Skip to main content
July 15, 2023
Question

Self Assessment questionnaire PCI compliance

  • July 15, 2023
  • 4 replies
  • 0 views
Where do I find self assessment questionnaire for PCI compliance.   I have called merchant services and they know nothing yet I continue to receive emails to pay for a service

4 replies

July 15, 2023

It's nice to see a new face here, @Karen11.d. 

 

Thank you for your interest in finding a self-assessment questionnaire for PCI compliance. I'll share more details to help you manage your local security environment.

 

PCI DSS Standards are required for all merchants that accept credit or debit cards. If you do these via the QuickBooks site, be PCI compliant. 

 

First, create an account with SecurityMetrics to streamline the PCI compliance validation process. After finishing it, you can purchase the PCI package and complete an SAQ.

 

  1. Select Sign Up, then fill out all the fields on the Create Account page.
    SecurityMetrics_CreateAccount_US_Ext_12032021.png
  2. Select Create Account, then follow Intuit FastPass to determine your PCI compliance requirements.
  3. Select Next then select a security package that best fits your business.

 

To know more about PCI DDS compliance, please see this article: Learn about the PCI DSS Compliance Services.

 

See this guide for the FAQs along with tools and services included in the QuickBooks PCI Service: Learn about QuickBooks PCI Service.

 

If you have other concerns about your QuickBooks account, please don't hesitate to let me know in the comments below. I'll gladly help. Take care.

January 17, 2024

What IP address are they specifically wanting, when setting up PCI. It asks me to "Enter the target(s) (IP address or Domain) you need scanned here." 

What are they asking for and where do I find it?

Adrian_A
January 17, 2024

Hello Misty,

 

You'll have to enter the IP address of the device you'll be setting up for the merchant services. 

 

To locate the IP address, you can follow these steps:

 

  1. Press the Windows button on your keyboard.
  2. Enter and select Settings.
  3. Click Network & Internet.
  4. On the Find a setting field, type in Properties.
  5. Click View your network properties.

 

Moreover, you can check this article to learn more about PCI compliance: Learn more about QuickBooks PCI Compliance.

 

Keep me posted whenever you have concerns about merchant services.

Fiat Lux - ASIA
July 16, 2023

@karen.duncan434@ 

I know someone went thru it entirely themselves to see how their paid version and you-do-it version compares to our free version and our we-do-it-for-you version. Here’s the breakdown about Intuit’s new mandatory PCI Compliance process, buckle in b/c it’s a lot of info for your benefit:

Security Metrics PCI Test Review:
The initial self-assessment questionnaire is moderately the same as other payment processor do but would be difficult for someone unfamiliar with the type of tech heavy questions, as Security Metrics doesn’t help guide you through this process unless you buy the $195/year package.

 

Once the self-assessment questionnaire is complete, you’ll be led to the paywall where you must purchase one of packages above. Unless you opt for the $195/year Intuit Managed package you’ll be completing everything by yourself with little to no guidance.

You’ll answer another 40 or so questions on top of the 50+ you answered in the self-assessment. If these are answered incorrectly, you’ll either instantly be flagged as non-compliant or your upcoming scan will fail and that too will mark you as non-compliant, which leads to more monthly fees hitting your account.

For the scan you’ll need to know your IP address and input it then pick a date within the next quarter to run this scan. If you were to want to scan another time for a separate IP address your business may have, it will cost $129 per extra quarterly scan. Which brings you to $516 per year + whichever package you bought earlier while setting up the account.

Security Metrics does have a good feature of telling you what you need to do to become compliant, but they don’t tell you how to do it (Unless you purchase Intuit Managed PCI Pro $195). There’s a lot to keep track of and answer all while having many important questions not being able to be re-answered if you answered it incorrectly.

If you don’t feel like doing it yourself at the $85 initial cost, or being guided through it at $195, they have a separate yearly package that will do almost everything for you to attain compliance for a steep price of $670. Another option, you should consider having a 3rd party merchant service provider to integrate with QB. Everything listed above one provider does for no extra cost and is built into their $30 fixed fee for newly boarded merchants for the entire duration of their time with them.

 

July 20, 2023

Can I complete the self assessment questionnaire from the PCI standards website, and send it to Quickbooks without paying for this service? I am SAQ-A.

