PCI DSS certification for travel agencies – everything you need to know
If your travel agency uses GDS systems (e.g. Amadeus, Travelport, Sabre) and processes card payments, you've probably already heard of PCI DSS certification. No, what does that actually mean, why is it important, and how do you get it?
Since 2018 IATA requires all accredited agencies to undergo PCI DSS certification.. Without it, you may face limitations when dealing with airlines and banks. Furthermore, this is not just another bureaucratic obligation – it is about protection your clients' data, avoiding potential fraud and ensuring the safety of your business.
If all of this sounds complicated to you – don’t worry! Below we bring simple guide who will explain how it all works and what you need to do.
Što je PCI DSS i koga se tiče?
PCI DSS (Payment Card Industry Data Security Standard) je Global safety standard which ensures the protection of card payment data.
If your agency processes, handles or stores payment card data, then you are obliged to meet this standard. This applies to all agencies in Croatia, Slovenia, Serbia, Bosnia and Herzegovina, Montenegro and North Macedonia – regardless of size.
Simply put: If you accept card payments, you must be compliant with the PCI DSS standard.
What does the certification process look like?
PCI DSS certification might sound complicated, but in reality, the process can be broken down into several concrete steps:
1. Determine how “big” you are”
There are four levels of merchants, depending on the number of card transactions per year:
- Level 1 – More than 6 million transactions annually (large systems, OTA portals).
- Level 2 – 1 to 6 million transactions per year (larger agencies).
- Level 3 – 20,000 to 1,000,000 e-commerce transactions annually.
- Level 4 – Fewer than 20,000 e-commerce transactions annually (most agencies fall into this category).
If you are a small agency, The certification process will be much simpler and cheaper!
2. Choose certification method
- Self-Assessment Questionnaire (SAQ) – Smaller agencies can complete the questionnaire themselves and submit it to the bank or IATA.
- Independent Audit (QSA Report) – Larger agencies must engage a qualified security assessor (QSA) who carries out a detailed inspection.
3. Introduce safety measures
To meet the standard, you must implement certain data protection measures, such as:
Secure entry of card details (no paper records or safekeeping!)
Data encryption
Access control and stronger passwords
Regular security testing
4. Perform security scans
If you have online systems, you must conduct quarterly vulnerability scanning from authorised service providers (ASV).
5. Complete and submit the documentation
When you are sure that you have implemented everything, you fulfil Attestation of Compliance (AOC) or submit documents to the bank or IATA.
Price of PCI DSS certification views on the size of your agency and how it works:
Male agencies (Level 4) – €200 to €500 per year
Medium agencies – €2,000 to €10,000 per annum
Large agencies and OTA portals – €15,000 to €40,000 or more
If you use external payment services (e.g. a PCI DSS certified payment gateway), your certification can be simpler and cheaper!
PCI DSS certification is carried out by Qualified Security Assessors (QSAs) and Approved Scanning Vendors (ASVs).
If you are a small agency, you can carry out the certification independently through the SAQ questionnaire. However, if you require a professional audit, the following authorised QSA companies operate in the region:
VikingCloud (SecureTrust) – IATA partner, offers a digital tool for PCI certification.
Advantio A European company specialising in tourism security.
SecurityMetrics – Provides SAQ tool and security scans.
ECS (Croatia) - Local consulting services for PCI DSS.
Deloitte, KPMG, PWC, Trustwave, Foregenix – International QSA audit providers.
PCI DSS is not just an obligation, This is an investment in the security of your clients and your business.I believe you are all familiar with these processes and are likely all aware of the risks that are increasingly coming to the fore with the development of technology. As far as I know, Non-IATA agencies do not have this obligation, but I believe that such checks can help, if nothing else, then at least to make employees aware of the importance of handling cards in a way that exposes clients, themselves, and their agencies to as little risk as possible.