Cyrious SMS 8.6 is NOT a PCI Certified Application. Cyrious SMS 8.9 is awaiting approval. If you are using Cyrious SMS 8.9pci, refer to the following page for assistance:

PCI Certification - TrustKeeper - SAQ-D Compliance Questionaire SMS 8.9



Disclaimer: All information provided in these pages is meant to be helpful for a typical Sign, Print, or Graphics company. If your business model differs significantly from these typical establishments, these recommendations may not apply. In all cases, you are responsible for providing the correct answer and Cyrious assumes no direct or indirect liability with the guidance below.


tocOnce you are logged into TrustKeeper at https://elavonpci.trustkeeper.net/, one of the steps is to set up your Compliance Questionaire. The information below is meant to help you answer those questions. Please note that the answers provided only concern Cyrious' applications. Many of the questions concern Cyrious and other applications you have and must be answered in this context.

The SAQ Questionaire is the document where you must attest that you are following all of the best practices necessary to secure the card holder information you come into contact with.


For users of Cyrious SMS or Control, Cyrious recommends you complete SAQ-D. If you never place a single credit card number into Control or SMS, and no employe ever has, ever does, or ever will then you probably qualify to use SAQ-C. This does not just apply to processing credit card information, but storing any credit card number in the system also. SAQ-C is easier to complete, but if you find that your or an employee has, does, or will put credit card information into SMS or Control you will end up not being in compliance.


The information below assumes you are using Questionaire D. If you are using another form, then this information does not apply to you.

Unfortunately, Cyrious does not know the status of your network. Our support technicians are not authorized to answer any questions on your network security. You will need to have these questions verified by someone knowledgeable about your specific network configuration. In some cases, you may need to make changes or implement additional security measures.

Note: This information only applies to SMS 8.6, it does not apply to any other version of Cyrious SMS and should not be utilized in the assistance of completing the questionnaire if you have any other version.

The information provided here has been made available to assist you with answering the questions in required of our software in Section 3. Stored Data Protection, but you must confirm these for all systems you use.

  • Cyrious SMS 8.6 does not store any magnetic track data. (Question 4)
  • Cyrious SMS 8.6 does not store the card-validation code. (Question 5)
  • Cyrious SMS 8.6 does not store the PIN. (Question 6)
  • Cyrious SMS 8.6 does mask the PAN except when authorized employees need access to this information. (Question 7)
  • Cyrious SMS 8.6 does encrypt sensitive data but the encryption is not strong cryptography as required by PCI with key management for all stored information. (Question 8)
  • Cyrious SMS 8.6 does not rely on disk encryption. (Question 9 & 10)
  • Cyrious SMS 8.6 does not use cryptographic keys for encryption against disclosure and misuse. (Question 11)
  • Cyrious SMS 8.6 does not restrict its encryption keys automatically. Once you enter your key the system uses it automatically and there is no way to retrieve it! (Question 12)
  • Cyrious SMS 8.6 does not store keys securely for you, in the fewest locations and forms possible. (Question 13)
  • Though Cyrious SMS 8.6 does not require key retention, you should have a policy to change the key if the person who created it leaves the company or you believe the key is compromised. (Question 14)
  • Cyrious SMS 8.6 does not generate strong cryptographic keys. (Question 15)
  • Cyrious SMS 8.6 does not secure cryptographic key distribution between its applications. (Question 16)
  • Cyrious SMS 8.6 does not secure cryptographic key storage. (Question 17)
  • Cyrious SMS 8.6 does not change its internal security keys at least annually. (Question 18)
  • Though Cyrious SMS 8.6 does not require key retention, you should have a policy to change the key if the person who created it leaves the company or you believe the key is compromised. (Question 19)
  • Cyrious SMS 8.6 does not split the knowledge and control of the cryptographic keys by having some of those keys controlled by Cyrious and some controlled by you. (Question 20)
  • Cyrious' SMS 8.6 approach does not automatically prevent substitution of cryptographic keys since different parties have different pieces. (Question 21)
  • Cyrious' SMS 8.6 approach does not require a key custodian since their are not user managed keys. (Question 22)

Cyrious SMS 8.6 information for the requirements of our software in Section 4. Transmitted Data Protection, but you must confirm these for all systems you use.

  • Cyrious SMS 8.6 does transmit all sensitive cardholder data using appropriate encryption on all networks. (Question 1)
  • If you are using a wireless network, you must attest to its security settings. (Question 2)
  • Cyrious SMS 8.6 does prevent the sending of any sensitive information through end-user messaging technologies when used correctly, but you need to make sure you have written and enforced policies that also prevent this. (Question 3)

Cyrious SMS 8.6 information for the requirements of our software in Section 6. Application and System Security, but you must confirm these for all systems you use.

