---
title: PCI DSS Certification
description: Securing credit card information is of paramount importance in today's digital age where financial transactions are increasingly conducted online. As consumers entrust their sensitive payment data to businesses, ensuring the protection of credit card information becomes a critical priority.
image: https://www.wearefiber.com/hubfs/Progetto%20senza%20titolo%20(19).png
---

[![](https://www.wearefiber.com/hs-fs/hubfs/Risorsa%2037.png?width=273&height=90&name=Risorsa%2037.png)](https://www.wearefiber.com/en/)

- [Approach](https://www.wearefiber.com/en/approach)
- [About](https://www.wearefiber.com/en/about)
- [CSR projects](https://www.wearefiber.com/en/blog/tag/csr-projects)
- [Knowledge base](https://www.wearefiber.com/en/blog/tag/knowledge-base)
- [Governance](https://www.wearefiber.com/en/governance)
- [Blog](https://www.wearefiber.com/en/blog)
- [Careers](https://www.wearefiber.com/it/careers)
- [Contacts](https://www.wearefiber.com/en/contacts)

- [Customer Service](https://www.wearefiber.com/en/customer-service-in-outsourcing) 
    - [Ticket management](https://www.wearefiber.com/en/ticket-management-in-outsourcing)
    - [Digital customer care](https://www.wearefiber.com/en/digital-customer-care)
    - [Help Desk](https://www.wearefiber.com/en/help-desk-in-outsourcing)
    - [Chatbot](https://www.wearefiber.com/en/chatbot-in-outsourcing-1)
    - [Booking office](https://www.wearefiber.com/en/booking-office-outsourcing)
    - [Smart assistance](https://www.wearefiber.com/en/smart-assistance-in-outsourcing)
- [Back Office](https://www.wearefiber.com/en/back-office-in-outsourcing) 
    - [Data entry](https://www.wearefiber.com/en/data-entry-outsourcing)
    - [Data enrichment](https://www.wearefiber.com/en/data-enrichment)
    - [Document management](https://www.wearefiber.com/en/gestione-documentale)
    - [Logistic management](https://www.wearefiber.com/en/gestione-logistica)
    - [Order management](https://www.wearefiber.com/en/gestione-ordini)
- [Process Management](https://www.wearefiber.com/en/process-management-in-outsourcing) 
    - [Control room](https://www.wearefiber.com/en/control-room-outsourcing)
    - [Quality audit](https://www.wearefiber.com/en/quality-audit-in-outsourcing)
    - [Robotic process automation](https://www.wearefiber.com/en/robotic-process-automation-in-outsourcing)
- [Outbound Marketing](https://www.wearefiber.com/en/outbound-marketing)
- Industry 
    - [Healthcare](https://www.wearefiber.com/en/healthcare-in-outsourcing)
    - [Ecommerce](https://www.wearefiber.com/en/ecommerce-in-outsourcing)
    - [Food delivery](https://www.wearefiber.com/en/food-delivery-in-outsourcing)
    - [Retail](https://www.wearefiber.com/en/retail-in-outsourcing)
    - [Finance & Insurance](https://www.wearefiber.com/en/finance-e-insurance-in-outsourcing)
    - [Mobility](https://www.wearefiber.com/en/mobility-in-outsourcing)
    - [Travel](https://www.wearefiber.com/en/travel-in-outsourcing)
    - [B2B services](https://www.wearefiber.com/en/b2b-services-in-outsourcing)

- [Approach](https://www.wearefiber.com/en/approach)
- [About](https://www.wearefiber.com/en/about)
- [CSR projects](https://www.wearefiber.com/en/blog/tag/csr-projects)
- [Knowledge base](https://www.wearefiber.com/en/blog/tag/knowledge-base)
- [Governance](https://www.wearefiber.com/en/governance)
- [Blog](https://www.wearefiber.com/en/blog)
- [Careers](https://www.wearefiber.com/it/careers)
- [Contacts](https://www.wearefiber.com/en/contacts)

# PCI DSS Certification

June 21, 2023  8 minutes to read

Securing credit card information is of paramount importance in today's digital age where financial transactions are increasingly conducted online. As consumers entrust their sensitive payment data to businesses, ensuring the protection of credit card information becomes a critical priority. Unauthorized access or breaches can have severe consequences, including financial loss, reputational damage, and legal liabilities.

