Hacker News new | ask | show | jobs
by wiredfool 4735 days ago
I wonder if this means that the NSA is going to fail it's annual PCI audit?
1 comments

Following PCI is a contractual requirement, not a statutory requirement. If you want to do certain things with credit cards, such as accept payments using them, then you have to enter into a contract that says you'll follow PCI.

If you have no need of any service that requires entering into such a contract, than you can completely ignore PCI.