Visa: Large Retailer PCI Compliance Hits 65 Percent

Visa: Large Retailer PCI Compliance Hits 65 Percent

Written By
Evan Schuman
Evan Schuman
Oct 25, 2007
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Sixty-five percent of the nations largest retailers are now compliant with the industry-standard Payment Card Industry Data Security Standard, Visa reported Oct. 24, up 81 percent from December 2006 and 63 percent since July.

Although the numbers do show a sharp increase, they also reflect the fact that 35 percent—more than 1 out of every 3—of large retailers today are still not PCI compliant, despite the passing of the Sept. 30 deadline and the start of the promised $25,000 per month in fines for non-compliance.

On a potentially even more scary note, Visa reported that PCI compliance among the more numerous Level 2 retailers—ones that process between one million and six million Visa transactions a year—is only at 43 percent, as of Sept. 30.

On the optimistic side of those Level 2 numbers, the Level 2 compliance was barely 15 percent in December 2006 and 33 percent in July, so this does show a healthy increase. Also, the deadline for Level 2 retailers doesnt kick in until New Years Eve of this year so its possible those numbers could sharply increase again by January.

Then again, most Level 2 retailers will have their hands full from late October through late December, so its not certain how much of an increase will materialize.

Visa issued a statement saying that it wants to see the compliance—and not the penalty revenue—go up.

“We’d much rather grow compliance than levy fines,” said Michael E. Smith, senior vice president of Enterprise Risk and Compliance for the U.S. market, Visa. “We’re making steady progress in accelerating merchant compliance with PCI standards to protect cardholder information.”

A promising note was Visa saying that 99 percent of Level 1 and Level 2 retailers “confirmed they are not storing prohibited account data such as magnetic stripe—also known as track data—CVV2 [the security code on the back of the card] and PIN data.” Thats up from the 96 percent that Visa reported in July. Those sets of prohibited data are seen as especially attractive to data thieves.

Retail Center Editor Evan Schuman can be reached at Evan.Schuman@ziffdavisenterprise.com.

Check out eWEEK.coms for the latest news, views and analysis on technologys impact on retail.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.