# **What is PCI DSS?**

The Payment Card Industry [Data](https://www.wearefiber.com/it/data-entry-outsourcing) Security Standard (PCI DSS) is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information, maintain a secure environment.

The Payment Card Industry Security Standards Council (PCI SSC) was launched on September 7, 2006, to manage the ongoing evolution of the Payment Card Industry (PCI) security standards with a focus on improving payment account security throughout the transaction process. The PCI DSS is administered and managed by the PCI SSC (www.pcisecuritystandards.org), an independent body that was created by the major payment card brands (Visa, MasterCard, American Express, Discover, and JCB.). 

## **To whom does the PCI DSS apply?**

The PCI DSS applies to ANY organization, regardless of size or number of transactions, that accepts, transmits, or stores any cardholder data. So, of course,[BPO](https://www.wearefiber.com/it/blog/bpo-cos-e-business-process-outsourcing)s, [outsourcing](https://www.wearefiber.com/en/blog/business-process-outsourcing-when-is-it-convenient-to-focus-on-outsourcing) service providers, and call centers are especially included!

Obtaining PCI DSS [certification](https://www.wearefiber.com/en/blog/soc-2-certification) is a significant achievement for any organization that handles payment card information. It demonstrates that the company has implemented robust security measures to protect sensitive cardholder data and is committed to maintaining those measures over time.

### **How can you achieve PCI DSS certification?**

To achieve PCI DSS compliance, companies must implement a set of security controls and procedures designed to protect payment card information. These controls and procedures are specified in the PCI DSS standard, which outlines requirements in areas such as network security, access control, and data encryption.

#### **What are the phases for the assessment process?**

The assessment process involves several stages, including:

**1.Scoping**

This involves defining the scope of the assessment, which typically includes all systems and processes that store, process, or transmit payment card data.

**2. Gap Analysis**

This involves identifying any gaps between the company's current security controls and the PCI DSS requirements. Any gaps that are identified must be addressed before the company can become compliant.

**3. Remediation**

This stage is about implementing security controls and procedures to address any gaps that were identified during the gap analysis.

**4. Assessment**

This involves an independent assessment of the company's security controls and procedures against the PCI DSS requirements.

**5. [Certification](https://www.wearefiber.com/it/le-nostre-certificazioni)**

If the company's security controls and procedures meet all of the PCI DSS requirements, the QSA will issue a certification stating that the company is PCI DSS compliant.

##### **What are the official requirements for the PCI DSS Compliance?**

There are 12 requirements for obtaining the PCI DSS Compliance.

1.**Use and Maintain Firewalls**

Install and maintain firewalls to protect your network from unauthorized access.

**2. Proper Password Protections**

Use strong passwords and change them regularly. Don't use default passwords.

**3. Protect Cardholder Data**

Keep cardholder data storage to a minimum and protect it at all times. Do not store sensitive authentication data after authorization.

**4. Encrypt Transmitted Data **

Use strong encryption methods to protect cardholder data during transmission over public networks.

**5. Use and Maintain Anti-Virus**

Install and regularly update anti-virus software to protect against malicious software.

**6. Properly Updated Software **

Ensure that all software is up-to-date with the latest security patches and updates.

**7. Restrict Data Access **

Limit access to cardholder data on a need-to-know basis. Use role-based access controls to restrict access.

**8. Unique IDs for Access: **

Assign a unique ID to each user with access to cardholder data.

**9. Restrict Physical Access**

Protect cardholder data by restricting physical access to data storage and processing areas.

**10. Create and Maintain Access Logs**

Keep detailed records of all access to cardholder data, including user activity and system activity logs.

**11. Scan and Test for Vulnerabilities**

Regularly scan and test for vulnerabilities in your network and systems.

**12. Document Policies**

Create and maintain comprehensive security policies and procedures and ensure that they are communicated to all relevant personnel.

