Jul 16, 2026 · 36 min · 16 segments
In this episode of InfoSec Insider, Tibor Laczko and Alastair Stewart, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, explore scoping in the Payment Card Industry Data…
Tibor LaczkoGuest
Alistair StewartGuestAnnieHost
yeah well yeah i mean it's if you're a merchant you're taking payments for yourself if you're a service provider you're
involved in payments
other businesses as well or on the side or your own payments so

When you're involved in some kind of protecting some kind of card data, but you're not actually the merchant, at that
point, you're going to become

So, for example, I don't know, a merchant selling tickets or selling services for something online is a merchant.

So that's sort of like besides which, like if you get the money instantly for your goods or services, then you're a merchant.

the money has to leave a customer's card and it hits a bank account somewhere whichever organization is responsible for that account they're the merchant anybody else is going to be a service provider

uh again sometimes confusion is uh sometimes service providers accept payments on their own their own merchant id um and they said like a lump sum amount once a week once a month whatever the agreement is but again where does the money go yeah i guess that's the golden rule

yeah yeah you get some service providers will accept the money on your behalf when they become the merchant then you also get some service providers that will accept payments for the services they provide to their merchants so they become both they're a service provider and a merchant for selling their own services so it does get confusing because you can be both or one or you can move from one to the other but follow the money you should find it
And would you say the distinction is based mainly on transaction volume, technical architecture, contractual role, or the ability to affect the security of cardholder data?

yeah well yeah i mean it's if you're a merchant you're taking payments for yourself if you're a service provider you're
involved in payments
other businesses as well or on the side or your own payments so

When you're involved in some kind of protecting some kind of card data, but you're not actually the merchant, at that
point, you're going to become

So, for example, I don't know, a merchant selling tickets or selling services for something online is a merchant.

So that's sort of like besides which, like if you get the money instantly for your goods or services, then you're a merchant.

the money has to leave a customer's card and it hits a bank account somewhere whichever organization is responsible for that account they're the merchant anybody else is going to be a service provider

uh again sometimes confusion is uh sometimes service providers accept payments on their own their own merchant id um and they said like a lump sum amount once a week once a month whatever the agreement is but again where does the money go yeah i guess that's the golden rule

yeah yeah you get some service providers will accept the money on your behalf when they become the merchant then you also get some service providers that will accept payments for the services they provide to their merchants so they become both they're a service provider and a merchant for selling their own services so it does get confusing because you can be both or one or you can move from one to the other but follow the money you should find it
And would you say the distinction is based mainly on transaction volume, technical architecture, contractual role, or the ability to affect the security of cardholder data?
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.