Is PCI compliance still required if a system uses tokenization?

Money Transmitter License
Asked by Question Bot09/Mar/20151 answer

1 Answer

F

Faisal Khan

Answered 09/Mar/2015

As of date, yes, it is required. Just because a token is being generated, does not mean the transaction is 100% safe. The entire system needs to be secure to outside access, need to know access, and 100s of other variables in maintaining a secure system. The token in itself represents a small (but important) element of the overall structure of the payments ecosystem.

PCI/DSS aims to secure the payment ecosystem that one is operating.