PCI Self-Assessment Questionnaire/Vulnerability Scanning


SaleSynergy and Data Delivery Service (DDS) have partnered to offer a complete process for merchants to become Payment Card Industry Data Security Standard (PCI DSS) compliant. 

DDS provides data security and compliance management solutions to organizations throughout the world.  DDS will assist all SaleSynergy merchants to secure their critical data and manage industry and regulatory compliance initiatives.  It is the responsibility of all merchants to utilize a third party approved service to validate PCI DSS compliance.  DDS is the approved third party service that SaleSynergy has chosen for our merchants.  DDS offers the most user friendly PCI Management Tool in the industry.  

Please read and print the PCI Checklist to help navigate the PCI Compliance process before proceeding:       

      www.salesynergy.com/pci-checklist

To begin the PCI Compliance process, you must log-in to the joint SaleSynergy/DDS web page.  A separate SAQ must be completed for each Merchant ID.  Your user name and password have previously been provided to you.  To log-in, please click on this link:

      https://www.pciapply.com/pci_fsp_Login.aspx

Once logged-in, follow the detailed instructions provided to help guide you throught the completion of the PCI Compliance process.  In summary, the merchant must accept the terms and conditions of the SaleSynergy/DDS PCI Management Tool program.  Next, the merchant will watch a video introduction to PCI Compliance.  After the video, the merchant fills out a basic questionnaire which leads to the selection of the appropriate Self-Assessment Questionnaire (SAQ).  That selection is primarily based on equipment and communication (SAQ B for dial-up terminals and SAQ C for IP terminals and POS interfaces).  After a successful completion of the SAQ, PCI Compliance is acknowledged by providing a digital confirmation.  Finally, a certificate of validation can be printed.

For SAQ C merchants, those utilizing an IP terminal and/or POS interface, the PCI Security Council requires network scanning.  DDS partners with ComplyGuard Networks for vulnerability scanning and ComplyGuard Networks has been recognized as an approved scanning vendor by the PCI Security Standards Council.   A link from the SAQ to information about the Comply Guard's scanning program is automatically provided for those merchants requiring scanning.