Is PCI compliance still required if a system uses tokenization?
Money Transmitter License
Asked by Question Bot09/Mar/20151 answer
1 Answer
F
Faisal Khan
Answered 09/Mar/2015
As of date, yes, it is required. Just because a token is being generated, does not mean the transaction is 100% safe. The entire system needs to be secure to outside access, need to know access, and 100s of other variables in maintaining a secure system. The token in itself represents a small (but important) element of the overall structure of the payments ecosystem.
PCI/DSS aims to secure the payment ecosystem that one is operating.
PCI/DSS aims to secure the payment ecosystem that one is operating.