PCI Compliance Vendors

Options
Hi folks,



Several years ago (probably around 2009 or 2010) we were told that we had to be PCI compliant or Convio would bill us $150 per year until we became PCI compliant. At the time, they recommended a company called Security Metrics to handle PCI compliance for Convio customers at $100 per year. Of course, it was a no-brainer to sign up with them.

 

We have been with Security Metrics ever since and every year they raise their prices significantly. Our latest renewal is over double was it was last year at $1,200 (from about $500.) And I became suspicious when they pushed to get a credit card immediately over the phone and offered a "security policy template" for only $250 if we don't already have one in-house.



Of course, we've had no warning about this increase and I'll have quite a bit of explaining to do to my finance department. :(



What vendors do others use and/or are they happy with them? Do the prices I list above sound reasonable?



Thanks for any advice!
Tagged:

Comments

  • Hi folks,



    My mistake... It was actually IATS, our merchant, that required PCI Compliance and suggested Security Metrics. We've contacted them and they are now recommending PCI Rapid Comply that seems much easier and tremendously less expensive.



    For anyone following the thread, I'll let you know how it pans out!



    Best,

    Jen
  • Hi Jen,


    We're over in the UK, and also using Security Metrics. We are struggling with their requests. All of our Payments are processed by BBIS/BBCRM.They are asking us specifically for a Merchant ID. Though Blackbaud KB suggests BBMS has no Merchant ID:


    https://kb.blackbaud.com/articles/Article/58869


    Security Metrics are now informing us that we are not compliant. All very confusing, if you have any advice that would be super. 


    Thanks, Reza.




     

Categories