Skip to content
RONPAY

PCI DSS

Home / PCI DSS

This is a translation for information purposes. The Romanian version of this document is the official one and prevails in case of any discrepancy.

1. What PCI DSS certification is

PCI DSS (Payment Card Industry Data Security Standard) is the global security standard created by Visa, Mastercard, American Express, Discover and JCB to protect cardholder data at every stage of a transaction.

Level 1 is the highest degree of compliance, reserved for organisations processing more than 6 million transactions a year. It requires annual audits by a Qualified Security Assessor (QSA), quarterly ASV scans and regular penetration testing.

The standard comprises 12 fundamental requirements, divided into 6 control objectives: from network protection to vulnerability management, and from access control to continuous system monitoring.

2. Why is PCI DSS essential for payments?

Mandatory in order to operate with the card networks

Visa, Mastercard and the other international networks require PCI DSS compliance from every party that handles card data. Without certification, payment processing is not possible.

3. Protection against security breaches and penalties

A data breach exposes a company to penalties of up to EUR 20 million (GDPR) and to fines from the payment networks. PCI DSS drastically reduces that exposure.

4. A requirement for enterprise and the public sector

In public tenders and B2B supplier selection processes, PCI DSS certification is often a knock-out criterion. Holding it speeds up onboarding with enterprise partners and clients.

5. How does RONPay implement the PCI DSS standard?

a) End-to-end encryption

All card data is encrypted with AES-256, both in transit and at rest. Card numbers (PAN) are tokenised and are never exposed in clear text in our systems.

b) Network segmentation

The CDE (Cardholder Data Environment) infrastructure is isolated from the rest of the network by dedicated firewalls, segmented VLANs and zero-trust access policies.

c) Continuous monitoring and penetration testing

Our in-house SOC monitors systems 24/7. We carry out quarterly penetration tests and ASV scans to identify and remediate vulnerabilities in real time.

d) Annual audit by a certified QSA

Every year, an independent Qualified Security Assessor verifies compliance with all 12 PCI DSS requirements and issues the official Report on Compliance (ROC).

6. Concrete benefits for your business. Zero liability over card data

With RONPay certified to PCI DSS Level 1, your business never comes into contact with sensitive data. Liability is handled entirely by our infrastructure.

7. Reduced fraud and chargebacks

PCI DSS security protocols reduce fraud rates and the costs associated with chargebacks by up to 80%, protecting your operating margin.

8. Faster onboarding with banks and partners

RONPay's PCI DSS certification removes the need for additional audits, speeding up due diligence with financial institutions and acquirers.

9. Trust from enterprise and the public sector

Working with a PCI DSS Level 1 certified provider strengthens your credibility in tenders, in requests for proposals and with corporate clients who require certified suppliers.

10. Frequently asked questions about PCI DSS certification

a) What is PCI DSS certification and why is it needed?

PCI DSS is the global security standard for protecting payment card data. It is mandatory for every organisation that processes, transmits or stores card data. Without certification, you cannot operate with Visa, Mastercard and the other international networks.

b) What is the difference between PCI DSS Level 1 and the other levels?

Level 1 is the most rigorous and applies to organisations with more than 6 million transactions a year. It requires annual audits by a certified QSA, quarterly ASV scans and penetration testing. Levels 2 - 4 have progressively less strict requirements and self-assessment questionnaires.

c) How does RONPay's PCI DSS standard protect my online store?

By integrating RONPay, your customers' card data never passes through your servers. Tokenisation and RONPay-hosted checkout pages remove your PCI scope, significantly reducing your business's compliance risks and costs.

d) Do I also need PCI DSS certification if I use RONPay?

No. By using RONPay payment services (APIs, hosted checkout, PCI Proxy), your PCI scope is reduced to a minimum. RONPay manages the entire security chain, and you can complete a simplified SAQ-A questionnaire instead of complex audits.

11. Protect your business's payments

See how RONPay's PCI DSS Level 1 certified infrastructure removes risk and simplifies compliance for your company.