By complying with these 12 requirements, the organization is taking the necessary steps to protect cardholder data and maintain a secure network. PCI DSS compliance is not a one-time event but a continuous process, and it is important to regularly review and update security measures to stay ahead of emerging threats.

**What are the PCI DSS Compliance Levels?**

PCI DSS compliance levels are classifications that determine the requirements and validation processes for businesses based on their annual volume of credit card transactions. These levels are established by the major card brands (Visa, Mastercard, American Express, Discover, and JCB) to ensure consistent security measures across the payment card industry. The PCI DSS compliance levels are as follows:

- **Level 1**

This is the highest compliance level and applies to businesses that process over 6 million card transactions annually, or those identified as high-risk entities by the card brands. Level 1 merchants must undergo an annual on-site assessment by a Qualified Security Assessor (QSA) and submit a Report on Compliance (ROC) to the card brands.

- **Level 2**

Level 2 applies to businesses that process between 1 million and 6 million card transactions annually. These merchants must complete a Self-Assessment Questionnaire (SAQ) annually, conduct quarterly vulnerability scans by an Approved Scanning Vendor (ASV), and submit an Attestation of Compliance (AOC) to their acquiring bank.

- **Level 3**

This level applies to businesses that process between 20,000 and 1 million e-commerce transactions annually. Level 3 merchants must complete an SAQ annually and conduct quarterly vulnerability scans by an ASV. They also submit an AOC to their acquiring bank.

- **Level 4**

This level applies to businesses that process fewer than 20,000 [e-commerce](https://www.wearefiber.com/en/blog/optimize-ecommerce-order-management-through-outsourcing) transactions annually or up to 1 million card transactions annually through other channels. Level 4 merchants must complete an SAQ annually and may need to perform quarterly vulnerability scans based on their acquiring bank's requirements.

It's important to note that the specific validation requirements may vary based on the card brand and the merchant's acquirer (the financial institution that enables card payments). Merchants should consult with their acquirer to determine the appropriate compliance level and corresponding validation requirements.

**PCI DSS & [We Are Fiber](https://www.wearefiber.com/en/)**

We Are Fiber is proud to announce that it holds the PCI DSS compliance certification, which is a testament to our unwavering commitment to maintaining the highest standards of data security in our call center and [BPO outsourcing services.](https://www.wearefiber.com/en/blog/why-is-it-convenient-for-companies-to-outsource)

###### **How did We Are Fiber obtained this certification?**

- **Protection of sensitive payment card information**

At [We Are Fiber](https://www.wearefiber.com/en/), we understand the critical importance of protecting sensitive payment card information. As a trusted provider of [customer care services](https://www.wearefiber.com/it/customer-service-in-outsourcing), we recognize that our clients depend on us to safeguard their customers' payment data. With our PCI DSS compliance certification, our customers can be assured that we are following the strictest security protocols and procedures to keep their customers' payment data safe and secure.

- **High quality fo customer care services**

In addition to our commitment to data security, We Are Fiber also takes pride in the quality of our customer care services. Our teams of highly skilled professionals are dedicated to providing top-notch customer care services that meet the highest standards of quality. We believe that customer satisfaction is the key to success, and we strive to ensure that our clients' customers are satisfied with every interaction.

- **Regular quality audits of our operations**

To ensure that we are consistently providing high-quality customer care services, we conduct [regular quality audits](https://www.wearefiber.com/it/quality-audit-in-outsourcing) of our operations. These audits allow us to identify areas for improvement and implement changes to enhance our services continually. Our commitment to quality is also reflected in our ISO 9001:2015 certification, which demonstrates our adherence to a rigorous quality management system.

**A few last words…**

We believe that data security and quality customer care are essential components of our call center and BPO outsourcing services. Our PCI DSS compliance certification and other important certifications such as ISO 9001:2015 are proof of our commitment to providing our clients with exceptional services that meet the highest standards of security and quality.

[We Are Fiber](https://www.wearefiber.com/en/) will continue to prioritize data security and quality customer care in all our operations. We are committed to meeting the evolving needs of our clients and providing them with exceptional services that exceed their expectations.

