Skip to content

Commit a383c9d

Browse files
committed
Brings documentation in line with new PCI-related macros
1 parent ff99fc6 commit a383c9d

2 files changed

Lines changed: 23 additions & 13 deletions

File tree

source/moto_payments/index.html.md.erb

Lines changed: 18 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -31,22 +31,35 @@ You do not need to provide any supporting information yet.
3131

3232
### Live services - turn on MOTO payments
3333

34-
How you turn on MOTO payments on a live account differs depending on whether you use Stripe or Worldpay as your PSP.
34+
You must make sure you comply with the latest version of PCI DSS before we turn on MOTO payments for your live service.
35+
36+
Before emailing GOV.UK Pay to turn on MOTO payments, make sure that both the part of your organisation that processes service data and any suppliers or delivery partners:
37+
38+
* comply with the latest version of PCI DSS
39+
* hold a valid Attestation of Compliance (AOC)
40+
41+
If you take a live MOTO payments and your service does not comply with PCI DSS, you could be fined.
42+
43+
Once you are sure your organisation complies with the latest version of PCI DSS, turning on MOTO payments depends on your whether your PSP is Stripe or Worldpay.
3544

3645
#### Stripe - turn on MOTO payments on a live account
3746

38-
1. Make sure you comply with the most recent version of the [Payment Card Industry Data Security Standards (PCI DSS)](https://www.pcisecuritystandards.org/document_library?category=pcidss&document=pci_dss).
47+
Email [govuk-pay-support@digital.cabinet-office.gov.uk](mailto:govuk-pay-support@digital.cabinet-office.gov.uk) to tell us:
48+
49+
* your organisation and any suppliers or delivery partners comply with the latest version of PCI DSS
50+
* your organisation and any suppliers or delivery partners hold a valid AOC
51+
* you would like to take MOTO payments on your live service
3952

40-
1. Email [govuk-pay-support@digital.cabinet-office.gov.uk](mailto:govuk-pay-support@digital.cabinet-office.gov.uk) to confirm you are PCI DSS compliant and would like to take MOTO payments on your account. We’ll email you to let you know we’ve turned on MOTO payments.
53+
We’ll email you to let you know when we’ve turned on MOTO payments.
4154

4255
#### Worldpay - turn on MOTO payments on a live account
4356

4457
1. Create a new MOTO service that is separate from your online payments service - to do this, sign in to the [GOV.UK Pay admin tool](https://selfservice.payments.service.gov.uk) and select **Add a new service**.
4558

4659
1. You need to process MOTO payments on a separate MOTO merchant code to the one you use for online (non-MOTO) payments. If you do not already have a merchant code for MOTO payments, ask for one by contacting Government Banking. You’ll use this merchant code when you [connect your new service to your PSP](https://docs.payments.service.gov.uk/switching_to_live/#go-live).
4760

48-
1. Make sure you comply with the [Payment Card Industry Data Security Standards (PCI DSS)](https://www.pcisecuritystandards.org/document_library?category=pcidss&document=pci_dss).
61+
1. Email [govuk-pay-support@digital.cabinet-office.gov.uk](mailto:govuk-pay-support@digital.cabinet-office.gov.uk) to confirm you and any suppliers or delivery partners comply with the latest version of PCI DSS. In the same email, let us know that would like to take MOTO payments on your account.
4962

50-
1. Email [govuk-pay-support@digital.cabinet-office.gov.uk](mailto:govuk-pay-support@digital.cabinet-office.gov.uk) to confirm you are PCI DSS compliant and would like to take MOTO payments on your account. We’ll email you to let you know we’ve turned on MOTO payments.
63+
We’ll email you to let you know we’ve turned on MOTO payments.
5164

5265
You can still [take online payments](https://docs.payments.service.gov.uk/making_payments/) through your non-MOTO service.

source/security/index.html.md.erb

Lines changed: 5 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -90,19 +90,16 @@ GOV.UK Pay is the data processor and your service is the data controller. The da
9090

9191
## Payment Card Industry (PCI) compliance
9292

93-
Anyone involved with the processing, transmission, or storage of cardholder
94-
data must comply with the [Payment Card Industry Data Security
95-
Standards](https://www.pcisecuritystandards.org/document_library?category=pcidss&document=pci_dss) (PCI DSS).
93+
Anyone involved with the processing, transmission, or storage of cardholder data must comply with the [Payment Card Industry Data Security Standards](https://www.pcisecuritystandards.org/document_library?category=pcidss&document=pci_dss) (PCI DSS).
9694

97-
GOV.UK Pay is certified as fully compliant as a Level 1 Service Provider with
98-
PCI DSS version 4.0.
95+
GOV.UK Pay is certified as fully compliant as a Level 1 Service Provider with the latest version of PCI DSS.
9996

100-
All GOV.UK Pay partners and any services that take MOTO payments through GOV.UK Pay must comply with PCI DSS v4.0 by 31 March 2025.
101-
102-
If your service takes MOTO payments, you should familiarise yourself with the [the changes from PCI DSS v3.2.1 to v4.0](https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v3-2-1-to-v4-0-Summary-of-Changes-r2.pdf).
97+
All GOV.UK Pay partners and any services that take MOTO payments for a live GOV.UK Pay service must comply with the latest version of PCI DSS.
10398

10499
You may be asked to provide certain information from GOV.UK Pay as part of your own PCI DSS compliance process. You can see our PCI DSS Attestation of Compliance by signing into [the GOV.UK Pay admin tool](https://selfservice.payments.service.gov.uk/my-services) and selecting Attestation of Compliance for PCI in the footer.
105100

101+
If you take live MOTO payments and are not PCI DSS compliant, you could be fined.
102+
106103
### Use your Merchant ID to report PCI DSS compliance
107104

108105
A merchant ID is a unique number that identifies you to your payment processor

0 commit comments

Comments
 (0)