Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Outsourcing payment processing does not outsource a merchant’s PCI DSS accountability. A payment provider is responsible for the account data it handles and the PCI DSS requirements it performs, but the merchant must still validate its own compliance and manage the provider relationship. Outsourcing may reduce which requirements apply directly to the merchant’s environment; it does not make the merchant compliant by default.

Does PCI DSS apply if a merchant outsources all payment processing?

Yes. PCI Security Standards Council (PCI SSC) says PCI DSS applies to an entity that stores, processes, or transmits cardholder data whether those activities are conducted directly or by a third-party service provider. Its outsourcing FAQ also directs merchants to the organizations managing their compliance programs, such as their acquirer or payment brand, to confirm the applicable validation requirements.

The practical distinction is between scope and accountability. A payment arrangement can reduce the systems and controls the merchant must address directly, depending on how account data flows and whether the merchant’s systems can affect the cardholder data environment (CDE). It does not eliminate the merchant’s obligation to protect account data, manage relevant providers, or complete the validation required for its circumstances.

What merchants must do under Requirement 12.8

PCI DSS v4.0 Merchant SAQ D sets out the merchant’s service-provider management responsibilities in Requirement 12.8. The accessible SAQ is dated April 2022; PCI SSC’s Document Library lists v4.0.1 as well. Confirm the current assessment requirements and validation route with the entity that accepts your compliance validation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Square Terminal - Credit Card Machine to Accept All Payments | Mobile POS
  • With Square Terminal, you can ring up sales, accept payments, and print receipts, all with one device. Use it at the counter or ring up customers anywhere in your store.
  • Accept all major credit and debit cards and pay one low rate with no hidden fees and no long-term contracts.
  • Process chip cards in just two seconds.
  • Get your money as soon as the next business day.
  • Use it cordlessly with the built-in battery, designed to last all day.
Requirement Merchant responsibility
12.8.1 Maintain a list of third-party service providers (TPSPs) and describe the services each provides.
12.8.2 Maintain written agreements that include the provider’s acknowledgment of its responsibility for the security of account data it possesses, stores, processes, or transmits for the merchant, or of the merchant’s CDE to the extent the provider’s services could affect its security. The agreement need not use PCI DSS’s suggested wording verbatim.
12.8.3 Perform due diligence before engaging a provider.
12.8.4 Have a program to monitor each provider’s PCI DSS compliance status at least once every 12 months.
12.8.5 Document which PCI DSS requirements the provider manages, which the merchant manages, and which are shared.

A provider’s Attestation of Compliance (AOC) or a statement on its website is not a substitute for the written agreement required by 12.8.2. Keep the agreement, due-diligence records, current provider-status evidence, and responsibility assignments together so the merchant can show how it manages the relationship.

What provider compliance does—and does not—mean

Evidence that a provider is PCI DSS compliant helps establish the provider’s status for the services covered by that evidence. It does not establish the merchant’s own compliance. PCI SSC states in the PCI DSS v4.0 Merchant SAQ D: “The use of a PCI DSS compliant TPSP does not make an entity PCI DSS compliant, nor does it remove the entity’s responsibility for its own PCI DSS compliance.”

Rank #2
Dejavoo Z8 EMV CTLS Credit Card Terminal (IP, WiFi, no Dial)
  • Includes Elavon encryption
  • Chip Card / EMV / NFC Compatible
  • 2.4’’ Color LCD with backlight
  • 192 MB of Memory (128 MB RAM / 64 MB DDR RAM)
  • Includes terminal and power supply

Requirement 12.8 does not, by itself, require every TPSP to validate to PCI DSS simply for its customer to satisfy 12.8; the merchant must monitor the provider’s status. But when the provider has agreed to meet PCI DSS requirements on the merchant’s behalf, the merchant must work with it to ensure those requirements are met. If an applicable requirement is not met by the provider, it is not in place for the merchant’s assessment either. A responsibility matrix should therefore identify not just the provider’s general status, but the specific requirements its service covers and the evidence available for them.

