The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outsourcing payment processing does not make a merchant automatically PCI DSS compliant or transfer the merchant’s accountability to its provider. PCI DSS still applies when a third party stores, processes, or transmits payment-card data. Outsourcing may reduce the systems and requirements that apply directly to the merchant, but the merchant must define its scope, validate compliance through the route set by its acquirer or other compliance-accepting entity, and manage provider responsibilities.
What the PCI DSS rule actually means
The headline “merchants are on the hook” is shorthand for a shared-responsibility model, not a rule that payment providers have no obligations. PCI Security Standards Council guidance says PCI DSS applies whether account-data activities are performed by the merchant or by a third party.
A merchant remains responsible for its own PCI DSS compliance. The council’s Merchant SAQ D states: “The use of a PCI DSS compliant TPSP does not make an entity PCI DSS compliant, nor does it remove the entity’s responsibility for its own PCI DSS compliance.” A provider remains responsible for the account data it possesses, stores, processes, or transmits and for services it performs that can affect a customer’s cardholder-data environment (CDE).
What outsourcing can—and cannot—change
| Question | What outsourcing may change | What it does not change |
|---|---|---|
| Where card data is handled | The provider may host or operate the payment page, gateway, tokenization, or other processing components, reducing the merchant’s direct technical scope. | The merchant must still understand the data flow and protect every component that remains in its environment. |
| Which requirements are performed by whom | The provider may perform particular controls on the merchant’s behalf. | The merchant must document the allocation and ensure those controls are actually met. |
| Compliance evidence | A provider’s assessment reports or attestations can supply evidence about its service. | Provider evidence is not the merchant’s own validation and does not remove the merchant’s responsibilities. |
| Assessment route | A simpler architecture may make a particular self-assessment questionnaire (SAQ) possible. | The acquirer, payment brand, or other compliance-accepting entity determines the merchant’s required validation route. |
Requirement 12.8: the merchant’s provider-management checklist
PCI DSS v4.0 Merchant SAQ D places third-party service-provider (TPSP) management in Requirement 12.8. The merchant should maintain evidence for each of these controls:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
1. Keep a current provider and service inventory
Under 12.8.1, list each relevant provider and describe the services it supplies. Include payment gateways, hosted checkout services, tokenization providers, managed security services, and other vendors whose work can affect payment-card security.
2. Put responsibility in a written agreement
Requirement 12.8.2 calls for written agreements that include the provider’s acknowledgment of its responsibility for the security of account data and the CDE, to the extent relevant to its service. The acknowledgment does not have to use PCI DSS’s sample wording. A provider’s website claim or an Attestation of Compliance (AOC) is not a substitute for the contractual acknowledgment.
3. Perform due diligence before engagement
Under 12.8.3, evaluate a provider before signing or relying on its service. Review what data it handles, how its service can affect the CDE, its security controls, and the evidence it can provide. Record the decision and any conditions or limitations.
Rank #2
4. Monitor status at least every 12 months
Requirement 12.8.4 requires a program to monitor each provider’s PCI DSS compliance status at least once every 12 months. Check the date, scope, and service covered by the provider’s current evidence rather than treating an old certificate or a generic marketing statement as proof.
Free tools Windows power users keep installed
One-click scans. No signup required.
5. Assign every applicable requirement
Under 12.8.5, identify which PCI DSS requirements are managed by the merchant, by the provider, or jointly. A responsibility matrix should name the control, the party operating it, the evidence produced, and any merchant action needed to make the control effective.
Why a provider’s compliance does not make the merchant compliant
If a provider has agreed to meet a PCI DSS requirement for the merchant, the merchant must work with that provider to ensure the requirement is met. If the provider fails to meet an applicable requirement, that requirement is not in place for the merchant’s assessment either.
PCI SSC guidance also clarifies that Requirement 12.8 does not require every TPSP to hold PCI DSS validation merely for a customer to satisfy 12.8. The merchant must monitor the provider’s status and understand the service’s evidence. Whether a particular provider must validate, and what documentation is acceptable, depends on the service, the payment-brand rules, and the merchant’s compliance-accepting entity.
