• Support Portal
  • 800.234.5695
  • Sales Meeting Request
RoomKeyPMS
  • Products
      cta image
      Introducing: Mobile Check-In & Check-Out

      Take advantage of touch-less mobile pre-arrival to speed up check-in and keep staff and guests physically distanced.

      Learn More

    • Property Management Software

      A simply feature rich PMS to manage your hotel

    • Mobile Guest

      A complete mobile experience for your guests built into the PMS

    • Embedded Payments

      Securely manage mobile, device and PMS payments in one place.

    • Capital

      Quick access to growth capital for your property

    • Direct & Distribution

      Powerful cost effective CRS integrated with the PMS

    • Rate Shopper

      Affordable competitor pricing and performance

    • Interfaces & Integration Marketplace

      Discover and connect with 100s of 3rd party products

  • Pricing
  • Resources
    • Cheat Sheets

      Short reads to help manage your hotel

    • How-To Guides

      Step by step guides for hotel operations

    • Whitepapers

      A wider look at industry trends

    • Videos
    • All Resources
  • Blog
  • Customers
  • Company
      cta image
      Press Release - Mobile Check-In & Check-Out with Automated Emails

      Increase automation to offset lower staffing levels

      Learn More

    • About

      A team of hoteliers managing 70,000 rooms

    • Press Releases

      News across our products, industry and team

    • Careers

      Opportunities to work with a 20-year hospitality leader

    • Customer Service

      Our local team of hoteliers to support you

Book a Demo
Book a Demo

Property Management System

What Hoteliers Need to Know About PCI Compliance

What Hoteliers Need to Know About PCI Compliance | Hotel PMS | RoomKeyPMS

Tim

President

October 8, 2019

Hoteliers have a responsibility to ensure that their customer’s personal data and payment information is handled properly and securely. Failure to do so can risk the exposure of that private data into the wrong hands, in the event of a system security breach. In order to reduce that risk and properly protect customer information, the Payment Card Industry Security Standards Council (also known as the PCI SSC) was established by five main credit companies: Visa, Mastercard, American Express, Discover and JCB.

The PCI SSC has mandated a minimum safety standard across the industry in regards to how payment information is captured, sent, processed and stored. This Payment Card Industry Data Security Standard (PCI DSS) was originally released in December 2004, and as of February 2018, PCI DSS 3.2 is the newest version that must be adopted by all organizations that process payment transactions.

Does PCI DSS apply to you?

Any organization that stores, processes or transmits cardholder data must adhere to the most current version of the PCI DSS, regardless of the size of their organization or transaction volume. This includes organizations who process payment transactions in person, over the phone or mail, or via ecommerce.

The standards are strict, but are designed to protect cardholders and their personal and financial information, as well as the organization that is processing the transactions.

What are the specific requirements of the PCI DSS?

The PCI DSS specifies twelve requirements, which are organized into six “control objective” groups:

  1. Build and Maintain a Secure Network and Systems
  2. Protect Cardholder Data
  3. Maintain a Vulnerability Management Program
  4. Implement Strong Access Control Measures
  5. Regularly Monitor and Test Networks
  6. Maintain an Information Security Policy

While each updated version of the PCI DSS has different sub-requirements under each of these control objectives, the twelve main requirements have not changed since the standard was initially launched, and are summarized below:

  1. Install and maintain a firewall configuration to protect cardholder data
  2. Do not use vendor-supplied defaults for system passwords and other security parameters
  3. Protect stored cardholder data
  4. Encrypt transmission of cardholder data across open, public networks
  5. Protect all systems against malware and regularly update anti-virus software or programs
  6. Develop and maintain secure systems and applications
  7. Restrict access to cardholder data by business need to know
  8. Identify and authenticate access to system components
  9. Restrict physical access to cardholder data
  10. Track and monitor all access to network resources and cardholder data
  11. Regularly test security systems and processes
  12. Maintain a policy that addresses information security for all personnel
PCI DSS Requirements | RoomKeyPMS
Photo Credit: PCI Security Standards Guide

There are four levels of PCI Compliance based on an organization’s annual transaction volume, as well as their level of risk (which is assessed by the payment brands, like Visa or Mastercard, who, in addition to the PCI DSS requirements, also each have their own compliance requirements as well).

  • Level 1 – Over 6 million transactions annually
  • Level 2 – Between 1 and 6 million transactions annually
  • Level 3 – Between 20,000 and 1 million transactions annually
  • Level 4 – Less than 20,000 transactions annually

If you accept or process payment cards, PCI DSS requirements apply to your organization. However, because smaller merchants often have simpler environments and potentially fewer systems at risk, their PCI DSS compliance requirements may be reduced and formal validation may not be mandatory. Compliance validation and reporting requirements specifically for smaller merchants will need to be confirmed by their merchant bank or the payment brand they work with (ie: Visa, Mastercard, etc.).

What happens if an organization is non-compliant?

