Frequently Asked Questions

Have a question? Look for the answer in our FAQ.

How do I log in to www.myControlScan.com ?

What is PCI compliance?

Why haven’t I heard anything from the card brands regarding PCI compliance?

Can I just download a form from the web and fill it out?

If I only accept credit cards over the phone, does PCI still apply to me?

What does the PCI Compliance Service fee cover?

How do I get the certificate of compliance?

What is the Payment Card Industry Data Security Standard (PCI DSS)?

Who needs to comply with the PCI DSS?

What happens if I do not comply?

My shopping cart/payment gateway/processing is outsourced, why is this my responsibility? If I am breached, wouldn’t it be their fault?

My payment application is already compliant- what else do I need to do?

What is a Self Assessment Questionnaire (SAQ)?

How do I know which Self Assessment Questionnaire (SAQ) to complete?

What is a network security scan?

Do I need vulnerability scanning to validate compliance?

How often do I have to scan?

Does this service protect me from breaches?

What if I’m already working with a compliance company?

I do not want this service.

Can I switch to a new processor who doesn’t require compliance?

What is the cost associated with a compliance failure or data breach?

How do I learn more about PCI DSS?

As a merchant, aren’t I entitled to store any data?

What are the PCI compliance ‘levels’ and how are they determined?

What should I do if I’m compromised?