 

- <http://www.facebook.com/share.php?u=https://www.wearefiber.com/en/blog/pci-dss-certification>
- <https://twitter.com/share?text=PCI%20DSS%20Certification&url=https://www.wearefiber.com/en/blog/pci-dss-certification&hashtags=weareawesome&via=bluleadz>
- <http://www.linkedin.com/shareArticle?mini=true&url=https://www.wearefiber.com/en/blog/pci-dss-certification>
- <https://www.pinterest.com/pin/create/button/?url=https://www.wearefiber.com/en/blog/pci-dss-certification&media=https://25104942.fs1.hubspotusercontent-eu1.net/hubfs/25104942/Progetto%20senza%20titolo%20%2819%29.png>
- [mailto:?subject='https://www.wearefiber.com/en/blog/pci-dss-certification'](mailto:?subject='https://www.wearefiber.com/en/blog/pci-dss-certification')

[Data entry solutions](https://www.wearefiber.com/en/blog/tag/data-entry-solutions)

### Recent posts

### Post tag

- [Social and customer care service (100)](https://www.wearefiber.com/en/blog/tag/social-and-customer-care-service)
- [Outsourcing and Process management solutions (62)](https://www.wearefiber.com/en/blog/tag/outsourcing-and-process-management-solutions)
- [Data entry solutions (27)](https://www.wearefiber.com/en/blog/tag/data-entry-solutions)
- [Back office and help desk solutions (26)](https://www.wearefiber.com/en/blog/tag/back-office-and-help-desk-solutions)
- [Ecommerce and order management (25)](https://www.wearefiber.com/en/blog/tag/ecommerce-and-order-management)
- [Teleselling and telemarketing (17)](https://www.wearefiber.com/en/blog/tag/teleselling-and-telemarketing)
- [Logistics management and food delivery (6)](https://www.wearefiber.com/en/blog/tag/logistics-management-and-food-delivery)
- [Knowledge base (5)](https://www.wearefiber.com/en/blog/tag/knowledge-base)
- [CSR Projects (2)](https://www.wearefiber.com/en/blog/tag/csr-projects)
- [healthcare (1)](https://www.wearefiber.com/en/blog/tag/healthcare)

See all

## Related Posts

<https://www.wearefiber.com/en/blog/strengthening-information-security-our-iso/iec-270012013-certification-journey>

## [Strengthening Information Security: Our ISO/IEC 27001:2013 certification journey](https://www.wearefiber.com/en/blog/strengthening-information-security-our-iso/iec-270012013-certification-journey)

June 30, 2023

In today's digital era, protecting sensitive information has become a critical priority for...

[CONTINUE READING](https://www.wearefiber.com/en/blog/strengthening-information-security-our-iso/iec-270012013-certification-journey)

<https://www.wearefiber.com/en/blog/soc-2-certification>

## [SOC 2 Certification](https://www.wearefiber.com/en/blog/soc-2-certification)

June 20, 2023

Managing customer data is crucial for businesses operating in today's data-driven landscape. As...

[CONTINUE READING](https://www.wearefiber.com/en/blog/soc-2-certification)

<https://www.wearefiber.com/en/blog/2020/08/12/optimizing-the-help-desk-an-opportunity-to-differentiate>

## [Optimizing the Help Desk: An Opportunity to Differentiate](https://www.wearefiber.com/en/blog/2020/08/12/optimizing-the-help-desk-an-opportunity-to-differentiate)

January 31, 2022

The Help Desk, also called The Service Desk, is essentially the first level of support services for...

[CONTINUE READING](https://www.wearefiber.com/en/blog/2020/08/12/optimizing-the-help-desk-an-opportunity-to-differentiate)

[![logo bianco WAF](https://www.wearefiber.com/hs-fs/hubfs/logo%20bianco%20WAF.png?width=170&height=54&name=logo%20bianco%20WAF.png "logo bianco WAF")](https://www.wearefiber.com/it)