Non-compliance to the PCI DSS requirements may result in substantial financial penalties (ranging from $5,000 to $100,000 per month), which are applicable even to small merchants. But more importantly, non-compliance may mean an organization and its systems and customers are at a security risk, which could have even more substantial repercussions.

Following PCI DSS can help you to ensure your systems are and remain secure and protected.

How can you ensure your hotel is PCI DSS compliant?

Merchants can complete a Self-Assessment Questionnaire (SAQ) which is a self-validation tool to assess security for cardholder data. Additionally, it’s important for hoteliers to work with PMS or Payment Solution tools which are already certified as PCI DSS compliant and who can provide an Attestation of Compliance (AOC).

How can you learn more about PCI DSS requirements and compliance?

For more detailed information about PCI DSS and its requirements, visit the PCI Security Standards website for access to documentation and training, or download the current Quick Reference Guide.

 

Security is essential in today’s sensitive breach environment. Keep your hotel PCI compliant and your guests safe with the RoomKeyPMS Payments solution. Contact our team today to book a demo and protect your hotel and guests.

 

Photo Credit: Rupixen on Unsplash

Hotel Payment Processing

Find Out All You Need To Know for Your Hotel

Download Cheat Sheet

About the author

Tim

President

Tim is president of RoomKeyPMS. Tim joined the company after his pioneering web application company was acquired by RoomKeyPMS. After acquiring his BBA he spent over 15 years developing web applications for hospitality clientele ranging from golf and ski resorts to international retreats. Although Tim’s passion lies in the challenge of software and service, he can also be found hunting down the best barbecue or traveling abroad with his family.

You might also like...

Property Management System

Revolutionizing Hotel Financing: How Cash Advances Are Changing the Hospitality Industry

By Tim on May 16, 2023

Read more
The Evolution of a Property Management System and Its Impact on Hoteliers | RoomKeyPMS
Property Management System

The Evolution of a Property Management System and Its Impact on Hoteliers

William Tam Profile Photo | RoomKeyPMS

By William Tam on March 17, 2020

Read more
Skift Research | Hotel PMS Survey | RoomKeyPMS
Property Management System

Skift Research Reports How Vendors like RoomKeyPMS are “Shaking Up” the PMS Space

By Tim on January 28, 2020

Read more

Subscribe to our newsletter!

  • Pricing
  • Customers
  • Blog
  • About
  • Resources
  • Careers
  • Support
  • Privacy Policy
  • Responsible Disclosure Policy
#408 – 55 Water Street, Office #8152 Vancouver, BC V6B 1A1
  • Tel: 604.984.6001
  • Toll Free: 800.234.5695
  • [email protected]
© 2025 NSight Inc. All Rights Reserved.
* please refer to Terms & Conditions
  • Twitter
  • Facebook
  • Instagram
  • LinkedIn

By continuing to browse or by clicking “Accept All Cookies,” you agree to the storing of first- and third-party cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.
Cookie Policy | Privacy Policy

Manage preferences

Privacy Preference Center

Close
  • Your Privacy
  • Essential cookies
  • Performance Cookies
  • Functional Cookies
  • Third-party cookies

Your Privacy

When you visit any web site, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences, your device or used to make the site work as you expect it to. The information does not usually identify you directly, but it can give you a more personalized web experience. You can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, you should know that blocking some types of cookies may impact your experience on the site and the services we are able to offer.

Privacy Policy

Required
Personal data collected during visits to our websites are processed by us according to the legal provisions valid for the countries in which the websites are maintained. Our data protection policy is also based on the data protection policy applicable to RoomKeyPMS. Read more

Cookie Policy

Required
RoomKeyPMS uses cookies and similar technologies, such as HTML5 web storage and local shared objects (all referred to as ‘cookies’ below), to record the preferences of users and optimize the design of its websites. They make navigation easier and increase the user-friendliness of a website. Read more

Essential cookies

These cookies are essential for websites and their features to work properly. Without these cookies, services such as the vehicle configurator may be disabled.

Cookies used

  • WordPress Required
  • Wordfence Required

Performance Cookies

These cookies collect information about how you use websites. Performance cookies help us, for example, to identify especially popular areas of our website. In this way, we can adapt the content of our websites more specifically to your needs and thereby improve what we offer you. These cookies do not collect personal data. Further details on how the information is collected and analyzed can be found in the section ‘Analysis of usage data’.

Cookies used

  • Google Analytics Sign out

Functional Cookies

These cookies allow the provision of enhance functionality and personalization, such as videos and live chats. They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies, then some or all of these functionalities may not function properly.

Cookies used

  • Zopim

Third-party cookies

These cookies are installed by third parties, e.g. social networks. Their main purpose is to integrate social media content on our site, such as social plugins.

Cookies used

  • Google / DoubleClick
  • Google / Advertising
  • CloudFlare
  • Facebook
  • LinkedIn
  • Bing
  • Sumo
  • Reddit
More information Save
Verified by MonsterInsights