New PCI Compliance Stats Show Little Change
Written by Evan SchumanJanuary 31st, 2011
The latest PCI compliance reports (data current as of Dec. 31, 2010) show little change for Level 1 and Level 2 merchants, with each group holding at 96 percent. Level 1 had been at 96 percent for months, but the number of retailers in that group jumped from 358 to 377 (since the prior report in June 30, 2010). Level 2 had been at 95 percent, so the 96 percent figure reflects a slight increase. The number of merchants in Level 2, however, dropped from 894 to 881. So if even a few of those 13 retailers had been non-compliant, that could explain the bump up to 96 percent.
As before, Visa has not released figures from Levels 3 and 4, continuing to label them both as “moderate” with no explanation.
February 3rd, 2011 at 1:54 pm
If the Level 3 and 4 statistics were disclosed, it wouldn’t be surprising to see that the percent of those claiming compliance went up in 2010. The push for merchants in this space to check the boxes on an SAQ really ramped up after we passed the July 1 PA-DSS deadline. Unfortunately all this activity isn’t driving improved security. We may never see the real numbers, but all indicators are that 2010 breaches exceed 2009 in the Level 3 and 4 space.
We need more focus on security best practices for the small guys instead of pushing nearly unattainable compliance.
February 11th, 2011 at 8:33 pm
An increasing number of merchants and business owners view PCI compliance fees as little more than a new revenue stream for merchant processors.