Visa Global Registry of Service Providers

Service providers in Canada, the U.S., Latin America and the Caribbean, Asia Pacific, Central & Eastern Europe, Middle East and Africa providing services to support the following activities must be registered with Visa before being added to Visa's Global Registry of Service Providers* (the "Registry"). Services and regional programs are listed and discussed more fully below.

Program Services (including but not limited to) Region(s) Email Inquiries / Compliance Submissions
PCI DSS Validated Service Providers Storing, processing or transmitting cardholder data AP, CEMEA pciagents@visa.com
Canada, US pcirocs@visa.com
LAC pcirocs@visa.com
Visa Third Party Agent (TPA) Program Solicitation activities (ISO) or deployment of ATM, POS or kiosk PIN acceptance devices and/or manage encryption keys (ESO) without touching cardholder data AP, CEMEA agents@visa.com
Canada, US agentregistration@visa.com
LAC agentregistrationLAC@visa.com
Visa Access Control Server (ACS) Program Verified by Visa services AP, CEMEA acs@visa.com
Canada, LAC, US AVPamericas@visa.com
Visa Approved Vendor Program (AVP) Payment card manufacturing and/or cardholder personalization services, including mobile AP, CEMEA VendorCompliance@visa.com
Canada, LAC, US AVPamericas@visa.com
Visa Issuer Processor Program issuerProcessing@visa.com

Payment Card Industry Data Security Standard (PCI DSS) Validated Service Providers

Service providers that store, process or transmit Visa cardholder data must be registered with Visa and demonstrate PCI DSS compliance. PCI DSS compliance validation is required every 12 months for all service providers. Inclusion on the Registry indicates only that the service provider successfully validated PCI DSS compliance with an on-site assessment, based on the report of an independent Qualified Security Assessor (QSA), and has met all applicable Visa program requirements.

Annual Revalidation

Service providers that store, process or transmit Visa cardholder data must demonstrate PCI DSS compliance and provide the compliance validation to Visa every 12 months. Non-compliance assessments begin at 10,000 USD per service provider (assessed to each registering Visa member).

The Registry is updated once a month. For service providers published on the Registry, if Visa does not receive the appropriate revalidation documents:

Please note that Visa reserves the rights to remove any service provider from the Registry at its discretion.

Visa Third Party Agent Program (Independent Sales Organizations / Encryption Support Organizations)

Third Party Agents that perform solicitation activities (ISO) or deploy ATM, POS or kiosk PIN acceptance devices and/or manage encryption keys (ESO) without touching cardholder data must be registered with Visa. Inclusion on the Registry indicates only that the service provider successfully completed registration with Visa.

Changes and Updates

Service providers are required to notify their financial institution(s) of changes to any information such as: legal name / business aliases; doing business as name (DBA); mergers and acquisitions; legal location or additional business locations; company point of contact; types of services offered; number of Visa transactions or accounts processed annually; compliance status (where applicable); and financial solvency.

Visa Access Control Server (ACS) Service Provider Program

Access Control Server (ACS) Service Providers are third-party providers of 3D Secure ACS services that enable secure processing of payment transactions over the Internet. Visa approved ACS Service Providers have validated their security and program compliance to Visa and are listed on the Visa Global Registry of Service Providers.

Prospective ACS service providers seeking to participate in Visa's ACS Service Provider Program must undergo on-site inspections and reviews of their financial background.

Validation

Approved ACS Service Providers offering services to Visa issuers for online internet transactions must demonstrate compliance to Visa program requirements and applicable security requirements. Contact your Visa Risk Representative to learn about program and validation requirements for your region.

The Registry is updated once a month. For ACS Service Providers published on the Registry, if Visa does not receive the revalidation documents:

Changes and Updates

Visa approved ACS Service Providers are required to notify Visa of changes to any information such as: legal name / business aliases; doing business as name (DBA); mergers and acquisitions; legal location or additional business locations; company point of contact; types of services offered; compliance status (where applicable); and financial insolvency.

