Payment Card Industry Data Security Standard (PCI DSS) applies to the fundraising and Peer-to-Peer portions of the Engaging Networks platform, and to our clients for whom we host pages on those parts of our platform. PCI DSS is a set of security requirements to protect environments that store, process, or transmit payment card data. Because of our open platform which allows clients to customize their templates, both Engaging Networks and our clients have a shared responsibility for the security of these pages.
We must comply with the 12 PCI DSS requirements:
If you have payment pages on the Engaging Networks platform, then you are considered a merchant, and every merchant is required to complete a self-assessment questionnaire (SAQ) at least every 12 months to report your PCI DSS status, whether you are compliant or non-compliant. The type of SAQ is determined by the volume of credit card transactions you process each year. Contact your payment gateway (eg. PayPal, Stripe) for more information.
Additionally, payment page vulnerability scans must be completed at least every 90 days by an Approved Scanning Vendor. To help reduce the scope and cost of these scans, here are some things you can do:
PCI Security Standards Organization
Where to request Engaging Networks AOC
This version was last updated on 28 Oct 2024.