Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The PCI Security Standards Council’s cloud computing guidelines help organizations understand how PCI DSS responsibilities and scope can work when payment environments use cloud services. They do not make cloud data exempt from PCI DSS, certify a customer’s setup, or replace the standard. The original supplement was announced on 7 February 2013; the current official edition located here is dated April 2018 and refers to PCI DSS version 3.2.

What the PCI SSC cloud guidelines are

PCI SSC announced the PCI DSS Cloud Computing Guidelines Information Supplement on 7 February 2013. Produced by its Cloud Special Interest Group, it was intended to help merchants, service providers, assessors, and others using, considering, providing, or assessing cloud technology understand security and PCI DSS implications. The announcement described it as a guide for choosing cloud solutions and third-party providers that can help secure payment data and support compliance. PCI SSC’s 2013 announcement.

The detailed official document available for this article is the April 2018 supplement. It covers cloud concepts and provider/customer relationships, PCI DSS responsibilities, scope and segmentation, compliance challenges, and business and technical security considerations. Appendices include service-model responsibility considerations, a sample system inventory, a sample responsibility management matrix, implementation questions, and technical security considerations.

The matrix is a discussion aid for assigning and clarifying work; it is not a new PCI DSS requirement. The supplement itself says it does not replace, supersede, or extend PCI SSC standards. It also states that its PCI DSS references are to version 3.2, so it should not be treated as a current compliance determination.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does PCI DSS apply to cloud services?

Yes, when account data is stored, processed, or transmitted in a cloud environment, the supplement says PCI DSS applies. Cloud deployment does not, by itself, remove systems or services from scope. PCI SSC’s current PCI DSS overview describes the standard’s audience as entities that store, process, or transmit cardholder data or sensitive authentication data, as well as entities that could affect the security of the cardholder data environment (CDE).

Whether a particular component is in scope depends on how it connects to, supports, or can affect the CDE and on the environment’s actual boundaries. A cloud provider’s general statement that it is PCI compliant does not establish that a customer’s services, configuration, data flows, and responsibilities are covered.

Who is responsible for PCI DSS in the cloud?

Responsibility varies with the cloud service and deployment arrangement, the services selected, and how the customer uses them. A provider may operate some relevant controls, the customer may operate others, and some work may be shared. The customer still needs to understand and manage its own obligations: a provider’s involvement does not transfer ultimate responsibility for protecting payment data or ensuring the payment environment is secure. PCI SSC and the Cloud Security Alliance reinforced that point in their 5 August 2021 joint bulletin.

Use the supplement’s responsibility matrix as a starting point for a service-specific conversation, not as a universal allocation of controls. For each applicable PCI DSS requirement, record who operates the control, what the other party must do, and what evidence can demonstrate that it is working.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Questions to settle with a cloud service provider

  • Which exact cloud service, region or environment, and deployment arrangement are covered by the provider’s validation?
  • When was the relevant validation performed, and what evidence can the provider supply for the service being used?
  • Which applicable controls does the provider operate, which remain customer-operated, and which are shared?
  • What customer configuration, access management, monitoring, testing, incident response, or reporting actions are required?
  • How do the contract and operating procedures define responsibilities for incidents, security testing, and evidence delivery?

Ask for evidence tied to the service and configuration in use. A provider-wide compliance claim is not proof that every service or customer deployment is included.

How to scope a cloud cardholder data environment

The supplement discusses private, public/shared, and hybrid cloud arrangements. It highlights effective isolation of CDE components and, in shared environments, separation between tenants. The relevant question is not simply whether a system runs in the cloud, but whether its data flows, connectivity, access, and security impact place it within or adjacent to the CDE.

  1. Inventory systems and data flows. Identify where account data is stored, processed, or transmitted, and which systems and services connect to or can affect those activities. The supplement includes a sample system inventory to support this work.
  2. Describe the cloud arrangement. Record the service model and deployment or tenancy model for each relevant service, including whether the environment is private, shared/public, or hybrid.
  3. Map responsibilities requirement by requirement. Assign each applicable PCI DSS activity to the provider, the customer, or both, and identify the evidence each party can produce.
  4. Confirm boundaries and isolation. Assess CDE connections, segmentation controls, and—where infrastructure is shared—how tenant separation is implemented and supported.
  5. Check validation scope and obligations. Match provider evidence to the precise services being used, then consult current PCI DSS materials and the applicable payment brand or acquirer program for validation obligations.

PCI SSC notes that payment brands and acquirers determine whether an entity must comply with or validate against a PCI SSC standard. The 2018 supplement can help frame the assessment, but it cannot decide an organization’s present validation requirements.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to compare cloud options for a payment environment

Compare arrangements by the responsibilities and evidence they create, rather than treating one cloud category as automatically compliant or out of scope.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Comparison area What to establish
Service model Whether the service is SaaS, PaaS, or IaaS, and which relevant controls the provider operates versus those left to the customer.
Deployment and tenancy Whether the environment is private, public/shared, or hybrid, and how CDE isolation and tenant separation are achieved where relevant.
Validation coverage The exact services included in the provider’s validation and whether the customer’s selected service and configuration are covered.
Evidence access What documentation or other evidence the provider can make available to support the customer’s assessment.
Scope and segmentation How data flows, connections, and isolation affect CDE boundaries and which systems may affect CDE security.
Operational and contractual clarity Who handles incidents, testing, reporting, and other shared activities, and how the arrangement is documented.

PCI SSC’s April 2018 announcement says the guidelines were developed in collaboration with more than 100 global organizations representing banks, merchants, security assessors, and technology vendors. That collaboration does not make the supplement a standard or an endorsement of any particular cloud provider or security product.

Which guidance to use for a current decision

Use the cloud supplement to structure questions about service models, scope, segmentation, and provider/customer responsibilities. Because its PCI DSS references are to version 3.2, pair it with PCI SSC’s current PCI DSS resources and the requirements of the applicable payment brand or acquirer when determining what applies now. For an environment-specific interpretation, PCI SSC’s overview points readers toward qualified assessors.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.