Moneris, a leading provider of payment processor solutions, offers a comprehensive suite of products including Smart Devices, Payment Devices, Online Payments, and Self-Checkout Kiosks. Our commitment to maintaining the highest level of security is demonstrated through our adherence to the Payment Card Industry Data Security Standard (PCI DSS) v4.0 requirements for both our products and underlying infrastructure.
We understand the diverse needs of our merchants, which is why we provide a range of payment solutions. Our Integrated Devices, for instance, empower merchants with greater control over their Devices. However, it is important to note that, with the exception of Standalone and Semi-Integrated Devices, Moneris does not have full control over the security of the operating system, packages, or applications deployed by our merchants.
In accordance with the PCI DSS, it is the responsibility of our merchants to ensure compliance with the relevant requirements pertaining to merchant-deployed operating systems, packages, and applications. While Moneris is responsible for meeting PCI DSS compliance and providing an Attestation of Compliance (AOC), this document serves as an outline of the specific responsibilities for merchants that are leveraging Moneris solutions.
It is crucial for merchants to understand that certain requirements are solely the responsibility of Moneris, while others are solely the responsibility of the merchant. Additionally, there are shared responsibilities that require collaboration between both parties. Merchants who utilize Moneris products within their cardholder data environment (CDE) must deploy services in a manner that aligns with the PCI DSS.
To facilitate the pursuit of PCI compliance, we highly recommend that merchants refer to the responsibility matrix provided in this document. This matrix serves as a valuable tool during PCI audits, enabling merchants to effectively fulfill their obligations and maintain a secure environment for cardholder data.
Purpose:
This document outlines the PCI DSS v4.0 responsibilities between Moneris as a Service Provider and its merchants. The guidance within this document applies only to merchants and not service providers who leverage Moneris solutions. Please reach out to your Moneris contact for additional support.
Third Party Service Provider (TPSP) Responsibilities Matrix Overview:
According to PCI DSS v4.0 Requirement 12.9.2, Moneris, as a service provider, is obligated to support its merchant's information requests in order to fulfill Requirements 12.8.4 and 12.8.5. This includes providing the following upon merchant request:
• PCI DSS compliance status information for any service performed by the TPSP on behalf of merchants (Requirement 12.8.4).
• Information regarding the TPSP's and the merchant's respective responsibilities for PCI DSS requirements, including any shared responsibilities (Requirement 12.8.5).
This document details the PCI DSS requirements that fall under the Moneris' responsibility as a TPSP and those that are the merchant's responsibility, including any shared responsibilities (Requirement 12.8.5).
Scope and Approach:
The approach for determining responsibilities between Moneris and its merchants were to categorize the several types of Moneris payment Devices and solutions based on their functionalities and use. This categorization helped define the scope of the Devices and solutions. The scope of the TPSP RACI Matrix encompasses the PCI DSS responsibilities between Moneris and it's merchants which are categorized by Moneris' seven (7) types of payment Devices and solutions described below.
1. Standalone Devices - Dial up: Payment devices that use a dial up network connection. The application used in these devices are developed and managed by Moneris. The Moneris application handles the cardholder data (CHD) and the communication with the Moneris host, while the merchant only sends the transaction amount and other parameters to the device. This reduces the merchant's PCI compliance scope and responsibility, as they do not have to deal with the payment host interface or the encryption of the CHD. To determine Merchant responsibilities for Standalone Devices - Dial Up, we have leveraged the guidance found under Merchant Eligibility Criteria for Self-Assessment Questionnaire (SAQ) B. For more information, please see the Appendix for reference.
In scope products: Moneris ICT250, Moneris VX 520, Moneris VX 820, Moneris IWL220
2. Standalone Devices: Payment and smart devices with wireless / IP network connection. The application used in these devices are developed and managed by Moneris. The Moneris application handles the CHD and the communication with the Moneris host, while the merchant only sends the transaction amount and other parameters to the device. This reduces the merchant's PCI compliance scope and responsibility, as they do not have to deal with the payment host interface or the encryption of the CHD. To determine Merchant responsibilities for Standalone Devices, we have leveraged the guidance found under Merchant Eligibility Criteria for SAQ B-IP. For more information, please see the Appendix for reference.
