Compliance Requirements

RIT PCI DSS Compliance Standard

RIT is committed to conducting its academic and administrative activities ethically and in compliance with applicable laws and regulations. When the University accepts payment for goods or services by means of a credit or debit card (collectively, payment cards), it has a responsibility to protect the personal financial information of the individual making the payment. This document outlines operational governance and technical standards required for all RIT Business Units accepting payment card transactions (in-person, phone, or online). All RIT Merchants must comply with Payment Card Industry Data Security Standards (PCI DSS) to maintain card processing authorization; compliance is not optional, as RIT must comply with the standards in order to continue to accept payment cards. Merchant compliance workflows are centrally managed via Eramba. In addition, any supplier/contractor with whom RIT engages to accept, capture, store, transmit or process payment card information must also be compliant with the PCI DSS. Any unauthorized exposure of credit or debit card information could subject the University to significant financial penalties and reputational damage. It is therefore the responsibility of all RIT departments who accept, capture, store, transmit, or process credit or debit card payments, to ensure compliance with PCI DSS. To ensure compliance, all employees processing credit or debit payments must be officially trained and must satisfy such compliance on annual basis.

RIT Merchants do not submit manual or paper SAQs. All compliance tasks, document access, and annual attestations are conducted through the eramba portal. Merchant Managers must complete and upload the following required items annually:

Required Deliverable
Operational Requirements & Submission Method

1. Annual Business Unit Agreement & Attestation

Access, complete, and upload the signed annual agreement and compliance attestation document directly via the eramba portal.

2. Terminal Characteristics & POI Inventory Log

Maintain an up-to-date Point-of-Interaction (POI) device inventory tracking serial numbers, models, locations, and routine physical inspection logs checking for tamper evidence or skimmers. Upload into eramba.

3. Third-Party Service Provider (TPSP) Proof

Collect and upload current Attestations of Compliance (AoC) for all third-party gateways, software vendors, and web hosts. Confirm an active Information Access and Protection Questionnaire (IAPQ) is registered in eramba.

4. PCI Awareness Training & Log

Ensure all staff, faculty, and student workers complete annual PCI Security Awareness Training via Skillsoft / RIT Talent Roadmap. Upload verified training completion logs into eramba.

5. Secure Storage Review Log

Document physical security reviews and verified storage practices for paper cardholder receipts or physical records. Upload completed review log to eramba.

 

Mandatory Operational Actions (DO)

Strict Operational Prohibitions (DON'T)

 

  • Complete mandatory RIT PCI training annually. 
  • Keep all physical card receipts locked and secured. 
  • Inspect POS terminals routinely for physical tampering, skimmers, or rogue wiring. 
  • Verify customer card details are shredded/destroyed when retention needs expire. 
  • E-Commerce Gateway Standard: Any web app taking payments must route directly through an ISO-approved external payment gateway and complete an ISO technical review prior to going live.
       
       
       

 

  • NEVER store card account numbers (PAN) or CVVs on local PCs, network drives, or spreadsheets. 
  • NEVER transmit credit card numbers via email, instant message, campus mail, or fax. 
  • NEVER share or disclose cardholder data without explicit consent. 
  • NEVER allow unapproved software or hardware changes on POS devices. 
  • No Digital Data Storage: Storing primary account numbers (PAN) or sensitive authentication data (SAD) electronically on RIT workstations, servers, or cloud storage is strictly prohibited.


 

Information Security Office & Controller's Office Support

Have more questions? Visit our FAQs on the PCI DSS page, or feel free to contact us: