All third-party processors (TPPs) are considered Level 1 Service Providers. Data Storage Entities (DSEs) are categorised as Level 1 or Level 2 Service Providers based on annual Mastercard transaction volume.
Based on level, review the Service Provider validation requirements and engage an Approved Scanning Vendor (ASV) or Qualified Security Assessor (QSA) as necessary.
Once compliant, submit a signed Attestation of Compliance (AOC); or for those SAQ eligible, please submit the SAQ D AOC and latest clean scan to Mastercard.
Please note: Mastercard will only list those Service Providers that also are registered and approved as a Member Service Provider (MSP) with the Mastercard Registration Program (MRP) and those that also have successfully completed an annual onsite assessment.
Mastercard requires all principal member bank(s) or financial institution(s) to submit a service provider registration on behalf of themselves and their affiliates via the MRP database (not required if the principal member is only providing services to themselves or their affiliates). Should a service provider have a direct relationship with one or more banks, they should contact each bank to submit a registration on their behalf.
Note: The customer bank must provide the SPR number so the registration can be reviewed for approval. Once the registration has been submitted, we will review and finalise the approval if all required information has been provided. The approval timeframe is approximately five to seven business days.
Please note the registration process is separate to the submission of PCI Compliance documentation and must be completed by a member bank prior to the service provider registration being approved. All PCI Compliance documents must be submitted to Mastercard.
To be listed as a Compliant Service Provider, service providers need to be both registered and approved as a MSP and must have successfully completed an annual onsite assessment conducted by a PCI SSC certified QSA.
If you have questions, please contact the Service Provider team at email@example.com.