Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: rotrott on January 14, 2012, 04:46:51 PM



Title: The Expense of PCI Compliance
Post by: rotrott on January 14, 2012, 04:46:51 PM
I'm sure this has probably been mentioned before, but I figured I would mention it anyway.  When selling things on the web (and outside the web), the cost of PCI compliance for software, websites, and small business owners can be prohibitive.  If they used bitcoin instead, they wouldn't have to go through a lengthy, costly (and ongoing costly) compliance with the PCI spec (and would still be inherently safer).

Don't get me wrong, I'm a big proponent of a lot of the PCI spec, but it can be a burden on small businesses.


Title: Re: The Expense of PCI Compliance
Post by: BitPay Business Solutions on January 14, 2012, 10:43:41 PM
I'm sure this has probably been mentioned before, but I figured I would mention it anyway.  When selling things on the web (and outside the web), the cost of PCI compliance for software, websites, and small business owners can be prohibitive.  If they used bitcoin instead, they wouldn't have to go through a lengthy, costly (and ongoing costly) compliance with the PCI spec (and would still be inherently safer).

Don't get me wrong, I'm a big proponent of a lot of the PCI spec, but it can be a burden on small businesses.

We talked to a few large businesses at CES this week.  They were very interested in bitcoins as a payment method because it eliminates all of the PCI compliance costs and hassles. 

Square was also at CES and many people were visiting our booth after they talked to Square.  Square is a convenient way to collect a payment, but it's still built on the credit card system and doesn't solve any of the problems of chargebacks or PCI.

It is very expensive for a company to safeguard all of this sensitive information, not only from hackers but also from their own employees.  Plus companies get to pay each year for a mandatory audit.  It's a real hassle.  Bitcoins are by far the most merchant friendly payment system available today, and we got that point across to some very important people this week.


Title: Re: The Expense of PCI Compliance
Post by: Meatpile on January 15, 2012, 03:48:10 AM
I just set up credit and interac online recently... And dont store any customer info, what rates do you get when you store the info yourself instead of using a processor?


Title: Re: The Expense of PCI Compliance
Post by: BitPay Business Solutions on January 15, 2012, 10:40:15 AM
It is not uncommon for a business to spend over $100,000 each year for PCI compliance.  Read this:

http://www.networkworld.com/news/2010/030110-pci-compliance-audit-cost.html (http://www.networkworld.com/news/2010/030110-pci-compliance-audit-cost.html)


Title: Re: The Expense of PCI Compliance
Post by: lonelyminer (Peter Šurda) on January 15, 2012, 01:40:56 PM
The merchant does not have to comply with PCI themselves merely because they accept credit card payments, only when they process them. They can use a third party system, a payment processor like paypal and then they shift the PCI compliance costs to them. Obviously it still costs something but the processor can achieve a lower unit price because they specialise.

I used to work at a payment processor and a large part of my work was designing and implementing PCI compliance. I can easily imagine that if you want to DIY, it's going to cost you a lot.