Hi,
I'm in the process of setting up a site for a client using HikaShop and they want to use the SagePay credit card processor. One of the requirements to use SagePay is that the software must be "PCI-DSS Certified".
Here's the quote:
The Payment Application - Data Security Standard (PA-DSS) requires that any software that stores, processes or transmits credit card data must be PA-DSS certified by July 1, 2010. Coupled with this, as a merchant, if you use a software product to store, process or transmit credit card data, then effective July 1, 2010, when asked by your Merchant Acquirer (credit card processor), you must validate that the software you are using is PA-DSS certified.
So, my question is, is HikaShop PCI-DSS certified? Does it need to be? I assume the above quote is not just from SagePay by would be applicable to any e-commerce program???
Thanks!