Campus Merchant Resources
Campus Merchant Resources
The Campus Credit Card Coordinator provides oversight in approving and coordinating with departments and organizations that wish to accept credit/debit cards as payment for their goods or services. The Campus Credit Card Coordinator is also tasked with ensuring compliance by campus merchants with all regulatory requirements, campus policies and related procedures.
Merchant Quick Links
New Merchant Information
- UCR New Merchant Application - Form used for potential campus merchants to receive internal consideration for accepting credit/debit card payments.
- Annual Credit Card Merchant Agreement- Form used for re-certification of credit card merchant responsibilities.
- Current Merchant Prices and Rates - Potential campus merchants considering a new Merchant application should review this for the latest prices and rates.
- Merchant System Exception Request Form - To accompany a New Merchant Application (see above) when using a non-campus-approved payment method.
- Web eCommerce Storefront options - a summary of eCommerce options available via Cashnet
- Campus Event/Conference Registration System - Summary of Campus Registration System via eTouches/Aventri
PCI DSS Compliance
- Vigione for SAQ completion and external vulnerability scan management
- Payment Card Industry (PCI) Security Standards Council (SSC) site for PCI DSS standards, forms, and documentation.
- UCR hosted PCI DSS v3.0 Training with Coalfire (10/29/2014)
UCR Policies, Procedures and Best Practices for Campus Merchants
- UCR Campus Policy No. 200-17: Credit/Debit Card Payments - Acceptance of
- UCOP BUS-49: Policy for Cash and Cash Equivalents Received
- UCR response to Third Party Merchant Services and Mobile Pay Devices (via Square, Stripe, etc.)
- UCR Terminal Control Measures
Contact UCR's Campus Cash and Credit Card Coordinator
Cashnet eMarkets (eCommerce)
Cashnet replaces Campus Gateway SecurePay/CyberSource
- Cashnet replaced Growl for Student Self-Service payments and billing presentment, and was deployed alongside Banner Student in October 2016.
- Cashnet was also identified as the replacement for SecurePay/CyberSource as the campus gateway for web ecommerce merchants, targeted for conversion by 12/31/2017.
- In addition, Cashnet also offers new options for campus web merchants that allow for rapid deployment and lower development costs.
Available Cashnet eMarket Options
Below is a brief comparison of the 2 configuration options to consider for Cashnet ecommerce deployments. Note that current SecurePay/CyberSource storefronts will be migrated to the "Checkout" eMarket.
Checkout eMarket |
Storefront eMarket |
Gives dept. complete control over the online store experience via a custom-built website |
Complete store on a single site, hosted entirely on CASHNet’s servers |
Primarily targeted for higher volume and/or third-party hosted solutions. |
Primarily targeted for rapid deployment and lower-volume sites |
Moderate-to-high technical skills required; likely to require IT involvement. |
Low technical skills required, with most changes done in a web-based GUI interface |
BAMS-issued Merchant ID with varying rates, typically less than 2.75% |
BAMS-issued Merchant ID with varying rates, typically around 2.75% |
Annual PCI DSS Validation Required |
Annual PCI DSS Validation Required |
Next Steps
Those interested in a Cashnet eMarket web storefront should review and complete the UCR New Merchant Application as well as the Current Merchant Prices and Rates .
Additional information can be found under Campus Merchant Resources.
PCI Policies
The follow represent the industry and campus policies governing merchant responsibilities for credit card acceptance.
Quick Links
- UCR Campus Policy No. 200-17: Credit/Debit Card Payments - Acceptance of
- UCOP BUS-49: Policy for Cash and Cash Equivalents Received
- UCR response to Third Party Merchant Services and Mobile Pay Devices (via Square, Stripe, etc.)
PCI Training
Links for PCI DSS Resources
Training Video or Presentations
- PCI DSS Security Awareness Training (SAT)
- Per PCI DSS, required annually by all merchants and those handling credit cards, including supervisors
- Go to http://ucrlearning.ucr.edu/
- Search for Activity "PCI DSS Security Awareness Training"
- UCR hosted PCI DSS v3.0 Training with Coalfire (10/29/2014)