logo
logo
sales@iqconnect.com8:00 AM – 5:00 PM EST
IQ Connect Achieves PCI DSS v4.0.1 Compliance

IQ Connect Achieves PCI DSS v4.0.1 Compliance

August 6, 20266 min readIQ Connect PCI DSS v4.0.1 compliance

iQ Connect’s assessed payment channel achieved PCI DSS v4.0.1 compliance through a full ROC independently validated by A-LIGN.

IQ Connect Achieves Independently Validated PCI DSS v4.0.1 Compliance

IQ Connect Technology Co., Ltd. has achieved PCI DSS v4.0.1 compliance for its assessed e-commerce payment channel after completing a full Report on Compliance conducted by A-LIGN, a PCI SSC-qualified security assessor.

The result was documented through a formal Report on Compliance, or ROC, and Attestation of Compliance, or AOC. This means the payment environment was evaluated by an independent Qualified Security Assessor rather than validated solely through a self-assessment.

For MVNOs and telecom operators, the assessment provides documented evidence that the controls supporting iQ Connect’s payment environment were reviewed against PCI DSS requirements. 

Why Independent PCI DSS Validation Matters

Not every PCI DSS compliance statement represents the same level of assessment.

Some organizations validate compliance by completing a Self-Assessment Questionnaire. Other environments undergo a more extensive review performed by an independent Qualified Security Assessor.

iQ Connect completed a full ROC assessment with A-LIGN. The review examined the policies, technical configurations, security controls, and operational processes supporting the assessed e-commerce payment channel.

The assessment covered all 12 principal PCI DSS requirements, as well as applicable Appendix A1 and A2 requirements. 

What the PCI DSS Assessment Covered

The assessed environment supports payment activity associated with:

  • Prepaid mobile activations.
  • Subscription billing.
  • Recurring payments.
  • Account recharges.
  • Manual invoice entry.
  • Other e-commerce transactions processed through the iQ Connect platform.

A-LIGN evaluated the technical and operational controls protecting this payment environment. The resulting AOC was signed by iQ Connect CEO Max Contador and validated by A-LIGN representatives. 

What This Means for MVNOs and Telecom Operators

PCI DSS compliance does not eliminate every security or compliance responsibility for an operator. It does, however, provide independently assessed evidence that a critical technology provider has implemented controls for protecting its payment environment.

More Defensible Vendor Due Diligence

MVNOs and telecom operators must evaluate third-party providers that can affect cardholder data security.

An AOC gives security, compliance, and procurement teams formal documentation when reviewing the compliance status of an OSS/BSS or billing platform.

This documentation may support:

  • Vendor due diligence.
  • Acquiring bank requests.
  • Internal security reviews.
  • Third-party risk assessments.

Each operator remains responsible for identifying its own PCI DSS obligations and validating compliance based on its payment architecture, processor relationships, and operating model. 

Payment-Page Integrity Monitoring

Payment attacks do not always target a payment processor directly.

Attackers may compromise scripts, integrations, or webpage components used during checkout to capture payment information before it reaches an authorized processor.

iQ Connect maintains controls designed to monitor payment-page integrity and identify unauthorized script injections or unexpected changes affecting its assessed payment environment. This allows suspicious modifications to be investigated instead of remaining undetected until a future annual review. 

Ongoing Security Monitoring

PCI DSS compliance is not limited to completing an annual assessment.

Access controls, logging, vulnerability management, security testing, and payment-page monitoring must continue operating after the formal review is complete.

This is particularly relevant for MVNOs processing recurring payments and subscriber transactions every day. The underlying security controls must operate continuously, not only during an audit period. 

How iQ Connect Limits Cardholder Data Exposure

A central part of iQ Connect’s payment security model is limiting the amount of cardholder data entering the assessed application environment.

Customers enter payment information through secure embedded iframe integrations provided by supported payment processors. Card data is transmitted directly from the customer’s browser to the selected processor through encrypted connections.

iQ Connect retains tokenized references and limited non-sensitive information when required for account identification or display.

The assessed application environment does not store:

  • Full primary account numbers.
  • CVV security codes.
  • Card expiration dates.

This approach reduces the amount of sensitive payment information handled by the platform while preserving the billing and payment functionality required by telecom operators. 

Security Controls Across the Assessed Environment

The ROC assessment evaluated controls across the payment environment rather than reviewing one isolated application component.

Network Security and Segmentation

Network segmentation, firewall rules, and security groups restrict access and help limit the systems included within the cardholder data environment.

Encryption and Data Protection

Payment information is transmitted through encrypted connections. Sensitive authentication data is not retained within the assessed application environment.

Access Control and Authentication

Access to in-scope systems is restricted according to job responsibilities and protected through multi-factor authentication. Shared accounts are not used within the assessed environment.

Logging and Security Monitoring

Cloud-native and third-party security services support event logging, infrastructure monitoring, and the identification of suspicious activity.

Vulnerability Management and Testing

The environment is supported by vulnerability management, anti-malware protections, and ongoing security testing.

Information Security Governance

Documented policies define how systems, access, service providers, incidents, and compliance responsibilities are managed. 

Why Payment Security Matters When Selecting an OSS/BSS Platform

An OSS/BSS platform can connect subscriber management, billing, carrier integrations, recurring payments, and other business-critical telecom workflows.

That makes payment security an architectural requirement rather than a secondary feature to evaluate after implementation.

MVNOs and telecom operators comparing platforms should ask:

  • Has the payment environment undergone an independent PCI DSS assessment?
  • Was compliance validated through a full ROC or only a self-assessment?
  • Can the provider supply a current AOC?
  • Does raw cardholder data enter or remain within the platform?
  • How are payment-page scripts monitored?
  • Are security controls monitored continuously?
  • Which payment processors and cloud providers support the environment?
  • How does the provider support third-party compliance reviews?

These questions help determine whether a provider’s security claims are supported by architecture, operational controls, and independent evidence. 


Frequently Asked Questions

Who validated iQ Connect’s PCI DSS compliance?

A-LIGN, a Qualified Security Assessor Company recognized by the PCI Security Standards Council, conducted the assessment.

Did iQ Connect complete a self-assessment?

No. iQ Connect completed a full ROC assessment conducted by an independent Qualified Security Assessor. The result was documented through a Report on Compliance and Attestation of Compliance.

Does iQ Connect store full customer card numbers?

No. The assessed application environment does not store full card numbers, CVVs, or card expiration dates. Card information is entered through secure embedded payment integrations and transmitted directly to the selected payment processor.

Does using iQ Connect automatically make an MVNO PCI DSS compliant?

No. Working with a PCI DSS-compliant service provider may help reduce compliance scope and provide supporting evidence, but each MVNO or telecom operator must determine and validate its own obligations.

What is the difference between a ROC and an AOC?

A Report on Compliance contains the detailed findings of the PCI DSS assessment. An Attestation of Compliance formally confirms the result of that assessment and the entity’s compliance status.

Tags

IQ Connect PCI DSS v4.0.1 compliancePCI DSS compliance for MVNOsMVNO payment securityOSS/BSS payment securitytelecom billing securityA-LIGN PCI DSS assessmentReport on Compliance ROCAttestation of Compliance AOC