FortConsult Services PCI Advisories Customers Careers Contact
Contact FortConsult if you wish to know:
- How to interpret the security requirements in PA DSS
- Whether you have the option of exemption from PA DSS certification
- How to be PA DSS validated in the quickest and most straightforward manner
- How you can minimise your costs in qualifying for PA DSS validation

We can also help you obtain PA DSS vali- dation.
FortConsult is the only Danish enterprise which is certified by the credit card companies to both conduct audits and security scans of enter- prises' critical payment systems in accordance with PCI DSS - and to check security in payment software in accordance with PA DSS.
Business enterprises that develop cash till solutions that are not integrated with a credit card terminal do not generally speaking have to be PA DSS certified. The same applies to businesses that develop backend solutions for handling credit card data, such as data warehouse and anti-fraud software.
 
In addition, stand-alone terminal solutions are exempt from PA DSS certification provided that:
  • The terminal does not have any data connection or other connection to the shop's systems or network
  • The terminal is connected directly to an acquiring bank or a PCI DSS certified processor
  • The developer of the payment application or software ensures the secure remote control of updates, troubleshooting, access and maintenance
  • The application does not retain full magnetic stripe content, card validation code or PIN/encrypted PIN data following final authorisation of the payment card
 
Even if your enterprise is not subject to the requirements from the PCI Council concerning PA DSS certification, it may anyway be a good idea to undergo the process that takes place prior to certification in order to make sure that you develop secure software. Alternatively, it can be a good idea for your software to undergo a more general security assessment. In both cases, this will provide benefits in terms of sales and marketing in relation to your competitors.
 
Furthermore, you should be aware that your solutions can be expected to come within the scope of the PCI Council's future rules concerning enterprises that have to be PA DSS certified. This applies in particular in the event that you develop centralised solutions with a lot of credit card data.
 
In any event, FortConsult can help you to perform the certification process. Please contact us if you wish to know more.
 
You can read more about the security requirements in PA DSS in the following, as well as how to obtain PA DSS validation in the easiest possible manner.
 
- PCI DSS certified in 2004 to perform security scans as the first and only company in Scandinavia.
- PCI DSS certified in 2005 to conduct audits as the first and only company in Scandinavia.
- Chosen by the bank sector in Denmark to help all Danish bank data centres to acquire PCI DSS validation due to our early PCI DSS certification, our considerable experience in the PCI area and our extensive knowledge of the financial sector.
- Permanent PCI DSS service provider to all Danish banks needing PCI DSS assistance.
- Has carried out PCI DSS tasks for some of the biggest retail chains in Scandinavia at international level.
- Is today the leading PCI DSS service provider in Scandinavia and the Baltic. We have, for instance, certified more than 60 percent of the enterprises on VISA's list of validated Scandinavian service providers.
- PA DSS certified in 2008 as the first and only company in Denmark - and among the first 14 in the world.
udskriv