<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: First Data PCI Compliance fee</title>
	<atom:link href="http://3dmerchant.com/blog/merchant-processing-security/pci-compliance-merchant-processing-security/first-data-pci-compliance-fee/feed/" rel="self" type="application/rss+xml" />
	<link>http://3dmerchant.com/blog/merchant-processing-security/pci-compliance-merchant-processing-security/first-data-pci-compliance-fee/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=first-data-pci-compliance-fee</link>
	<description>Merchant card processing or credit card processing tips, for large businesses and non-profits to lower the cost of payment processing. Advanced material for CFO\'s and controllers.</description>
	<lastBuildDate>Thu, 29 Mar 2012 11:02:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: cspeedy</title>
		<link>http://3dmerchant.com/blog/merchant-processing-security/pci-compliance-merchant-processing-security/first-data-pci-compliance-fee/#comment-4088</link>
		<dc:creator>cspeedy</dc:creator>
		<pubDate>Tue, 29 Nov 2011 15:24:11 +0000</pubDate>
		<guid isPermaLink="false">http://3dmerchant.com/blog/?p=189#comment-4088</guid>
		<description>HI Dana
I haven&#039;t heard of a $189 fee or an increase yet from anyone else. 
Something is amiss with what&#039;s going on in your account. 
When you pay your processor the fee, you login to Security Metrics and should not be charged another fee. It sounds like you&#039;ve signed up at SM and are paying them. Therefore, the certification is not getting back to FD. When there is a mix up, contact your processor. 
$19.99 is because the processor does not have a record of the completed certification. 

If you&#039;re switching, contact me for options. We can help.</description>
		<content:encoded><![CDATA[<p>HI Dana<br />
I haven&#8217;t heard of a $189 fee or an increase yet from anyone else.<br />
Something is amiss with what&#8217;s going on in your account.<br />
When you pay your processor the fee, you login to Security Metrics and should not be charged another fee. It sounds like you&#8217;ve signed up at SM and are paying them. Therefore, the certification is not getting back to FD. When there is a mix up, contact your processor.<br />
$19.99 is because the processor does not have a record of the completed certification. </p>
<p>If you&#8217;re switching, contact me for options. We can help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brains auto center</title>
		<link>http://3dmerchant.com/blog/merchant-processing-security/pci-compliance-merchant-processing-security/first-data-pci-compliance-fee/#comment-2800</link>
		<dc:creator>Brains auto center</dc:creator>
		<pubDate>Tue, 11 Oct 2011 03:01:30 +0000</pubDate>
		<guid isPermaLink="false">http://3dmerchant.com/blog/?p=189#comment-2800</guid>
		<description>First data charged me also.what a scam,I am changing services and also going to complaining  to SAMs wholesale where I got the services threw</description>
		<content:encoded><![CDATA[<p>First data charged me also.what a scam,I am changing services and also going to complaining  to SAMs wholesale where I got the services threw</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: POFFMERCHANT</title>
		<link>http://3dmerchant.com/blog/merchant-processing-security/pci-compliance-merchant-processing-security/first-data-pci-compliance-fee/#comment-2481</link>
		<dc:creator>POFFMERCHANT</dc:creator>
		<pubDate>Thu, 15 Sep 2011 17:26:09 +0000</pubDate>
		<guid isPermaLink="false">http://3dmerchant.com/blog/?p=189#comment-2481</guid>
		<description>I became compliant and First Data still kept charging the fee  for months.  I had to relentlessly call them and security matrix to find out why this was happening.  Each person I spoke with came up with a different reason for the continued charges, which has assured me this charge has been bogus since the day it started.  First Data agreed to refund me a portion of this fee, which is a total admission on their part the fees for PCI are bogus.</description>
		<content:encoded><![CDATA[<p>I became compliant and First Data still kept charging the fee  for months.  I had to relentlessly call them and security matrix to find out why this was happening.  Each person I spoke with came up with a different reason for the continued charges, which has assured me this charge has been bogus since the day it started.  First Data agreed to refund me a portion of this fee, which is a total admission on their part the fees for PCI are bogus.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: daniel</title>
		<link>http://3dmerchant.com/blog/merchant-processing-security/pci-compliance-merchant-processing-security/first-data-pci-compliance-fee/#comment-2402</link>
		<dc:creator>daniel</dc:creator>
		<pubDate>Thu, 01 Sep 2011 21:17:51 +0000</pubDate>
		<guid isPermaLink="false">http://3dmerchant.com/blog/?p=189#comment-2402</guid>
		<description>We run a small hair salon that does maybe $15k worth of visa transactions annually. We have a dial up card reader, no internet connection, and store none of our records digitally. Our receipts are handled by me and nobody else. Yet I have to pay 129 bucks a year to fill out a three-line survey on a website, none of the questions from which apply to my business. 

