Skip to main content
Renae T
December 30, 2022
Solved

Security Metrics sent an email for PCI compliance. Is this legit?

  • December 30, 2022
  • 12 replies
  • 0 views
I called QBO after starting the signup process and was told it was a scam, but now I'm not sure and want to continue if this is something I should be doing.
Best answer by rvrfrf

Thanks for reaching out to the Community, Renae T.

 

SecurityMetrics is an official partner of Intuit. They provide streamlined PCI DSS compliance services for QuickBooks Payments accounts.

 

After creating an account with SecurityMetrics, you'll be able to complete their FastPass and purchase a PCI package that works best for your business.

 

I've also included a detailed resource about working with PCI compliance which may come in handy moving forward: Intuit Security Center - PCI Compliance

 

I'll be here to help if there's any additional questions. Have an awesome Friday!

12 replies

December 30, 2022

Security Metrics, as well as PCI Compliance are actually legit.  

If you're not PCI compliant, you could get fined.  

Not sure who QB uses for PCI compliance, either.  Security Metrics is a company out of Orem Utah. You can look them up, and call them, if you're still not sure and maybe don't receive a better answer, here. 

July 18, 2023

Trying to post this at the top of the thread as I have many questions.

 

In the e-mail (snip below) they say there are multiple companies that we can use to become PCI compliant, I'm already compliant through another merchant account and don't believe I need to then become compliant with a service I strictly allow the customers to pay online with as I don't integrate QBO Payments with any 3rd party. I belivve this is misleading expecially charging customers to "become PCI compliant" you either are or are not PCI Compliant. 

 

In fact, my other merchant services account does not charge to certify PCI compliance and nor should whomever is partnered with Intuit. 

 

If you really dig and really answer all the questions truthfully to ANY PCI compliance and if you are handling the PII (credit card numbers, etc) in your hands and the customer is not entering them into a company site like Intuit directly then it is nearly impossible for most small businesses to truely be 100% compliant, it is simply a way for the mechant service processing companies to shift blame to you under the veil of "protecting the customers information" Further, most companies want you to open back doors into your network so they can scan it for whatever they are scanning for, listen, if you cannot get in from outside then I'm doing my job and do not need to open a door for you to access. I'm not creating gaping holes in my network for a network I have no control of. Further, I do not see Intuit posting their PCI compliance certificates anywhere, how do WE know that you are really PCI compliant with OUR customer's data?

 

I think PCI Compliance had great intentions, and it is a great way for you to review your own processes, policies, network, devices etc every year to have as best proteciton as you can but in the end especially with Intuit Payments, this seems to be a money driven task that is pointless for 99% of intuit merchant services customers. 

 

I can't even get a hold of anyone at Security Metrics or QUICKBOOKS for that matter to have this discussion so with today 7/18/23 being the last day of "GET IT NOW OR ELSE" I would hope that Quickbooks or rather Intuit would send out a much better email with explination on how we can use our own 3rd party vendors to be "PCI Compliant" rather than this scammy company Security Metrics sending out these seemingly threating e-mails with "LAST DAY" "Better do it now" 

 

You can do better Intuit.

 

Exerpt from E-mail I received.1

"...There are multiple companies that provide security and compliance services you can use to become PCI compliant. Intuit has partnered with SecurityMetrics to help merchants become PCI compliant. You can receive a partner discount by using your email address ([email address removed]) to sign up for services. Visit the following link to get started online: [removed] or you can call them at [removed] ...." 

 

 

bahamabreeze
December 19, 2023

If you go to the PCI Security website it shows that the credit card companies are the ones who started the website. That totally explains the confusion.

 

Who are the founders of the PCI Security Standards Council?

The founders of the PCI Security Standards Council are American Express, Discover Financial Services, JCB, Mastercard, and Visa Inc.
 
November 2021
Article Number 1227
rvrfrfAnswer
December 30, 2022

Thanks for reaching out to the Community, Renae T.

 

SecurityMetrics is an official partner of Intuit. They provide streamlined PCI DSS compliance services for QuickBooks Payments accounts.

 

After creating an account with SecurityMetrics, you'll be able to complete their FastPass and purchase a PCI package that works best for your business.

 

I've also included a detailed resource about working with PCI compliance which may come in handy moving forward: Intuit Security Center - PCI Compliance

 

I'll be here to help if there's any additional questions. Have an awesome Friday!

March 5, 2023

Is it true you can be fined for not being compliant?

Daniela_A
March 5, 2023

Hello there, @Gotcha.

 

As much as I wanted to help you, however, this falls outside the scope of what we're able to support with on the Community. To ensure you'll be able to get the correct information, I'd suggest contacting PCI directly. You may go to this link to reach them:  https://www.pcisecuritystandards.org/contact_us/.

 

For further QuickBooks related concern, feel free to utilize this page: View all help.

