x

PCI Compliant Environment

We have another merchant relationship that primarily handles the bulk of our transactions (ecommerce, retail, etc.) and they require us to use Security Metrics to complete the PCI Self Eval each year.  Whenever we discuss our operating environment (online software, hardware devices, etc) we also mention that we use Square on a limited basis for mobile or "pop-up" events.  We recently had a consultant come through to ensure we were stating our environment correctly and they are deadset against Square.  They say that the product puts our whole network into PCI scope since it is not P2PE.  Also the only way we could possibly use it is to have a locked down cellular device that only accesses the Square app.  Could you please help me in understanding their concerns and how Square reduces our PCI scope environment?   Thanks in advance for any assistance.

1,170 Views
Message 1 of 2
Report
1 REPLY 1
Super Seller

1,146 Views
Message 2 of 2
Report