What a ripoff. </description>
		<content:encoded><![CDATA[<p>We run a small hair salon that does maybe $15k worth of visa transactions annually. We have a dial up card reader, no internet connection, and store none of our records digitally. Our receipts are handled by me and nobody else. Yet I have to pay 129 bucks a year to fill out a three-line survey on a website, none of the questions from which apply to my business. </p>
<p>What a ripoff.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 3D Merchant admin</title>
		<link>http://3dmerchant.com/blog/merchant-processing-security/pci-compliance-merchant-processing-security/first-data-pci-compliance-fee/#comment-2400</link>
		<dc:creator>3D Merchant admin</dc:creator>
		<pubDate>Thu, 01 Sep 2011 02:23:30 +0000</pubDate>
		<guid isPermaLink="false">http://3dmerchant.com/blog/?p=189#comment-2400</guid>
		<description>Sorry for your troubles- make sure you work with them until you pass to avoid monthly fees as well as liability should you have a data breach. As a last resort, if you can&#039;t resolve that, contact Christine here at 3D Merchant Services for an alternative processor that does not use Security Metrics, though I strongly recommend everyone use a 3rd party service for protection. It&#039;s an added layer you can use in your defense should you ever be accused of a data breach. 

My scan passed yet again on Friday. Here&#039;s the email excerpt-  Site Certification Pass- Your scan (ID---------09) has completed for the following Site Certification:
IP Address: -------------3
Domain Name: -----------------
SCID: ----------------

Congratulations, your scan passed!  If &#039;------------------&#039; is a publicly accessible web site, you may now place the SecurityMetrics Site Certified logo on that specific website.  This logo helps increase consumer confidence and spending.  See your latest passing scan results and select the &quot;Add Site Certified Logo Instructions&quot; link.

If you are participating in the merchant compliance program, you should log into your account and ensure that you have completed all your compliance requirements.</description>
		<content:encoded><![CDATA[<p>Sorry for your troubles- make sure you work with them until you pass to avoid monthly fees as well as liability should you have a data breach. As a last resort, if you can&#8217;t resolve that, contact Christine here at 3D Merchant Services for an alternative processor that does not use Security Metrics, though I strongly recommend everyone use a 3rd party service for protection. It&#8217;s an added layer you can use in your defense should you ever be accused of a data breach. </p>
<p>My scan passed yet again on Friday. Here&#8217;s the email excerpt-  Site Certification Pass- Your scan (ID&#8212;&#8212;&#8212;09) has completed for the following Site Certification:<br />
IP Address: &#8212;&#8212;&#8212;&#8212;-3<br />
Domain Name: &#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
SCID: &#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>Congratulations, your scan passed!  If &#8216;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8217; is a publicly accessible web site, you may now place the SecurityMetrics Site Certified logo on that specific website.  This logo helps increase consumer confidence and spending.  See your latest passing scan results and select the &#8220;Add Site Certified Logo Instructions&#8221; link.</p>
<p>If you are participating in the merchant compliance program, you should log into your account and ensure that you have completed all your compliance requirements.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick M</title>
		<link>http://3dmerchant.com/blog/merchant-processing-security/pci-compliance-merchant-processing-security/first-data-pci-compliance-fee/#comment-2392</link>
		<dc:creator>Patrick M</dc:creator>
		<pubDate>Tue, 30 Aug 2011 04:48:21 +0000</pubDate>
		<guid isPermaLink="false">http://3dmerchant.com/blog/?p=189#comment-2392</guid>
		<description>Security Metrics provided us with a list of TCP and UDP ports on our corporate IP address that are in violation and therefore, resulted in a fine. However, we had several scans done and could not find any such ports that yield a security risk. Additionally, we could not find any ports open that they reported. Further more, gateways simply do not provide any open ports in the first place. After I talked with them directly and finally got someone who even knew what a port is, they told me that the scan may not be accurate and that it is generally an approximation because they could not do anything but ping a customers Gateway to a LAN. What a scam! I too will assist in any class action lawsuit as well. meanwhile Visa MC is cashing in on us.</description>
		<content:encoded><![CDATA[<p>Security Metrics provided us with a list of TCP and UDP ports on our corporate IP address that are in violation and therefore, resulted in a fine. However, we had several scans done and could not find any such ports that yield a security risk. Additionally, we could not find any ports open that they reported. Further more, gateways simply do not provide any open ports in the first place. After I talked with them directly and finally got someone who even knew what a port is, they told me that the scan may not be accurate and that it is generally an approximation because they could not do anything but ping a customers Gateway to a LAN. What a scam! I too will assist in any class action lawsuit as well. meanwhile Visa MC is cashing in on us.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lady T</title>
		<link>http://3dmerchant.com/blog/merchant-processing-security/pci-compliance-merchant-processing-security/first-data-pci-compliance-fee/#comment-2236</link>
		<dc:creator>Lady T</dc:creator>
		<pubDate>Thu, 30 Jun 2011 01:02:05 +0000</pubDate>
		<guid isPermaLink="false">http://3dmerchant.com/blog/?p=189#comment-2236</guid>
		<description>I&#039;m waiting for that class action lawsuit as well.  