#### [Certifications](https://www.wearefiber.com/it/le-nostre-certificazioni)

| ![27002-588x600](https://www.wearefiber.com/hs-fs/hubfs/27002-588x600.png?width=50&name=27002-588x600.png) ![data destruction](https://www.wearefiber.com/hs-fs/hubfs/data%20destruction.png?width=50&height=50&name=data%20destruction.png) ![SOC 2 TYPE 1](https://www.wearefiber.com/hs-fs/hubfs/SOC%202%20TYPE%201.png?width=40&height=55&name=SOC%202%20TYPE%201.png) | ![iso_0000_Livello-3](https://www.wearefiber.com/hs-fs/hubfs/iso_0000_Livello-3.png?width=50&height=50&name=iso_0000_Livello-3.png) ![icon green](https://www.wearefiber.com/hs-fs/hubfs/icon%20green.png?width=50&height=50&name=icon%20green.png) ![soc-2](https://www.wearefiber.com/hs-fs/hubfs/soc-2.png?width=43&height=58&name=soc-2.png) | ![iso_0002_Livello-1](https://www.wearefiber.com/hs-fs/hubfs/iso_0002_Livello-1.png?width=50&name=iso_0002_Livello-1.png)![pci](https://www.wearefiber.com/hs-fs/hubfs/pci.png?width=50&height=50&name=pci.png)   |
| --- | --- | --- |

#### Contacts

[info@wearefiber.com](mailto:info@wearefiber.com)

Rruga “Don Bosko”, Kompleksi "Don Bosko", Kulla 7, kati I-re Tiranë

#### Company

- [Our story](https://www.wearefiber.com/en/about)
- [Vision](https://www.wearefiber.com/en/approach)
- [Meet our team](https://www.wearefiber.com/en/approach)
- [Career](https://www.wearefiber.com/en/careers)

#### Insights

- [Blog](https://www.wearefiber.com/en/blog)
- [Knowledge base](https://www.wearefiber.com/en/blog/tag/knowledge-base)

#### Services

- [**Customer Service**](https://www.wearefiber.com/en/customer-service-in-outsourcing) 
    - [Ticket Management](https://www.wearefiber.com/en/ticket-management-in-outsourcing)
    - [Digital Customer Care](https://www.wearefiber.com/en/digital-customer-care)
    - [Chatbot](https://www.wearefiber.com/en/chatbot-in-outsourcing-1)
    - [Booking Office](https://www.wearefiber.com/en/booking-office-outsourcing)
    - [Smart Assistance](https://www.wearefiber.com/en/smart-assistance-in-outsourcing)
- [**Back office**](https://www.wearefiber.com/en/back-office-in-outsourcing) 
    - [Data Entry](https://www.wearefiber.com/en/data-entry-outsourcing)
    - [Data Enrichment](https://www.wearefiber.com/en/data-enrichment)
    - [Document Management](https://www.wearefiber.com/en/gestione-documentale)
    - [Logistic Management](https://www.wearefiber.com/en/gestione-logistica)
    - [Order Management](https://www.wearefiber.com/en/gestione-ordini)
- [**Process Management**](https://www.wearefiber.com/en/process-management-in-outsourcing) 
    - [Control room](https://www.wearefiber.com/en/control-room-outsourcing)
    - [Quality Audit](https://www.wearefiber.com/en/quality-audit-in-outsourcing)
    - [Robotic Process Automation](https://www.wearefiber.com/en/robotic-process-automation-in-outsourcing)
- [**Outbound Marketing**](https://www.wearefiber.com/en/outbound-marketing)

#### Industries

- [Healthcare](https://www.wearefiber.com/en/healthcare-in-outsourcing)
- [Ecommerce](https://www.wearefiber.com/en/ecommerce-in-outsourcing)
- [Food delivery](https://www.wearefiber.com/en/food-delivery-in-outsourcing)
- [Retail](https://www.wearefiber.com/en/retail-in-outsourcing)
- [Finance & Insurance](https://www.wearefiber.com/en/finance-e-insurance-in-outsourcing)
- [Mobility traveler](https://www.wearefiber.com/en/mobility-in-outsourcing)
- [B2B Services](https://www.wearefiber.com/en/b2b-services-in-outsourcing)

#### Newsletter

###### Follow us on

<https://www.facebook.com/wearefiber/> <https://www.instagram.com/wearefiber/> <https://www.linkedin.com/company/we-are-fiber/>

