalties, charge backs, etc. that are not insignificant.