I understand completely why the credit card companies and processors want merchants to understand compliance and BE compliant, but the SAQ&#039;s are available for free online from the PCI Security Standards Council.  This is the body that makes all the rules, and according to them a complete SAQ is all that is needed from small businesses like ours that don&#039;t process cc information online and have no POS.  

I got hoodwinked by an acquirer who said we could use the SAQ for self-attestation of compliance and then denied it once we established an account.  They sent me to Security Metrics where I completed the EXACT SAME questionnaire online - then they denied that too! In the meantime they&#039;re charging us $19.95 a month PLUS they slapped a $99 annual compliance fee on us, and for what? What are we paying for? The privilege of filling out a questionnaire that I can (and did!) get for free elsewhere?

The credit card companies themselves (Visa, MC, etc) insist that acquirers validate their customer&#039;s compliance, but they have nothing to do with the fees.  It&#039;s totally arbitrary, just another way to make a profit.  Most customers won&#039;t even look that closely at their statements, and those that do will be made to believe this is some kind of law and/or the fees are simply handed down from the top, but they&#039;re simply not.  There needs to be some regulation of this industry, to protect businesses from predatory practices like this.

I&#039;m told there&#039;s a government agency in the works to do just that.  Maybe help is on the way?  Let&#039;s hope.</description>
		<content:encoded><![CDATA[<p>I&#8217;m waiting for that class action lawsuit as well.  </p>
<p>I understand completely why the credit card companies and processors want merchants to understand compliance and BE compliant, but the SAQ&#8217;s are available for free online from the PCI Security Standards Council.  This is the body that makes all the rules, and according to them a complete SAQ is all that is needed from small businesses like ours that don&#8217;t process cc information online and have no POS.  </p>
<p>I got hoodwinked by an acquirer who said we could use the SAQ for self-attestation of compliance and then denied it once we established an account.  They sent me to Security Metrics where I completed the EXACT SAME questionnaire online &#8211; then they denied that too! In the meantime they&#8217;re charging us $19.95 a month PLUS they slapped a $99 annual compliance fee on us, and for what? What are we paying for? The privilege of filling out a questionnaire that I can (and did!) get for free elsewhere?</p>
<p>The credit card companies themselves (Visa, MC, etc) insist that acquirers validate their customer&#8217;s compliance, but they have nothing to do with the fees.  It&#8217;s totally arbitrary, just another way to make a profit.  Most customers won&#8217;t even look that closely at their statements, and those that do will be made to believe this is some kind of law and/or the fees are simply handed down from the top, but they&#8217;re simply not.  There needs to be some regulation of this industry, to protect businesses from predatory practices like this.</p>
<p>I&#8217;m told there&#8217;s a government agency in the works to do just that.  Maybe help is on the way?  Let&#8217;s hope.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Semyon</title>
		<link>http://3dmerchant.com/blog/merchant-processing-security/pci-compliance-merchant-processing-security/first-data-pci-compliance-fee/#comment-2227</link>
		<dc:creator>Semyon</dc:creator>
		<pubDate>Fri, 17 Jun 2011 04:32:10 +0000</pubDate>
		<guid isPermaLink="false">http://3dmerchant.com/blog/?p=189#comment-2227</guid>
		<description>After reading all the posts and the Administrator&#039;s answers - I am coming to conclusion that PCI compliance fee is bogus and outright rip-off.  What is the purpose of paying $129 (usually - because $79 is almost always marked up) if the only transactions the merchant does are through dummy terminal?  No names and full CC numbers are printed. What expenses does Merchant Account Provider endure in this case? None.  
There are two problems with CC transaction security, thou:
1) The Merchant Account Providers are having direct access to merchant&#039;s bank account. They will do anything to debit those accounts justifying it by any reasons and ridiculous fees.
2) 99% of every online fraud are caused by insiders ( they can be Merchant Account Provider&#039;s employees as well)  - so paying any fees to the same people who potentially can do the most harm is a double nonsense.</description>