July 20, 2023

Hello there, @mattp42-bellsout. Let me share some insights regarding compliance with QuickBooks Payment Card Industry Data Security Standard (PCI DSS).

 

PCI compliance is vital for protecting your business and customers from theft and fraud. Major payment card providers like Visa, MasterCard, American Express, and Discover require annual PCI compliance for businesses that handle card data. Whether you accept, store, or transmit payment card data, PCI compliance is mandatory.

 

In regards to your question, I recommend contacting SecurityMetrics to verify if you need to subscribe or not. The steps below will walk you through the complete steps.

 

  1. Go to this link: SecurityMetrics.
  2. Select Sign Up. Fill out all the fields on the Create Account page.
  3. Click Create Account. Then, follow Intuit FastPass to determine your PCI compliance requirements.
  4. Hit Next. Then, select a security package that best fits your business.

 

Check out this article for more information about the requirements, how to deal with it, and how to be compliant: Learn about QuickBooks PCI Service

 

Here's more information about accepting electronic customer payments for online invoices and in-person sales: Take and process payments in QuickBooks Online with QuickBooks Payments

 

Let me know if you need further information about the PCI compliance. I'm always here to answer them for you. Keep safe, and have a wonderful day!

June 19, 2024

I have the same question. I am inundated by e-mails and phone calls from Security Metrics but I understand that I can do a self-assessment instead. Except I cannot find any information on that.

June 19, 2024

Thank you for joining this thread, Weigandi. I assure you I can help you where you can find your self-assessment question.

 

Intuit has partnered with SecurityMetrics, a leading PCI service provider, to help merchants securely handle, process, and store payment card data.

 

First, signing up to SecurityMetrics simplifies the PCI compliance validation process. Once done, you'll receive the self-assessment question in your email.

 

Here's how:

 

  1. Select the Sign-up, then fill out the information needed.
  2. Click Create Account, then follow the Intuit FastPass to determine your PCI compliance requirements.
  3. Select Next, then click the security package that best fits your business.

 

If you have questions about the self-assessment, you can check the phone number in this article: Learn about the PCI DSS Compliance Services.

 

You can also check this article to learn more about PCI Compliance: Learn about QuickBooks PCI Compliance.

If you have other concerns besides the self-assessment, you can click the comments below. Stay safe and have a good one!

September 20, 2024

I hope this information helps someone else since it is very clear the support team is goal oriented in pushing this onto everyone. 

 

 

To complete the PCI Compliance Assessment in QuickBooks Payments, follow these steps:

  1. Log into QuickBooks Online:

  2. Go to the Payments Section:

    • In the left-hand menu, click on "Settings" (the gear icon) in the upper right corner.
    • Under the "Your Company" section, select "Account and Settings".
    • Next, go to the "Payments" tab.
  3. Look for PCI Compliance Notifications:

    • In the Payments section, look for any messages or notifications related to PCI compliance. QuickBooks will often notify you if an assessment is needed.
    • If prompted, follow the on-screen steps to complete the PCI compliance process. You may be redirected to a third-party provider, such as SecurityMetrics, which handles PCI assessments for QuickBooks Payments.
  4. Complete the PCI Compliance Assessment:

    • The assessment typically involves answering a series of questions regarding how your business processes and handles payment card data.
    • If you use QuickBooks Payments exclusively for processing payments and don’t store any sensitive card data yourself, the assessment is usually straightforward.
  5. Download and Save Your PCI Compliance Certificate:

    • Once completed, you’ll receive a confirmation of your compliance, usually in the form of a certificate. Make sure to save a copy for your records.
    • If required by your bank or payment processor, provide them with a copy of your PCI compliance certificate.
  6. Contact QuickBooks Support (If Needed):

    • If you don’t see any PCI compliance-related options or need further assistance, you can contact QuickBooks Payments support for clarification on your status and next steps.

By completing the PCI compliance assessment, you ensure that your business adheres to the required standards for processing credit card payments securely.

September 22, 2024

There are 9 versions of the questionnaire. Anyone have an idea which one is for a quickbooks merchant who does all transactions either through invoicing or through the quickbooks card reader (mobile) and no transaction data is stored locally.