Skip to main content

PCI Compliance with Aperia

Learn how to manage your PCI compliance with Aperia.

What Is PCI Compliance?

The PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements designed to protect payment cardholder data.

Any business that accepts, processes, stores, or transmits credit card information must comply with this standard to maintain a secure environment and reduce the risk of fraud and data breaches.

For merchants using ProgressionPay payment processing services, maintaining PCI compliance is a contractual requirement.


How Valpay Manages PCI Compliance

Valpay has partnered with Aperia, a PCI compliance specialist, to help merchants meet their annual compliance obligations.

Aperia manages:

  • PCI compliance program administration

  • Self-Assessment Questionnaire (SAQ) administration

  • Required vulnerability scans

  • Compliance reminders and follow-ups

  • Issuance of official compliance documents


Enrollment in the Aperia Program

When a merchant is onboarded through Valpay, they are automatically enrolled in Aperia's PCI compliance program.

Aperia creates an account using the following information:

  • The designated contact person's name

  • The email address provided during onboarding


Enrollment Timeline

Merchants can expect to receive their Aperia portal invitation within 5 to 7 business days following activation.


Communications Sent by Aperia

The designated contact person will receive all PCI compliance-related communications, including:

  • Enrollment confirmation and portal access details

  • SAQ due date reminders

  • Follow-up notices for overdue requirements

  • Vulnerability scan notifications

  • Scan results

  • Compliance-related alerts

Important: If the designated contact person's name or email address needs to be updated, please contact the Customer Success Team so the information can be updated within Aperia.


Accessing the Aperia Portal

Merchants can access the Aperia portal at any time to manage their PCI compliance.

Aperia Portal:

From the Portal, You Can:

  • Complete your Self-Assessment Questionnaire (SAQ)

  • View vulnerability scans and scan results

  • Download compliance documents

  • Monitor your compliance status


First-Time Login

When logging into the portal for the first time, select "First Time Logging In?" and provide the following information:

  1. Your username or merchant number

  2. The last four digits of the authorized signer's Tax Identification Number (TIN) or Social Security Number (SSN)

  3. The two-character province/state code and postal/ZIP code associated with the merchant account


Self-Assessment Questionnaire (SAQ)

The SAQ is an annual compliance requirement for all merchants.

It is a questionnaire used to evaluate the security practices your business follows to protect cardholder data.

Depending on your payment environment, the type of questionnaire required may vary.


What to Expect

  • Aperia sends an email reminder before your annual due date.

  • Follow-up notifications are sent if the questionnaire is not completed on time.

  • The questionnaire must be completed directly through the Aperia portal.


Need Help Completing the SAQ?

All SAQ-related questions should be directed to Aperia.

Their support team can guide you through the questionnaire step by step.

Before contacting support, have the following ready:

  • Your Merchant ID

  • The last four digits of your Tax Identification Number

Important: Contact the Customer Success Team if you cannot locate your Merchant ID.


Phone Menu Options

Option

Description

Option 1

Assistance completing the SAQ

Option 2

Vulnerability scan assistance

Option 3

Billing inquiries (redirected to Valpay)

Aperia Support Contact Information

Canada

1-866-232-0910

United States

1-866-232-0910

Europe

+353 1 966 0950

United Kingdom

+44 161 509 5883

Australia

+61 8 6285 2680

Support Hours:
Monday through Friday, 7:00 AM to 7:00 PM Central Time, excluding holidays.


Vulnerability Scans

Depending on your account type and payment processing method, quarterly vulnerability scans may be required.

Aperia will notify you:

  • When a scan is scheduled

  • When a scan begins

  • When scan results become available

  • If a scan fails and corrective action is required


What Should I Do If a Scan Fails?

If a vulnerability scan is marked as failed, contact Aperia directly.

Their team will guide you through the remediation steps required to restore compliance.


Compliance Documents

Once your compliance requirements have been completed, you can access your official documents under the Current Documents section of the Aperia portal.

Available documents may include:

Certificate of Completion

Confirms that all compliance requirements have been successfully met.

Attestation of Compliance (AOC)

An official document demonstrating PCI DSS compliance to banks, partners, and other third parties.

Additional Documents

Any other compliance documents applicable to your payment processing environment.


Quick Reference: Who Should I Contact?

Question or Issue

Contact

Help completing the SAQ

Aperia

Vulnerability scan questions

Aperia

Failed vulnerability scans

Aperia

Portal access issues

Aperia

Updating contact information

ProgressionLIVE

Onboarding or account-related questions

ProgressionLIVE


Contact Aperia

Region

Phone Number

Canada and United States

1-866-232-0910

Europe

+353 1 966 0950

United Kingdom

+44 161 509 5883

Australia

+61 8 6285 2680

Support Hours:
Monday through Friday, 7:00 AM to 7:00 PM Central Time, excluding holidays.

Did this answer your question?