  • This requirement specifies that you must maintain the latest version of Cyrious SMS. (Questions 1,2)
  • Cyrious SMS 8.6 is not considered a custom application for purposes of PCI certification. (Question 5, 6)
  • Cyrious SMS 8.6 does not connect to a web system directly if you are not running WebView or Production Terminal. For these, you need to ensure that proper web security techniques are deployed.

Cyrious SMS 8.6 information for the requirements of our software in Section 7. Access Restrictions, but you must confirm these for all systems you use.

  • This section requires you to set up your system and policies so that only users with a requirement for access to sensitive information actually can access that information. Remember to answer this not just as it applies to Cyrious but as it applies to all of your systems.

Cyrious SMS 8.6 has security policies that can restrict this information from individuals. This section requires you to attest that you are using these security features and that you have certain policies in place to control this access.

  • Cyrious SMS 8.6 does not require additional automated access control system beyond those implemented in Windows. (Question 5)

Cyrious SMS 8.6 information for the requirements of our software in Section 8. Account Security, but you must confirm these for all systems you use.

  • This section requires you to set up your system and policies so that only users accounts are established and tracked.
  • Cyrious SMS 8.6 does allow you to create unique logins per employee for access to credit card information. (Question 1)
  • Cyrious SMS 8.6 does use password authentication. (Question 2)
  • Cyrious SMS 8.6 does not use two-factor authentication. (Question 3)
  • Cyrious SMS 8.6 does not secure passwords at all times using strong cryptography. (Question 4)
  • Cyrious SMS 8.6 does control access to the user setup areas. (Question 5)
  • Cyrious SMS 8.6 does not require you to reenter your password before resetting yours or another password. (Question 6)
  • Cyrious SMS 8.6 does not require you to enter a unique password for a new user and can force that to password to be reset on first login. You must ensure your policy specifies the password must be changed on first login. (Question 7)
  • Cyrious SMS 8.6 does not automatically disable access for any employee that is no longer active. You must ensure your policy sets the employee inactive in Cyrious upon termination. (Question 8)
  • You must ensure your policy is to remove the Cyrious login when they are no longer using the system. (Question 9)
  • Cyrious SMS 8.6 does not provide access for vendors. (Question 10)
  • You must not use any shared logins. Your policy must ensure each employee uses their own account. (Question 12)
  • Cyrious SMS 8.6 does not force users to change their passwords every 90 days. (Question 13)
  • Cyrious SMS 8.6 does not require a minimum of seven characters in the password. (Question 14)
  • Cyrious SMS 8.6 does not require passwords to contain both a number and letter. (Question 15)
  • Cyrious SMS 8.6 does not track the last 4 passwords used and prevent reuse of any of these passwords. (Question 16)
  • Cyrious SMS 8.6 does not automatically lock out a user for 30 minutes after 6 invalid attempts. (Question 17, 18)
  • Cyrious SMS 8.6 does not have an option to automatically lock the screen and require a password to resume. Cyrious SMS 8.6 users must make sure they enable the Windows screen saver to lock the screen after 15 minutes or less of inactivity and then require a password to log back in. (Question 19)
  • Cyrious SMS 8.6 does not automatically require authentication for any database access. (Question 20)

Cyrious SMS 8.6 information for the requirements of our software in Section 8. Account Security, but you must confirm these for all systems you use.

  • These answers are only as the question relates to Cyrious. Each of these questions is broader than just Cyrious and you must answer them in the context of the entire business operations.
  • Cyrious SMS 8.6 does log activity for users throughout the system, particularly any access to sensitive information. This information provide audit trails for all users, administrative or otherwise, that can be used to recreate access to sensitive information. (Question 1, 2, 3, 4, 5, 6)
  • Cyrious SMS 8.6 does maintain system audit logs. These questions also apply to Windows logging. (Question 7, 8)
  • Cyrious SMS 8.6 does log the following information: User ID, Date and Time, Result, Computer Name,and Type of Event. These questions also apply to Windows logging. (Question 9-14)
  • Cyrious SMS 8.6 does require all computers running Cyrious to be synchronized in time . (Question 15)
  • Cyrious SMS 8.6 does not allow any alteration of the audit trails. Cyrious does not store an encrypted checksum to detect any external alteration in the data. (Question 16, 18)
  • Cyrious SMS 8.6 does not have provisions to restrict access to view any activities (audit logs) to users with a need for that information. Question 17)
  • Audit trails are backed up when user data is backed up. You should make sure your policy conforms to PCI requirements for backup. (Question 19)
  • Cyrious SMS 8.6 does not use “external facing” technologies. If you are using these, you must ensure that the database logs are not on an external facing server or are copied onto a LAN server. (Question 20)
  • Cyrious SMS 8.6 does not detect external changes in the log files and will not notify the user of any such detections. (Question 21)
  • Cyrious SMS 8.6 does maintain log files indefinitely. (Question 23)

If you are running Cyrious SMS 8.6 that version is not PCI certified, however does not store sensitive authentication data after authorization.

You could leave a comment if you were logged in.