Sage 100

 View Only
Expand all | Collapse all

Holy crap, what the hell am I missing? How have I

  • 1.  Holy crap, what the hell am I missing? How have I

    Posted 04-14-2015 12:37
    Holy crap, what the hell am I missing? How have I not had to address this previously? Client just upgraded from 4.40 to v2014. When they enter credit card Sales Orders, they simply just specify the credit card info and that's it; they don't pre-auth or charge the card or anything at that time; that's done at time of S/O Invoicing when they hit the card for the full order/invoice amount. So therefore they're unable to appropriately enter the CVV2 (validation code) during S/O Entry at the same time they enter the credit card info, which means they won't have it during Invoicing. In 4.40 you could enter the CVV2 during S/O Entry even if you're not performing an actual credit card transaction. I know the code can be stored in some other field, but that defeats part of the whole PCI Compliance.


  • 2.  RE: Holy crap, what the hell am I missing? How have I

    Posted 04-14-2015 13:23
    Good points Brett. I would like to see some best practices others employ for this when the time between pre-auth and shipment (invoicing) is lengthy and credit cards are in use. Storing the code is definitely frowned upon.


  • 3.  RE: Holy crap, what the hell am I missing? How have I

    Posted 04-14-2015 17:53
    Storing the CVV2 is frowned upon... however I see most clients use that ""code"" as the Card ID.


  • 4.  RE: Holy crap, what the hell am I missing? How have I

    Posted 04-14-2015 18:37
    @MadelineStefanou - Interesting....


  • 5.  RE: Holy crap, what the hell am I missing? How have I

    Posted 04-15-2015 08:39
    And it will get even more interesting if they have a data breach...


  • 6.  RE: Holy crap, what the hell am I missing? How have I

    Posted 04-15-2015 09:36
    Agree @PhilMcIntosh. If they are using the CVV as the card ID, they didn't get that idea from us!


  • 7.  RE: Holy crap, what the hell am I missing? How have I

    Posted 04-16-2015 09:36
    So what is it that Sage expects folks to do in this situation? As far as I can tell, the only option is to basically go against PCI Compliance and store the validation code somewhere. Same 'ol Sage I guess. 1 step forward by introducing/integrating Sage Exchange Vault re: PCI Compliance, but 2 steps back by taking away the ability to enter the validation code during S/O Entry (unless of course you actually process a cc trans from S/O Entry).


  • 8.  RE: Holy crap, what the hell am I missing? How have I

    Posted 05-04-2015 08:55
    So basically I found out that you can simply no longer store the CVV2 in Sage 100 like you used to be able to in S/O Entry. Doing so goes against PCI Compliance. If however you pre-authorize a credit card during S/O Entry, you'll be prompted to specify the CVV2 within Sage Exchange. Therefore I'm suggesting the client reach out to SPS to make sure they understand if and how their credit card processing rate/fees might change if they begin pre-authorizing. I'm also encouraging them to inquire as to the impact of whether the CVV2 is present or not during S/O Invoice Entry credit card processing.


  • 9.  RE: Holy crap, what the hell am I missing? How have I

    Posted 05-04-2015 10:06
    Ok so based on What @BrettZimmerman is saying does anyone know how APS deals with this?


  • 10.  RE: Holy crap, what the hell am I missing? How have I

    Posted 05-04-2015 10:12
    American Psychological Society, @DianeRuth?


  • 11.  RE: Holy crap, what the hell am I missing? How have I

    Posted 05-04-2015 10:15
    American Payment Solutions .


  • 12.  RE: Holy crap, what the hell am I missing? How have I

    Posted 05-04-2015 10:18
    @DianeRuth, I don't think it matters whether it's SPS or APS or whomever, because the CVV2 field is just no longer present in Sage 100 S/O Entry.


  • 13.  RE: Holy crap, what the hell am I missing? How have I

    Posted 05-05-2015 11:12
    Well I am pretty sure that APS has a feature in their gateway - not in MAS - that tells the system to remember the cvv code in the vault or gateway and not require it any longer. Ask for Melanie at APS.