Visa Approved Vendor Program

Visa Approved Vendors are third-party providers of Visa products or services who have validated their security compliance to Visa. Prospective vendors seeking to participate in the Approved Vendor Program (AVP) must undergo due diligence reviews, on-site inspections and reviews of their financial background. They must also sign a contract before participating in the AVP program. Final approval of a new facility is given once the security of the facility is confirmed and, if applicable, the vendor's finished product samples have been successfully reviewed and approved for quality and consistency. When granted, vendor approval is provided by Visa to ensure certain security and operational characteristics important to the Visa systems and products as a whole. However, this does not, under any circumstances, include any endorsement or warranty regarding the functionality, quality, or performance of any particular product or service. Visa does not warrant any products or services provided by third parties. All rights and remedies regarding products and services, which have received Visa approval, shall be provided by the party providing such products or services, and not by Visa.

The Visa Rules require Members to use only approved vendors, Visa or another Issuer for the manufacture, personalization, chip embedding, initialization, data preparation, fulfillment of Visa products, over-the-air (OTA) personalization or cloud-based payment providers in support of Visa’s cloud-based payments program.

The Visa Global Registry of Service Providers lists all approved vendors (card manufacturers, magnetic-stripe card personalizers, IC personalizers, IC pre-personalizers, over-the-air personalizers and cloud-based payment providers) approved by Visa to produce Visa products or perform cloud-based services under the Visa Approved Vendor Program.

Members placing orders for the manufacture, personalization, fulfillment, or initialization of Visa products or contracting for cloud-based services may contract with any of the Visa approved vendors on the list.

Annual Revalidation

All approved vendors providing services to Visa issuers for payment products bearing the trademark or service marks of Visa must on an annual basis, comply with; Visa program requirements, including submission of annual reporting and payment of program fees, PCI Card Production Security Requirements and/or other applicable security requirements. Approved vendors must demonstrate compliance to required security requirements every 12 months. For approved vendors published on the Registry, if Visa does not receive the revalidation documents or the approved vendor falls into program non-compliance:

The Registry is updated once a month.

Applicable Security Requirements

Within the Approved Vendor Program, vendors are required to validate annually against one or more security requirements. Approved vendor security requirements are:

Note: PCI DSS does not apply to services within the Approved Vendor Program.

Changes and Updates

Visa approved vendors are required to notify Visa of changes to any information such as: legal name / business aliases; doing business as name (DBA); mergers and acquisitions; legal location or additional business locations; company point of contact; types of services offered; compliance status (where applicable); and financial insolvency.

Visa Issuer Processor Program

The Visa Issuer Processor Program lists issuer processors that have met a minimum set of criteria to demonstrate to Visa that they are capable of supporting a new program implementation or conversion. The program is intended to support and catalyze growth of new and existing Visa Issuers by introducing capable processors on a geography and region specific basis. VIPP inclusion does not constitute a partnership or reseller agreement with Visa.

Validation requirements

While the assessment process will vary by region, a questionnaire will be provided to interested parties and is designed to ensure platform strength and capability, processing consistency and responsible business practices. Visa will request annual financial documentation and updates if any material changes to the processor occur at any time during the year.

Changes and Updates

Visa service providers are required to notify Visa of changes to any information including, but not limited to: legal name / business aliases; doing business as name (DBA); mergers and acquisitions; legal location or additional business locations; company point of contact; types of services offered; compliance status (where applicable); and financial insolvency.

*The companies listed were validated as being PCI DSS compliant by a QSA as of the "VALIDATION DATE (1)". Service providers are required to revalidate their compliance to Visa every 12 months, with the Attestation of Compliance (AOC) and full Report on Compliance (ROC) (as applicable) due to Visa one year from the "VALIDATION DATE". Entities are listed in each Visa region where they have been registered by at least one client, including: AP - Asia Pacific, CEMEA - Central & Eastern Europe / Middle East / Africa, LAC - Latin America / Caribbean, CAN - Canada, U.S. - United States. Visa clients are responsible for and are required to use compliant service providers and to follow up with service providers directly if there are any questions about their compliance status. Visa clients are liable for the service providers they use.

(1)PCI DSS assessments represent only a "snapshot" of security in place at the time of the review, and do not guarantee that those security controls remain in place after the review is complete. These reviews did not cover proprietary software solutions that may be used or sold by these service providers.

For service providers registered with Visa Europe, please go to https://www.visaeurope.com/receiving-payments/security/downloads-and-resources.

Please note that Visa reserves the rights to remove any service provider from the Registry at its discretion.