- [Privacy Policy](https://www.wearefiber.com/en/privacy-policy)
- [Cookie Policy](https://www.wearefiber.com/en/cookie-policy)
- [Terms & Conditions](https://www.wearefiber.com/en/termini-e-condizioni)

Back to top

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "articleBody" : "Securing credit card information is of paramount importance in today's digital age where financial transactions are increasingly conducted online. As consumers entrust their sensitive payment data to businesses, ensuring the protection of credit card information becomes a critical priority. Unauthorized access or breaches can have severe consequences, including financial loss, reputational damage, and legal liabilities. What is PCI DSS? The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information, maintain a secure environment. The Payment Card Industry Security Standards Council (PCI SSC) was launched on September 7, 2006, to manage the ongoing evolution of the Payment Card Industry (PCI) security standards with a focus on improving payment account security throughout the transaction process. The PCI DSS is administered and managed by the PCI SSC (www.pcisecuritystandards.org), an independent body that was created by the major payment card brands (Visa, MasterCard, American Express, Discover, and JCB.). To whom does the PCI DSS apply? The PCI DSS applies to ANY organization, regardless of size or number of transactions, that accepts, transmits, or stores any cardholder data. So, of course, BPOs, outsourcing service providers, and call centers are especially included! Obtaining PCI DSS certification is a significant achievement for any organization that handles payment card information. It demonstrates that the company has implemented robust security measures to protect sensitive cardholder data and is committed to maintaining those measures over time. How can you achieve PCI DSS certification? To achieve PCI DSS compliance, companies must implement a set of security controls and procedures designed to protect payment card information. These controls and procedures are specified in the PCI DSS standard, which outlines requirements in areas such as network security, access control, and data encryption. What are the phases for the assessment process? The assessment process involves several stages, including: 1.Scoping This involves defining the scope of the assessment, which typically includes all systems and processes that store, process, or transmit payment card data. 2. Gap Analysis This involves identifying any gaps between the company's current security controls and the PCI DSS requirements. Any gaps that are identified must be addressed before the company can become compliant. 3. Remediation This stage is about implementing security controls and procedures to address any gaps that were identified during the gap analysis. 4. Assessment This involves an independent assessment of the company's security controls and procedures against the PCI DSS requirements. 5. Certification If the company's security controls and procedures meet all of the PCI DSS requirements, the QSA will issue a certification stating that the company is PCI DSS compliant. What are the official requirements for the PCI DSS Compliance? There are 12 requirements for obtaining the PCI DSS Compliance. 1.Use and Maintain Firewalls Install and maintain firewalls to protect your network from unauthorized access. 2. Proper Password Protections Use strong passwords and change them regularly. Don't use default passwords. 3. Protect Cardholder Data Keep cardholder data storage to a minimum and protect it at all times. Do not store sensitive authentication data after authorization. 4. Encrypt Transmitted Data Use strong encryption methods to protect cardholder data during transmission over public networks. 5. Use and Maintain Anti-Virus Install and regularly update anti-virus software to protect against malicious software. 6. Properly Updated Software Ensure that all software is up-to-date with the latest security patches and updates. 7. Restrict Data Access Limit access to cardholder data on a need-to-know basis. Use role-based access controls to restrict access. 8. Unique IDs for Access: Assign a unique ID to each user with access to cardholder data. 9. Restrict Physical Access Protect cardholder data by restricting physical access to data storage and processing areas. 10. Create and Maintain Access Logs Keep detailed records of all access to cardholder data, including user activity and system activity logs. 11. Scan and Test for Vulnerabilities Regularly scan and test for vulnerabilities in your network and systems. 