cancel
Showing results for 
Search instead for 
Did you mean: 
robert151
Level 1

PCI compliance and security metrics is this a scam?

 
3 Comments 3
Kurt_M
QuickBooks Team

PCI compliance and security metrics is this a scam?

Hello there, @robert151.

 

It looks like you've already posted this here in the Community space, and my colleague responded to it. We'll be more than happy to route you to her response to your previous post. Feel free to visit the link below.

 

https://quickbooks.intuit.com/learn-support/en-us/account-management/re-pci-compliance-[…]w-security...

 

@robert151, feel free to come by and visit us here in the Community space. We'll be happy to help you sort out your QuickBooks-related queries. Take care, and have a nice day!

Fiat Lux - ASIA
Level 15

PCI compliance and security metrics is this a scam?

@robert151 

I know someone went thru it entirely themselves to see how their paid version and you-do-it version compares to our free version and our we-do-it-for-you version. Here’s the breakdown about Intuit’s new mandatory PCI Compliance process, buckle in b/c it’s a lot of info for your benefit:

Security Metrics PCI Test Review:
The initial self-assessment questionnaire is moderately the same as other payment processor do but would be difficult for someone unfamiliar with the type of tech heavy questions, as Security Metrics doesn’t help guide you through this process unless you buy the $195/year package.

FiatLuxASIA_0-1689473350250.png

 

Once the self-assessment questionnaire is complete, you’ll be led to the paywall where you must purchase one of packages above. Unless you opt for the $195/year Intuit Managed package you’ll be completing everything by yourself with little to no guidance.

You’ll answer another 40 or so questions on top of the 50+ you answered in the self-assessment. If these are answered incorrectly, you’ll either instantly be flagged as non-compliant or your upcoming scan will fail and that too will mark you as non-compliant, which leads to more monthly fees hitting your account.

For the scan you’ll need to know your IP address and input it then pick a date within the next quarter to run this scan. If you were to want to scan another time for a separate IP address your business may have, it will cost $129 per extra quarterly scan. Which brings you to $516 per year + whichever package you bought earlier while setting up the account.

Security Metrics does have a good feature of telling you what you need to do to become compliant, but they don’t tell you how to do it (Unless you purchase Intuit Managed PCI Pro $195). There’s a lot to keep track of and answer all while having many important questions not being able to be re-answered if you answered it incorrectly.

If you don’t feel like doing it yourself at the $85 initial cost, or being guided through it at $195, they have a separate yearly package that will do almost everything for you to attain compliance for a steep price of $670. Another option, you should consider having a 3rd party merchant service provider to integrate with QB. Everything listed above one provider does for no extra cost and is built into their $30 fixed fee for newly boarded merchants for the entire duration of their time with them.

DB10
Level 2

PCI compliance and security metrics is this a scam?

I'd like to know who the other provider is that includes this. I started this process and it was so onerous and I stopped because I assumed QB was covering this compliance since I thought we had/have the "everything-included package." Also, we have very few credit card payments - less than a handful a YEAR but we use ACH payments a LOT. Does it only apply to CC payments or both CC & ACH? Is there a minimum CC usage below which PCI compliance isn't an issue? 

Need to get in touch?

Contact us