What Is PCI Compliance?
The PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements designed to protect payment cardholder data.
Any business that accepts, processes, stores, or transmits credit card information must comply with this standard to maintain a secure environment and reduce the risk of fraud and data breaches.
For merchants using ProgressionPay payment processing services, maintaining PCI compliance is a contractual requirement.
How Valpay Manages PCI Compliance
Valpay has partnered with Aperia, a PCI compliance specialist, to help merchants meet their annual compliance obligations.
Aperia manages:
PCI compliance program administration
Self-Assessment Questionnaire (SAQ) administration
Required vulnerability scans
Compliance reminders and follow-ups
Issuance of official compliance documents
Enrollment in the Aperia Program
When a merchant is onboarded through Valpay, they are automatically enrolled in Aperia's PCI compliance program.
Aperia creates an account using the following information:
The designated contact person's name
The email address provided during onboarding
Enrollment Timeline
Merchants can expect to receive their Aperia portal invitation within 5 to 7 business days following activation.
Communications Sent by Aperia
The designated contact person will receive all PCI compliance-related communications, including:
Enrollment confirmation and portal access details
SAQ due date reminders
Follow-up notices for overdue requirements
Vulnerability scan notifications
Scan results
Compliance-related alerts
Important: If the designated contact person's name or email address needs to be updated, please contact the Customer Success Team so the information can be updated within Aperia.
Accessing the Aperia Portal
Merchants can access the Aperia portal at any time to manage their PCI compliance.
Aperia Portal:
From the Portal, You Can:
Complete your Self-Assessment Questionnaire (SAQ)
View vulnerability scans and scan results
Download compliance documents
Monitor your compliance status
First-Time Login
When logging into the portal for the first time, select "First Time Logging In?" and provide the following information:
Your username or merchant number
The last four digits of the authorized signer's Tax Identification Number (TIN) or Social Security Number (SSN)
The two-character province/state code and postal/ZIP code associated with the merchant account
Self-Assessment Questionnaire (SAQ)
The SAQ is an annual compliance requirement for all merchants.
It is a questionnaire used to evaluate the security practices your business follows to protect cardholder data.
Depending on your payment environment, the type of questionnaire required may vary.
What to Expect
Aperia sends an email reminder before your annual due date.
Follow-up notifications are sent if the questionnaire is not completed on time.
The questionnaire must be completed directly through the Aperia portal.
Need Help Completing the SAQ?
All SAQ-related questions should be directed to Aperia.
Their support team can guide you through the questionnaire step by step.
Before contacting support, have the following ready:
Your Merchant ID
The last four digits of your Tax Identification Number
Important: Contact the Customer Success Team if you cannot locate your Merchant ID.
Phone Menu Options
Option | Description |
Option 1 | Assistance completing the SAQ |
Option 2 | Vulnerability scan assistance |
Option 3 | Billing inquiries (redirected to Valpay) |
Aperia Support Contact Information
Canada | 1-866-232-0910 |
United States | 1-866-232-0910 |
Europe | +353 1 966 0950 |
United Kingdom | +44 161 509 5883 |
Australia | +61 8 6285 2680 |
Support Hours:
Monday through Friday, 7:00 AM to 7:00 PM Central Time, excluding holidays.
Vulnerability Scans
Depending on your account type and payment processing method, quarterly vulnerability scans may be required.
Aperia will notify you:
When a scan is scheduled
When a scan begins
When scan results become available
If a scan fails and corrective action is required
What Should I Do If a Scan Fails?
If a vulnerability scan is marked as failed, contact Aperia directly.
Their team will guide you through the remediation steps required to restore compliance.
Compliance Documents
Once your compliance requirements have been completed, you can access your official documents under the Current Documents section of the Aperia portal.
Available documents may include:
Certificate of Completion
Confirms that all compliance requirements have been successfully met.
Attestation of Compliance (AOC)
An official document demonstrating PCI DSS compliance to banks, partners, and other third parties.
Additional Documents
Any other compliance documents applicable to your payment processing environment.
Quick Reference: Who Should I Contact?
Question or Issue | Contact |
Help completing the SAQ | Aperia |
Vulnerability scan questions | Aperia |
Failed vulnerability scans | Aperia |
Portal access issues | Aperia |
Updating contact information | ProgressionLIVE |
Onboarding or account-related questions | ProgressionLIVE |
Contact Aperia
Portal:
Access the Aperia Portal
Region | Phone Number |
Canada and United States | 1-866-232-0910 |
Europe | +353 1 966 0950 |
United Kingdom | +44 161 509 5883 |
Australia | +61 8 6285 2680 |
Support Hours:
Monday through Friday, 7:00 AM to 7:00 PM Central Time, excluding holidays.