In scope products: Moneris Go Terminal Plus, Moneris Go Terminal, Moneris Core V400m, Moneris Core V400c, Moneris Core Desk/5000, Moneris Core Move/5000, Moneris ICT250, Moneris VX 520, Moneris VX 820, Moneris IWL220, Moneris IWL255
3. Semi-Integrated Devices: These devices use a Moneris application that runs on a device such as a PIN pad or a mobile phone. The Moneris application handles the CHD and the communication with the Moneris host, while the merchant only sends the transaction amount and other parameters to the device. This reduces the merchant's PCI compliance scope and responsibility, as they do not have to deal with the payment host interface or the encryption of the CHD. To determine Merchant responsibilities for Semi-integrated Devices, we have leveraged the guidance found under Merchant Eligibility Criteria for SAQ B-IP. For more information, please see the Appendix for reference.
Note: Moneris Kiosks are considered an semi-integrated solution. However, these devices are not in scope as Moneris does not manage the software in the kiosks and only provides the hardware to merchants.
In scope products: Moneris Go PINPad, Moneris Go Slim, Moneris Go Unattended, Moneris Go Terminal Plus, Moneris Go Terminal, Moneris Core V400m, Moneris Core V400c, Moneris Core Desk/5000, Moneris Core Move/5000, Moneris ICT250, Moneris VX 520, Moneris VX 820, Moneris IWL220, Moneris IWL255, POSPad IPP320, POSPad P400, POSPad E355, POSPad ICMP, Direct Connect UX301, Direct Connect UX410, Direct Connect UX300
4. Point-to-Point Encryption (P2PE) Devices: These devices are PCI SSC-listed approved devices that Moneris provides to its merchants. P2PE Devices helps reduce the PCI scope of merchants. To determine Merchant responsibilities for P2PE Devices, we have leveraged the guidance found under Merchant Eligibility Criteria for SAQ P2PE. For more information, please see the Appendix for reference.
In scope products: POSPad P400, Moneris Go Slim, Moneris Go Terminal Plus
5. Payment Platforms & Gateways: Payment platforms & gateways are Moneris solutions that allow merchants to accept online payments from their merchants through a secure and encrypted connection. To determine the merchant responsibilities for Payment Platforms & Gateways, we have leveraged the guidance found under Merchant Eligibility Criteria for SAQ D. For more information, please see the Appendix for reference.
In scope products: IPGate, Moneris Gateway, Transit Gateway, Terminal Gateway, Moneris Cloud
6. Hosted Solutions - Cardholder Facing: Hosted Solutions - Cardholder Facing including Moneris Checkout are hosted eCommerce (iFrame with JavaScript integration) solution that collects CHD and sends it to Moneris Gateway to process transactions. This solution is an integration option for merchants to process e-commerce transactions from their website. To determine the merchant responsibilities for this hosted solution, we have leveraged the guidance found under Merchant Eligibility Criteria for SAQ A-EP. For more information, please see the Appendix for reference.
In scope products: Moneris Checkout, Hosted Pay Page (HPP)
7. Hosted Solutions - Merchant Facing: These are Moneris hosted solutions that allow merchants to process payments online using their own computer and web browser, also known as a Virtual Terminal. They are typically used for eCommerce and card-not-present transactions (e.g., such as phone orders, mail orders, or recurring payments). To determine the merchant responsibilities for this hosted solution, we have leveraged the guidance found under Merchant Eligibility Criteria for SAQ C-VT. For more information, please see the Appendix for reference.
In scope products: Virtual Terminal, Moneris Go Portal, Merchant Direct, Merchant Resource Centre
8. Merchant Integrated Devices: These are devices where the merchant's point of sale software, Electronic Cash Register (ECR), is responsible for creating and sending the payment messages to the Moneris host. The merchant also integrates with a device to capture the CHD and send it back to the ECR. The merchant has more control and customization over the payment process, but also more responsibility for securing the CHD in their environment. To determine the merchant responsibilities for Merchant Integrated Devices, we have leveraged the guidance found under Merchant Eligibility Criteria for SAQ C. For more information, please see the Appendix for reference.