Frequently Asked Question
															How do I contact the payment card brands?
Contact the applicable payment brands and/or acquirer (merchant bank) for more information about PCI compliance programs.
Contact details for the PCI SSC Participating Payment Brands are provided below:
American Express
Website: http://www.americanexpress.com/datasecurity
Email: AmericanExpressCompliance@securetrust.com
Discover
Website: https://www.discovernetwork.com/en-us/
For questions about the DISC program:
https://www.discovernetwork.com/en-us/business-resources/fraud-security/pci-rules-regulations/
Email: DISCCompliance@discover.com
JCB
Website: http://www.global.jcb/en/products/security/data-security-program/
Email: riskmanagement@info.jcb.co.jp
Mastercard
Website: http://www.mastercard.com/sdp
Email: sdp@mastercard.com
UnionPay
Website: http://unionpayintl.com/en/
Email: risk@unionpayintl.com
Visa
Website: https://usa.visa.com/support/small-business/security-compliance.html
Asia Pacific
Email: vpssais@visa.com - for Merchant Requirement
Email: pciagents@visa.com - for Clients, Third Party Agents and Service Provider Requirements
Canada and the U.S.
Email: pcicap@visa.com - for Merchant Requirement
Email: pcirocs@visa.com - for Clients, Third Party Agents and Service Provider Requirement
Central Europe, Middle East, & Africa
Email: pcicemea@visa.com
Europe
Email: datasecuritystandards@visa.com - for Clients and Merchant requirements
Email: pcidsseurope@visa.com - for Clients, Third Party Agents and Service Provider Requirements
Latin America and the Caribbean
Email: aislac@visa.com
Visa PIN Security Program
Website: http://www.visa.com/pin
For information about PCI SSC Affiliate Members, please refer to the
following link: https://www.pcisecuritystandards.org/get_involved/affiliate_members.php
Related
- 
										Are Approved Scanning Vendors and Qualified Security Assessors considered third-party service providers for PCI DSS Requirements 12.8 and 12.9?
										
 - 
										What are the expectations for entities when assigning risk rankings to vulnerabilities and resolving or addressing those vulnerabilities?
										
 - 
										Is phishing-resistant authentication alone acceptable as multi-factor authentication for PCI DSS Requirements 8.4.1 and 8.4.3?
										
 
Featured FAQ Articles
Featured
- 
									
										Do PCI DSS requirements for keyed cryptographic hashing apply to previously hashed PANs?									
									
 - 
									
										Is the PCI DSS Attestation of Compliance intended to be shared?									
									
 - 
									
										How does an entity report the results of a PCI DSS assessment for new requirements that are noted in PCI DSS as best practices until a future date?									
									
 - 
									
										Where do I direct questions about complying with PCI standards?									
									
 - 
									
										Can SAQ eligibility criteria be used as a guide for determining applicability of PCI DSS requirements for merchant assessments documented in a Report on Compliance?									
									
 
Most Popular
- 
									
										Are Approved Scanning Vendors and Qualified Security Assessors considered third-party service providers for PCI DSS Requirements 12.8 and 12.9?									
									
 - 
									
										What are the expectations for entities when assigning risk rankings to vulnerabilities and resolving or addressing those vulnerabilities?									
									
 - 
									
										Is phishing-resistant authentication alone acceptable as multi-factor authentication for PCI DSS Requirements 8.4.1 and 8.4.3?									
									
 - 
									
										Are passkeys synced across devices, implemented according to the FIDO2 requirements, acceptable for use as phishing-resistant authentication to meet PCI DSS Requirement 8.4.2?									
									
 - 
									
										How should PCI DSS v4.x requirements noted as superseded by another requirement be reported after 31 March 2025?									
									
 
Most Recently Updated
- 
									
										Can unencrypted PANs be sent over e-mail, instant messaging, SMS, or chat?									
									
 - 
									
										Are entities allowed to request that cardholder data be provided over end-user messaging technologies?									
									
 - 
									
										Does PCI DSS allow faxing of payment card numbers?									
									
 - 
									
										What is the maximum period of time that cardholder data can be stored?									
									
 - 
									
										To which devices does PCI DSS Requirement 10.4.2 apply?