PCI Compliance: Are U.K. Businesses Ready?

Not really. They lag behind their U.S. colleagues in meeting PCI security standards, with only 11 percent certified as compliant.

April 22, 2010

LONDON - A new white paper released by CIO Business Technology Leadership reveals that U.K. businesses lag far behind their U.S. colleagues in meeting PCI security standards, with only 11 percent of U.K. organizations currently certified as PCI compliant.

The study found that 58 percent of Level 1 merchants ?" those processing more than six million transactions annually ?" met the security standards, with all other merchants meeting a collective 4 percent to 8 percent compliance rate.

The study revealed that the majority of Level 3 and Level 4 merchants perceive their existing security protocols to exceed those required by PCI. By contrast, none of the Level 1 and 2 merchants surveyed held that opinion, assessing PCI-DSS requirements as "on par" with their security procedures.

The study concluded that organizations underplay PCI requirements and that most face a steep challenge at achieving PCI compliance by the September 2010 deadline.

Among the key findings:

  • 12% of U.K. organizations that process credit and debit cards are certified as PCI compliant.
  • 57% of U.K. retail organization said that they do not fully understand PCI-DSS.
  • 77% of U.K. organizations had no difficulty in securing funding to ensure PCI-DSS requirements are met.
Advertisement
Advertisement
Advertisement