- Job title
- Store Manager
- Sector
- Catering
- Organization type
- 20-person company
- Joined
- Mar 2024
- Message
- 132
We have two brick-and-mortar retail stores in Bursa and an online store running on a turnkey platform. In the stores, we use physical POS terminals provided by banks, while on our website, the payment step is completed via an iframe from a licensed third-party payment gateway.
The other day, we got an informational email from the bank we use for our virtual POS. It says that for PCI DSS compliance, we need to fill out a self-assessment questionnaire and upload it to their system, otherwise POS commission rates could increase or the service might be suspended.
This is the first time I'm seeing this term. What exactly is PCI DSS? We do not store card numbers anywhere on our own servers or in our stores; the card details are handled entirely on the payment gateway's screen. Despite that, what does this standard require from an SME like us, and what are we supposed to declare to the bank?