Turn on suggestions					
					
	
				
			
		
	
	
	
	
	
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
		Showing results for 
		
	
	
	
	
	
	
	
Get 50% OFF QuickBooks for 3 months*
Buy now@fastmoney If your device has access to a merchant account login, then generally, yes, your device is a possible security weakness.
That said, it doesn't have to be through QB's partner, or even anybody, really; there are ways to do it yourself.
 
					
				
		
Even if you do not process Point of Sale (POS) payments, PCI compliance is required if you handle payment card data in any capacity, @fastmoney. Let me explain how this applies using QuickBooks and adhering to the Payment Card Industry Data Security Standard (PCI DSS).
PCI compliance is crucial for safeguarding your business and customers from theft and fraud by securing customer payment information. Keep in mind that even without data storage, unauthorized access to your devices and through the internet can pose significant security risks.
Any business that handles payment card data must be PCI compliant, whether they take payments online, over the phone, or through invoices—even without a physical POS. Using systems like QuickBooks for these transactions underscores the need for stringent security measures that are compliant with PCI standards.
 
All merchants are required to complete a Self-Assessment Questionnaire (SAQ) based on their methods of storing, handling, and processing card data. To gain a comprehensive understanding of these requirements, I recommend consulting the following resources:
If you are using QuickBooks Payments to accept payments, you can check the deposit speed via QuickBooks Online or the Merchant Service Center. For more details, please refer to this article: Check the deposit speed for your product.
Moreover, maximize the efficiency of your financial processes by collaborating with our QuickBooks Live Expert Assisted team. They're veterans in the field, known for smoothing out financial operations and offering insights tailored to your business. One click connects you to a more prosperous financial path.
Please let me know if you have questions about PCI compliance. The QuickBooks Community is here for you, and we’re committed to resolving your concerns promptly.
How many people have to be completely annoyed by these ambiguous answers before we actually get helpful clear answers? Yes or no--if a user ONLY has quick books process their ACH payments (no POS), do they need this compliance certification? And, if we have to do a self assessment, where the heck is the assessment??? I feel like Quick Books is trying to make it unclear so customers purchase extra things they don't need. They already charge $35/mo AND take 1% of my profits to "process ACH payments" and now you want ME to certify data security for them? Ridiculous. What's the 1% for then?
How many people have to get completely annoyed asking the same question to get an answer that's actually helpful, clear and concrete?
YES OR NO--if you are invoicing through Quick Books and Quick Books taking ACH payments on your behalf is the ONLY way that you receive money (no POS and zero physical handling of any card/account information and no cc processing), do you, or do you not, need to acquire PCI Compliance? And if a self-assessment is required, where is the self-assessment??? Finally, if it's required for users to be PCI compliant when Quick Books is the one processing the payments, what the heck are we paying $35/mo PLUS 1% of all payments for ACH "processing" for? Isn't that the whole reason to pay Quick Books for payment processing; so THEY handle the payments and the compliance? I feel like Quick Books is being ambiguous and vague on purpose to force our hand to pay for a service that is not actually required, but they don't want to tell us that.
I understand how exhausting it is to repeatedly ask for help and still feel dismissed, unheard, or stuck with vague responses, @socialeyes247.
While QuickBooks applications are designed to be secure, the overall security of your environment can still be impacted by other applications on your local computer or network. It's important to note that using QuickBooks Payments services does not automatically make your business PCI compliant. It simply means that specific elements of the transaction processing chain meet PCI compliance standards; however, additional steps may be required on your end to ensure full compliance.
With this, all merchants accepting credit or debit cards must adhere to PCI DSS standards. Your payment handling methods and annual transaction volume determine your validation requirements. Each merchant must complete a Self-Assessment Questionnaire (SAQ), with the specific SAQ based on how you store, manage, and process card data.
Here is an article to help you understand more about PCI DSS Compliance Services: Learn about the PCI DSS Compliance Services.
For the self-assessment, follow the steps below to create an account with SecurityMetrics to streamline the PCI compliance validation process. After finishing it, you can purchase the PCI package and complete an SAQ.
QuickBooks Online (QBO) ACH fees cover payment processing, automation, and convenience—not PCI compliance. Merchants are responsible for securing cardholder data and meeting compliance requirements.
For QBO Payment pricing, all ACH transactions are charged at a 1% fee with a maximum of $10 per entry.
Processing fees vary by payment method: swiped (2.4%), invoiced (2.9%), or keyed (3.4%), and depend on the payment amount. See the screenshot below for details.
Here’s a helpful reference to assist with processing ACH payments and understanding when QuickBooks deposits them into your bank account:
If there's anything else you require additional assistance with managing customer payments and processing fees, leave a comment below.
You have clicked a link to a site outside of the QuickBooks or ProFile Communities. By clicking "Continue", you will leave the community and be taken to that site instead.
 For more information visit our Security Center or to report suspicious websites you can contact us here