Hi Christian,
About 90% of the PCI compliance audit involves your hosting environment, physical security, firewall, windows server, iis, sql server, DotNetNuke, windows security/permissions, etc, etc. The other 10% involves the shopping cart.. If your credit card processing company requires PCI certification on your site before they issue your merchant account, you will need to hire a company that does PCI audits and they will run an audit of your hosting environment, DNN portal and cart and will issue your business a PCI certificate which you can then give to the company you are working with on your merchant account. Most merchant account providers dont require a seperate PCI audit is usually is only required for high risk businesses or non US sites.
Alternatively, if your business is categorized as a high risk business, the following options would eliminate the requirement for a PCI audit to process credit cards on your site:
1. Configure your cart to not save credit cards (in payment setup screen)
2. Use one of the many hosted payment gateways integrated in Smith Cart where your site will not handle credit cards.
Please see the following link for more info on Smith Cart PCI compliance:
http://www.smith-consulting.com/Products/PCICompliance.aspx
Scott Kelly
Project Manager
|
|