generated: '2026-07-24' method: searched source: >- Cuscal company profile + public payments product pages (https://www.cuscal.com/payments/) and Australian payments regulatory record note: >- These are payment-scheme / regulatory participation and standards claims established in the public record (Cuscal is an APRA/ASIC-regulated ADI and a participant in the named Australian payment rails and the Consumer Data Right). They are NOT derived from a machine-readable Cuscal OpenAPI, which is not published. No published third-party audit certificate (SOC 2, ISO 27001, PCI DSS attestation) was located on the public site, so no `Compliance` pointer is emitted — only standards participation is asserted here. standards: - id: consumer-data-right name: Consumer Data Right (CDR) / Australian open banking conforms: true evidence: >- Cuscal operates as a CDR data holder and accredited data recipient (ADR), following the CDR technical standards (Data Standards Body / ACCC). - id: npp-iso20022 name: New Payments Platform (NPP) — ISO 20022 messaging (PayID, PayTo) conforms: true evidence: >- Cuscal is an NPP participant offering PayID and PayTo; NPP settlement and messaging use the ISO 20022 standard under Australian Payments Plus (AP+). - id: bpay name: BPAY scheme conforms: true evidence: Cuscal provides BPAY biller and payer services as a scheme participant. - id: direct-entry name: Direct Entry (BECS) bulk electronic clearing conforms: true evidence: Cuscal offers Direct Entry processing under the AP+/BECS framework. - id: rtgs name: Real-Time Gross Settlement (RITS/RTGS) conforms: true evidence: Cuscal provides RTGS services as a settlement participant. - id: card-schemes name: Scheme card issuing and acquiring (Visa / Mastercard / eftpos) conforms: true evidence: >- Cuscal is a principal issuer and acquirer across the major card schemes and a member of eftpos Payments Australia. - id: pci-dss name: PCI DSS (card data handling) conforms: true evidence: >- As a scheme card issuer-processor and acquirer, Cuscal operates under PCI DSS obligations; no public attestation document was located. published_certificate: false