12. Document Policies Create and maintain comprehensive security policies and procedures and ensure that they are communicated to all relevant personnel. By complying with these 12 requirements, the organization is taking the necessary steps to protect cardholder data and maintain a secure network. PCI DSS compliance is not a one-time event but a continuous process, and it is important to regularly review and update security measures to stay ahead of emerging threats. What are the PCI DSS Compliance Levels? PCI DSS compliance levels are classifications that determine the requirements and validation processes for businesses based on their annual volume of credit card transactions. These levels are established by the major card brands (Visa, Mastercard, American Express, Discover, and JCB) to ensure consistent security measures across the payment card industry. The PCI DSS compliance levels are as follows: Level 1 This is the highest compliance level and applies to businesses that process over 6 million card transactions annually, or those identified as high-risk entities by the card brands. Level 1 merchants must undergo an annual on-site assessment by a Qualified Security Assessor (QSA) and submit a Report on Compliance (ROC) to the card brands. Level 2 Level 2 applies to businesses that process between 1 million and 6 million card transactions annually. These merchants must complete a Self-Assessment Questionnaire (SAQ) annually, conduct quarterly vulnerability scans by an Approved Scanning Vendor (ASV), and submit an Attestation of Compliance (AOC) to their acquiring bank. Level 3 This level applies to businesses that process between 20,000 and 1 million e-commerce transactions annually. Level 3 merchants must complete an SAQ annually and conduct quarterly vulnerability scans by an ASV. They also submit an AOC to their acquiring bank. Level 4 This level applies to businesses that process fewer than 20,000 e-commerce transactions annually or up to 1 million card transactions annually through other channels. Level 4 merchants must complete an SAQ annually and may need to perform quarterly vulnerability scans based on their acquiring bank's requirements. It's important to note that the specific validation requirements may vary based on the card brand and the merchant's acquirer (the financial institution that enables card payments). Merchants should consult with their acquirer to determine the appropriate compliance level and corresponding validation requirements. PCI DSS &amp; We Are Fiber We Are Fiber is proud to announce that it holds the PCI DSS compliance certification, which is a testament to our unwavering commitment to maintaining the highest standards of data security in our call center and BPO outsourcing services. How did We Are Fiber obtained this certification? Protection of sensitive payment card information At We Are Fiber, we understand the critical importance of protecting sensitive payment card information. As a trusted provider of customer care services, we recognize that our clients depend on us to safeguard their customers' payment data. With our PCI DSS compliance certification, our customers can be assured that we are following the strictest security protocols and procedures to keep their customers' payment data safe and secure. High quality fo customer care services In addition to our commitment to data security, We Are Fiber also takes pride in the quality of our customer care services. Our teams of highly skilled professionals are dedicated to providing top-notch customer care services that meet the highest standards of quality. We believe that customer satisfaction is the key to success, and we strive to ensure that our clients' customers are satisfied with every interaction. Regular quality audits of our operations To ensure that we are consistently providing high-quality customer care services, we conduct regular quality audits of our operations. These audits allow us to identify areas for improvement and implement changes to enhance our services continually. Our commitment to quality is also reflected in our ISO 9001:2015 certification, which demonstrates our adherence to a rigorous quality management system. A few last words… We believe that data security and quality customer care are essential components of our call center and BPO outsourcing services. Our PCI DSS compliance certification and other important certifications such as ISO 9001:2015 are proof of our commitment to providing our clients with exceptional services that meet the highest standards of security and quality. We Are Fiber will continue to prioritize data security and quality customer care in all our operations. We are committed to meeting the evolving needs of our clients and providing them with exceptional services that exceed their expectations.",
  "author" : {
    "@type" : "Person",
    "name" : "wafstaff",
    "sameAs" : "",
    "url" : "https://www.wearefiber.com/en/blog/author/wafstaff"
  },
  "dateModified" : "21/06/2023",
  "datePublished" : "21/06/2023",
  "headline" : "PCI DSS Certification",
  "image" : {
    "@type" : "ImageObject",
    "height" : 400,
    "url" : "https://25104942.fs1.hubspotusercontent-eu1.net/hubfs/25104942/Progetto%20senza%20titolo%20%2819%29.png",
    "width" : 750
  },
  "mainEntityOfPage" : "https://www.wearefiber.com/en/blog/pci-dss-certification",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://25104942.fs1.hubspotusercontent-eu1.net/hubfs/25104942/Risorsa%2037.png"
    },
    "name" : "",
    "url" : "www.wearefiber.com"
  }
}
```