Are Nonprofits Required to be PCI Compliant?

Are Nonprofits Required to be PCI Compliant?

The simple answer is yes. All merchants (businesses or organizations) that accept, store, or transmit credit card data must be PCI compliant. This requirement extends to nonprofit organizations, charities, schools, and churches. Even if your organization processes only a very small volume of credit card sales or donations, you must maintain PCI security standards to protect your constituent data.

What Is PCI Compliance?

The Payment Card Industry (PCI) Data Security Standard is a global standard for protecting payment card data (credit and debit cards) and consumer financial data. It incorporates the requirements of the Visa USA Cardholder Information Security Program (CISP) and the Visa International Account Information Security (AIS) program, the MasterCard International Site Data Protection (SDP) program, as well as the security requirements of American Express DSS, DiscoverCard DISC, and the Japan Credit Bureau (JCB).

How Can Organizations Become PCI Compliant?

What is PCI Compliance?

PCI standards were created to protect donor and customer financial data against theft and fraud. To maintain PCI Compliance (certification), all publicly accessible internet devices and any associated domains hosted on them must be audited every three months. So maintaining the PCI standard is an ongoing process, not something your organization can do once and forget about. PCI defines the following three-step process for showing and maintaining compliance:

  1. Assess — Take an inventory of your hardware and business processes involved in credit card processing, and analyze them for vulnerabilities that pose a risk to your cardholders’ personal data. This is generally done with the PCI Self-Assessment Questionnaire (SAQ).
  2. Re-mediate — Fix any vulnerabilities found. The Security Standard mandates that any vulnerabilities found and categorized as Urgent, Critical, or High severity must be corrected within 72 hours of discovery.
  3. Report — Compile and submit required remediation validation records (if applicable) and submit required compliance reports to your merchant service provider.

DoJiggy Software Is PCI Compliant

Choosing a compliant software provider is key to maintaining compliance and safeguarding your donor and constituent data. At DoJiggy, we work hard every day on security and compliance for all of our fundraising software.

Learn more about our strict security policy or contact us to request a current Attestation of Compliance.

DoJiggy Auction Websites
Lisa Bennett

About Lisa Bennett

I’ve been part of the DoJiggy Sales team since 2006, and I genuinely love helping organizations raise more with less stress. Before joining DoJiggy, I worked in the nonprofit world managing special event fundraising, so I understand the challenges (and rewards) that come with it.When I’m not talking fundraising strategy, you’ll usually find me spending time with my teenage son or recharging on my yoga mat.

See other posts from Lisa Bennett

Want to Learn More About
DoJiggy’s Online Fundraising Platform?

We’re here to help.
Call us at (888) 436-1999