How to tell whether a vendor is a TPSP

Do not classify a vendor by its label alone. The relevant question is what the vendor actually does, whether it accesses or affects the CDE, and which service responsibilities it assumes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
First Data FD150 EMV CTLS Credit Card Terminal
  • Same look and feel as the FD130.
  • Upgraded to PCI 5.0.
  • Memory: 128MB, Flash: 256MB
  • Chip Card / EMV / NFC Compatible
  • Processor: Cortex A5 500MHZ

Equipment resellers and manufacturers

A vendor that only supplies or provisions equipment, without ongoing operation or maintenance, is not treated as a TPSP for Requirements 12.8 and 12.9 on that basis. A vendor that provides ongoing support, operates or maintains the equipment, or has access to the CDE can be a TPSP for those services. PCI SSC addressed this distinction in its November 2025 FAQ on equipment resellers and OEMs.

Third-party scripts

For an e-commerce assessment, a script provider can fall outside TPSP treatment under 12.8 and 12.9 only when its sole service is providing scripts unrelated to payment processing and those scripts cannot affect the security of cardholder data or sensitive authentication data. PCI SSC explains the conditions in its March 2025 FAQ on third-party script providers.

Rank #4
Sale
Verifone Vx520 DC EMV Credit Card Terminal
  • Verifone VX520 with Smart Card generates new recurring revenues from value-added applications, thanks to an extraordinary increase in memory of 160 MB standard, increasing to over 500 MB
  • Included: Terminal, power supply, 1 roll paper
  • Mfr Part Number: M252-753-03-NAA-3
  • Specs & Features: Dual EMV Condition

Acquirers

An entity that a payment brand defines as the merchant’s acquirer is not a TPSP for that merchant under 12.8 merely because it acquires transactions. If it also supplies other services, such as terminal management, the parties should determine who is responsible for the PCI DSS requirements applicable to those services. Payment-brand rules determine whether an acquirer must validate as a provider. See PCI SSC’s FAQ on acquirer classification.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Build a responsibility map for your payment setup

For each provider and payment service, record the details that determine scope and responsibility:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Whether account data is stored, processed, or transmitted by the merchant, the provider, or both.
  • Whether the provider’s service can affect the CDE, including through access, support, maintenance, or scripts.
  • Which PCI DSS requirements each party operates or shares, and what evidence supports the assignment.
  • The provider’s PCI DSS status and the date and scope of the evidence being monitored.
  • The merchant’s required validation route and any SAQ eligibility, as confirmed by its acquirer, payment brand, or other compliance-accepting entity.

PCI SSC’s current Document Library lists PCI DSS v4.0.1. The detailed Requirement 12.8 text cited above is from the accessible v4.0 Merchant SAQ D, so do not assume every sentence was checked against the full v4.0.1 standard. For the specific validation path and the effect of a particular payment architecture on scope, ask the organization that accepts your compliance assessment and, where needed, your assessor.

Quick Recap

SaleBestseller No. 1
Square Terminal - Credit Card Machine to Accept All Payments | Mobile POS
Square Terminal - Credit Card Machine to Accept All Payments | Mobile POS
Process chip cards in just two seconds.; Get your money as soon as the next business day.; Use it cordlessly with the built-in battery, designed to last all day.
$239.14
Bestseller No. 2
Dejavoo Z8 EMV CTLS Credit Card Terminal (IP, WiFi, no Dial)
Dejavoo Z8 EMV CTLS Credit Card Terminal (IP, WiFi, no Dial)
Includes Elavon encryption; Chip Card / EMV / NFC Compatible; 2.4’’ Color LCD with backlight
$228.00
Bestseller No. 3
First Data FD150 EMV CTLS Credit Card Terminal
First Data FD150 EMV CTLS Credit Card Terminal
Same look and feel as the FD130.; Upgraded to PCI 5.0.; Memory: 128MB, Flash: 256MB; Chip Card / EMV / NFC Compatible
$299.00
SaleBestseller No. 4
Verifone Vx520 DC EMV Credit Card Terminal
Verifone Vx520 DC EMV Credit Card Terminal
Included: Terminal, power supply, 1 roll paper; Mfr Part Number: M252-753-03-NAA-3; Specs & Features: Dual EMV Condition
$108.21
Bestseller No. 5

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.