		<content:encoded><![CDATA[<p>After reading all the posts and the Administrator&#8217;s answers &#8211; I am coming to conclusion that PCI compliance fee is bogus and outright rip-off.  What is the purpose of paying $129 (usually &#8211; because $79 is almost always marked up) if the only transactions the merchant does are through dummy terminal?  No names and full CC numbers are printed. What expenses does Merchant Account Provider endure in this case? None.<br />
There are two problems with CC transaction security, thou:<br />
1) The Merchant Account Providers are having direct access to merchant&#8217;s bank account. They will do anything to debit those accounts justifying it by any reasons and ridiculous fees.<br />
2) 99% of every online fraud are caused by insiders ( they can be Merchant Account Provider&#8217;s employees as well)  &#8211; so paying any fees to the same people who potentially can do the most harm is a double nonsense.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 3D Merchant admin</title>
		<link>http://3dmerchant.com/blog/merchant-processing-security/pci-compliance-merchant-processing-security/first-data-pci-compliance-fee/#comment-2223</link>
		<dc:creator>3D Merchant admin</dc:creator>
		<pubDate>Wed, 15 Jun 2011 15:14:53 +0000</pubDate>
		<guid isPermaLink="false">http://3dmerchant.com/blog/?p=189#comment-2223</guid>
		<description>Hi Dana-  $19.95 is charged when they don&#039;t receive your certification. If they are reported correctly on time you will never see this fee. Something is amiss.  If you pay First Data $99, you should not also pay Security Metrics $25. PCI Compliance is not just for online. If you read the appropriate worksheet at pcisecuritystandards.org, you choose the one right for your company. Plenty of data breaches occur in retail and business environments that are not online. 
If you want an offline solution with no annual PCI fee give me a call. A word of warning though- it&#039;s a small fee for the protection it provides if you maintain proper procedures year round, not just on the day you complete a form.</description>
		<content:encoded><![CDATA[<p>Hi Dana-  $19.95 is charged when they don&#8217;t receive your certification. If they are reported correctly on time you will never see this fee. Something is amiss.  If you pay First Data $99, you should not also pay Security Metrics $25. PCI Compliance is not just for online. If you read the appropriate worksheet at pcisecuritystandards.org, you choose the one right for your company. Plenty of data breaches occur in retail and business environments that are not online.<br />
If you want an offline solution with no annual PCI fee give me a call. A word of warning though- it&#8217;s a small fee for the protection it provides if you maintain proper procedures year round, not just on the day you complete a form.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dana</title>
		<link>http://3dmerchant.com/blog/merchant-processing-security/pci-compliance-merchant-processing-security/first-data-pci-compliance-fee/#comment-2222</link>
		<dc:creator>Dana</dc:creator>
		<pubDate>Sun, 12 Jun 2011 19:33:39 +0000</pubDate>
		<guid isPermaLink="false">http://3dmerchant.com/blog/?p=189#comment-2222</guid>
		<description>We pay Security Metrics a $25 fee every year to become &quot;certified,&quot; although we do not do any financial business online, and do not store any financial data. We use a dumb swipe terminal. They are supposed to be contacting First Data to tell them we are certified. 

We intermittently get charged $19.99 PCI Security Fee by First Data during the year even though we are certified. In addition, at the end of the year, First Data charged us an additional $99 PCI Security Fee.  

We are going to switch clearinghouses. This is ridiculous!  As an aside, I fail to see why the merchants should have to pay ongoing fees for security problems that MasterCard and VISA are having.</description>
		<content:encoded><![CDATA[<p>We pay Security Metrics a $25 fee every year to become &#8220;certified,&#8221; although we do not do any financial business online, and do not store any financial data. We use a dumb swipe terminal. They are supposed to be contacting First Data to tell them we are certified. </p>
<p>We intermittently get charged $19.99 PCI Security Fee by First Data during the year even though we are certified. In addition, at the end of the year, First Data charged us an additional $99 PCI Security Fee.  </p>
<p>We are going to switch clearinghouses. This is ridiculous!  As an aside, I fail to see why the merchants should have to pay ongoing fees for security problems that MasterCard and VISA are having.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

