Square mobile pin security policy and procedures pci software pin on cots (16 pages)
Summary of Contents for Square Contactless and Chip Reader
Page 1
Contactless and Chip Reader PCI Compliance Policy and Procedures Version 1.00...
Page 2
Table of Contents Introduction Square Reader Authentication and Use Square Reader Security Version History...
Page 3
PCI SSC this document can be placed in the public domain. Environment description The Square Contactless and Chip Reader (“Reader”) is a secure payment device that is designed for use by merchants in many industries for accepting card-present payment transactions. The Reader only works with the Square Register application and a compatible mobile device running in a Square Stand (https://squareup.com/stand).
Page 7
To store the Square Reader simply remove it from the Square Stand USB port and store for next use. In the event the Seller will not use the Square Reader for more than twelve (12) months at a time, be sure to charge the Square Reader prior to storage and periodically to preserve its readiness.
Page 8
Square Reader Authentication and Use on. The Square Reader also implements a forced reboot every 23.5 hours which initiates the same self-tests as when the device is powered on. How to decommission a Square Reader To decommission the Square Reader please ship the device to the following address for decommissioning: Square, Inc.℅...
Page 9
Square Reader Security Privacy shielding The Square Reader is not a PIN-entry device and, in accordance with PCI POS PED Security Requirements and EPP Security Requirements technical FAQs version 2.0, does not require a privacy screen. Firmware and software update Square will update the firmware associated with the Square Reader automatically and as...
Page 10
Any attempt to open/disassemble/take apart the Square Reader or access parts inside The Square Reader is intended to be fully charged once a year. If the Square Reader’s primary battery is fully discharged and left for more a year without a recharge it may become inoperable.
Page 11
Square Readers entering the key provisioning stage authenticate the key-bundles received as having originated from Square’s factory key provisioning module. The Square Reader does not accept keys from any entity other than the factory provisioning module. Using the Square-proprietary protocol, the cryptographic keys are injected into new devices in encrypted form.
Need help?
Do you have a question about the Contactless and Chip Reader and is the answer not in the manual?
Questions and answers