Do to the new and useless PCI DSS security standard; we are currently unable to except Credit Cards.
The short explanation of this that they do a port scan on up to 2 IP addresses and if there are no open ports, the merchant is considered secure. We come in through multiple IP addresses (more then 2), so they won't verify us. We are not going to change our business model just to make visa and master card happy.
To clarify why this is useless and why we cannot be verified.
1. The port scan of 1-2 IP's is easily defeated, simply by setting up a proxy server.
2. Even easier than that, all anyone really has to do to get around the PCI verification is lie.
3. The port scan is no indication that the system submitting the transaction is secure or even that the connection is encrypted.
4. It doesn’t even take dynamic IP’s into account.
The simplistics are: We refuse to lie or circumvent the system just to be able to use it. We have never had 1 single mistake or complaint, not even a single charge back.
All this info was obtained though talking with Express MPS and Security Metrics about trying to find a solution for our credit card processing. In the end the choices we were given: change our business model, pay even more money to the credit card companies for the privilege of being charged for accept their cards, or stop excepting crediting cards.
If we find solution to this we may start excepting credit cards again.