
It was back in 2006 when OrderMotion performed its first formal PCI audit. If you’re not familiar with PCI or more specifically, PCI DSS (Payment Card Industry Data Security Standards), it is an information security standard for organizations that handle cardholder data to reduce credit card fraud. Any merchant or service provider that processes, stores or transmits cardholder data is required to comply with PCI standards every year. In 2006, PCI compliance was a new requirement for many organizations, not just OrderMotion. We upgraded our infrastructure, contracted additional security devices from our hosting provider, developed and implemented many new policies in our organization, and made sure our system met all twelve chapters of requirements outlined in the early years of PCI data security standard. Confident about our compliance, we hired a reputable company to perform the third party audit. As it turned out, OrderMotion was one of the first SaaS service providers to undergo a PCI audit, and as a result the auditors initially struggled to apply the data security standard intended for merchants to a SaaS service provider such as us. We spent six months educating the auditor, and documenting and discussing what PCI for a SaaS company meant. In the end, we submitted our first ROC (Report of Compliance) to VISA and promptly received our AOC (Attestation of Compliance). Victory at last!