Laserfiche WebLink
<br />Section 3: Validation and Attestation Details <br />Part 3. PCI DSS Validation <br />This AOC is based on results noted in the ROC dated 29 Jun 2021. <br />Based on the results documented in the ROC noted above, the signatories identified in Parts 3b-3d, as <br />applicable, assert(s) the following compliance status for the entity identified in Part 2 of this document <br />(check one): <br />☒Compliant: All sections of the PCI DSS ROC are complete, all questions answered affirmatively, <br />resulting in an overall COMPLIANT rating; thereby Bluefin Payment Systems LLC has demonstrated <br />full compliance with the PCI DSS. <br />☐Non-Compliant: Not all sections of the PCI DSS ROC are complete, or not all questions are <br />answered affirmatively, resulting in an overall NON-COMPLIANT rating, thereby Bluefin Payment <br />Systems LLC has not demonstrated full compliance with the PCI DSS. <br />Target Date for Compliance: <br />An entity submitting this form with a status of Non-Compliant may be required to complete the Action <br />Plan in Part 4 of this document. Check with the payment brand(s) before completing Part 4. <br />☐Compliant but with Legal exception: One or more requirements are marked “Not in Place” due to a <br />legal restriction that prevents the requirement from being met. This option requires additional review <br />from acquirer or payment brand. <br />If checked, complete the following: <br />Details of how legal constraint prevents <br />Affected Requirement requirement being met <br />N/A N/A <br />Part 3a. Acknowledgement of Status <br />Signatory(s) confirms: <br />(Check all that apply) <br />☒ <br />☒ <br />☐ <br />☒ <br />☒ <br />The ROC was completed according to the PCI DSS Requirements and Security Assessment <br />Procedures, Version 3.2.1, and was completed according to the instructions therein. <br />All information within the above-referenced ROC and in this attestation fairly represents the results of <br />my assessment in all material respects. <br />I have confirmed with my payment application vendor that my payment system does not store <br />sensitive authentication data after authorization. <br />I have read the PCI DSS and I recognize that I must maintain PCI DSS compliance, as applicable to <br />my environment, at all times. <br />If my environment changes, I recognize I must reassess my environment and implement any <br />additional PCI DSS requirements that apply. <br />PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 <br />© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. <br />June 2018 <br />Page 10