 

You can go back here if you have more questions. I'm right here together with the Community people to help you out. Stay safe!

June 15, 2023

I got the email and they said Intuit requires my company to be PCI compliant which I believe is not true.  Intuit needs to have a chat with Security Metrics and tell them to stop misleading customers.  I personally think it is junk email scaring people to buy their product.  We take payments through Intuit, but never handle any customer credit card information.  So I wager it is complete JUNK EMAIL...but this is just my opinion.

 

June 15, 2023

looks like PCI wants $399 per year for small business compliance - WOW.  Maybe they give a discount for Intuit users I don't know, I don't have time to inquire or put up with another sales pitch, but If I have to pay an additional $400 per year to use QB online, we may stop credit card payments altogether...this is pretty bad.  We used to use quickbooks desktop and they did not require this ,so I am really confused and disappointed.

 

June 22, 2023

I use dtop and they are requiring it.  

June 23, 2023

If you are not storing your client's credit card and bank information, you do not need this.  Regardless of what Security Metrics' email says. 

July 17, 2023

Here are some helpful links and hints I've found:

 

Find out your SAQ with the Self-Assessment:

https://listings.pcisecuritystandards.org/documents/SAQ-InstrGuidelines-v3_2.pdf 

 

If your SAQ is A then all should need to do is fill out this:

https://docs-prv.pcisecuritystandards.org/SAQ%20(Assessment)/SAQ/PCI-DSS-v4-0-SAQ-A-r1.pdf 

 

Intuits AoC (Assentation of Compliance)

https://compliance-portal.app.intuit.com/app/PCI-DSS 

 

Somehow give your completed SAQ A and a copy of Intuits AoC to QuickBooks to show your compliance.

July 17, 2023

Geesh...Just tell everyone this!

July 17, 2023

Yet QB is allowing Secure Metrics to send out aggressive emails telling their clients that subscribing to their products is mandatory and that you may be fined by QB if you do not.

July 17, 2023

VERY scammy

July 18, 2023

After reading all of the responses to this not quite a scam, but very disingenuous email, I have come to the conclusion that 1.) If you, like me, are not handling credit cards directly and are not storing any credit card numbers or financial data, it is not required of you.  ALL of my credit card transactions are processed through QuickBooks.  QuickBook handles the transaction and stores data.  It is Quickbooks who needs to be compliant.  I pay QB 2.9% +25¢ per transaction for this service.  Part of that money is because QB needs to be compliant.  2.) It leads you directly to a QB partner and makes it appear was though this is your only choice.  It is not your only choice and I would avoid SecurityMetrics on principal.  I am paying QB for a service.  But they want me to pay their partner for what QB is obligated to have.  3.  You can't send me a "Final Notice" to cover a data breach when I have no data.

November 11, 2023

Thank you all for this informative discussion and insights. I have been very stressed over Security Metrics harassment. I don't mind completing a questionnaire for Intuit, if need be. But with Security Metrics, you can't even pass 25% completion of the form without making your purchase option.

 

Like many of the folks on this thread, clients pay us via QB. I'm going to have Gmail mark Security Metrics as spam.

January 3, 2024

I don't believe it's a completely legitimate company. I purchased the service recommended by Intuit. They stored my bank information and enrolled me in automatic payment for the second payment. When I logged into my account on their website, I realized that they don't give you access to your payment information. I also did not receive any explanatory email about this automatic payment. In the end, I had to call and have customer service send me an email confirming the deactivation of the automatic payment. What a disappointment. I'd screenshot shows a service expiring, not an automatic autopayment due coming.

 

[Removed]

January 3, 2024

I had to call

amex and have them cancel

it in disputes I hope it is resolved 

August 29, 2024

We are PCI compliant through Clover.

Where do I attached my certificate?

August 29, 2024

Hi there, @jmeyers2.

 

Since you're already PCI compliant outside QuickBooks, you don't need to attach the certificate, as proof isn't required currently.

 

Also, please know that as long as you have an active MID, you'll receive system-generated email notifications about the PCI DSS Compliance Services. You can however disregard them since you already are.

 

For more comprehensive information about PCI Compliance, feel free to visit these articles:
 

 

You can add a Reply below if you have other questions related to PCI compliance or need assistance performing tasks inside the program. We'll be here to assist you anytime.

September 19, 2024

What in the world is going on here??  This "Intuit partner" is engaging in deceptive practices, threatening Intuit customers and lying about whether or not this is "required", and Intuit has allowed this to go on for OVER A YEAR???  

 

I demand to know why.  I almost filled all of this out.  It is posed as if it is a strict Intuit requirement and that if I don't do it, I won't be able to continue to accept credit cards.  This is OUTRAGEOUS!

September 18, 2024

Now I am glad that we are moving away from "Go Payment".    Square has been so much easier to use.