Merchant duties versus provider duties
Merchant responsibilities
- Define the payment architecture and PCI DSS scope.
- Protect systems, people, and processes that remain in the merchant’s environment.
- Maintain the TPSP inventory, agreements, due-diligence records, annual status checks, and responsibility matrix required by 12.8.
- Complete the applicable validation and submit evidence through the route specified by the acquirer, payment brand, or other compliance-accepting entity.
Provider responsibilities
- Protect account data it possesses, stores, processes, or transmits.
- Operate the PCI DSS requirements it has accepted on the merchant’s behalf.
- Provide accurate, service-specific evidence and disclose relevant limitations or changes.
- Support the customer’s assessment without implying that the customer inherits the provider’s compliance status.
Requirement 12.9 is the corresponding support requirement for service providers when the assessed entity is a service provider. It is not the merchant’s substitute for 12.8. Merchants using providers should focus on their own 12.8 controls and the responsibilities assigned to each service.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsIs every vendor a TPSP?
Classification depends on what the vendor actually does, not merely on its label or industry.
Rank #4
Equipment reseller or original equipment manufacturer
A vendor that only sells or provisions equipment and does not operate or maintain it is not a TPSP for 12.8 or 12.9 on that basis alone. If it provides ongoing support, operation, maintenance, or access to the CDE, those services can make it a TPSP for the relevant activities.
Third-party scripts
In an e-commerce assessment, a script provider can fall outside TPSP treatment only when its sole service is providing scripts unrelated to payment processing and the scripts cannot affect the security of cardholder data or sensitive authentication data. A script that can influence payment capture or security requires a more careful scope and responsibility analysis.
Acquirer
An entity defined by a payment brand as the merchant’s acquirer is not a TPSP for that merchant under 12.8 simply because it acquires transactions. If the acquirer also supplies services such as terminal management, the parties should assign responsibility for the requirements relevant to those additional services. Payment-brand rules determine whether the acquirer must validate as a service provider.
How to evaluate a payment-service arrangement
Before selecting or renewing a service, compare the arrangement on these five axes:
- Data location: Determine whether the merchant, provider, or both store, process, or transmit account data.
- CDE influence: Identify whether the provider’s systems, code, support access, or administration can affect the CDE.
- Control ownership: Map each applicable requirement to the merchant, provider, or both, and identify the evidence available.
- Evidence currency: Check the provider’s PCI DSS status, the date of its evidence, the assessed service, and any exclusions.
- Validation route: Confirm with the acquirer, payment brand, or other compliance-accepting entity which SAQ, assessment, and documentation apply to the specific architecture.
Keep the resulting data-flow diagram, contract, responsibility matrix, provider evidence, annual review, and validation records together. A change to checkout code, hosting, terminals, support access, or tokenization can change the analysis.
Which PCI DSS version and guidance apply?
The PCI SSC Document Library lists PCI DSS v4.0.1. The detailed Requirement 12.8 wording cited here is from the accessible PCI DSS v4.0 Merchant SAQ D dated April 2022. PCI SSC FAQs include an equipment-reseller clarification from November 2025 and a script-provider clarification from March 2025. Because validation programs and payment-brand rules can impose additional conditions, confirm the current requirements and the correct SAQ with the entity that accepts the merchant’s compliance.
A practical compliance record to maintain
- Current list of providers and the services each performs.
- Signed agreements containing the relevant responsibility acknowledgment.
- Pre-engagement due-diligence results and approval records.
- Provider AOCs, assessment reports, or other service-specific evidence, with dates and scope.
- An annual—or more frequent, where risk or contract requires—status review record.
- A requirement-by-requirement responsibility matrix and data-flow diagram.
- The merchant’s completed validation documents and communications with its compliance-accepting entity.
The Bottom Line
Outsourcing can narrow a merchant’s technical PCI DSS scope, but it cannot outsource accountability. The merchant must validate its own compliance, manage providers under Requirement 12.8, and confirm exactly which controls and evidence belong to each party.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




