PCI DSS is a contractual standard set by the card brands through the PCI Security Standards Council. The Council publishes the standard and lists assessors; it does not list compliant companies. Public evidence lives in two places: the Visa Global Registry of Service Providers and the Mastercard Site Data Protection (SDP) compliant service provider list. Both are maintained by the card brands from Attestations of Compliance submitted by Qualified Security Assessors. Everything else, including the "PCI compliant" badge on a checkout page, is a claim until one of those lists confirms it.
- v4.0.1
- Current PCI DSS version
- Published June 2024; v4.0 retired 31 December 2024
- 31 Mar 2025
- Future-dated v4 requirements became mandatory
- The 51 requirements marked best practice until then
- 43.4%
- of organisations maintained full compliance after initial validation
- Verizon Payment Security Report
Why there is no central registry
The PCI SSC is a standards body owned by the card brands. It maintains the standard, the assessor programmes (QSA, ASV, PCI Forensic Investigator) and the lists of those assessors. Compliance obligations flow through the card brands’ rules and the acquiring banks’ contracts, so the card brands keep the lists of validated service providers. A merchant checks its own acquirer’s requirements; a buyer of a payment-adjacent service checks the brand registries.
The Visa Global Registry of Service Providers is the source for listing service providers that have validated compliance with the PCI DSS.
How the Visa registry works
A service provider that stores, processes or transmits cardholder data on behalf of Visa clients must validate PCI DSS compliance and register. Level 1 providers, those handling over 300,000 transactions a year, need an on-site assessment by a QSA and an Attestation of Compliance. The registry lists the provider, the services validated, the assessor, the region and the validation date. Providers must revalidate every twelve months, with the AOC and Report on Compliance due to Visa one year from the validation date, which is why a listing older than twelve months is treated as expired.
| Registry field | What it tells you | What CertReports records |
|---|---|---|
| Validation date | When the AOC was accepted | The as-of date; expiry twelve months later |
| Services validated | Which services were in the assessment scope | Kept verbatim in the row detail |
| Assessor (QSA) | Who performed the assessment | Linked to the auditor page |
| Region | Visa region of registration | Kept in the row detail |
| Third Party Agent | Registered agent, not necessarily PCI-validated for the service you use | Recorded as an agent registration; no framework state without a validation date |
The Third Party Agent trap
The Visa registry mixes two populations: providers with a PCI DSS validation date, and Third Party Agents registered with Visa for other reasons, such as merchant servicers, encryption support organisations and independent sales organisations. Roughly three quarters of the rows are agent registrations with no validation date. Treat every row as PCI compliant and you mislabel most of the registry. CertReports creates a verified PCI DSS row only when the registry shows a validation date, and records agents separately. The full analysis has the counts.
The Mastercard SDP list
Mastercard publishes its own list of compliant service providers under the Site Data Protection programme. It relies on the same AOC as evidence but is maintained separately, so a provider can appear on one list and not the other. CertReports records both where public; a vendor on either list with a current validation date is registry-verified.
What the AOC must say
The Attestation of Compliance is a short signed summary of the assessment. The Report on Compliance is the full document and is rarely shared. For a buyer the AOC is enough, provided it says four things: the PCI DSS version assessed, the services in scope, the assessor and the date. An AOC for "payment gateway services" does not cover a reporting dashboard or a customer support tool that sees card data.
| Situation | What it means | What to ask |
|---|---|---|
| Badge on the website, no registry row | Vendor-stated | Send the AOC with version, scope, assessor and date |
| Registry row with a validation date within 12 months | Verified by registry | Confirm the service you buy is in the services validated |
| Registry row older than 12 months | Expired | Has the AOC been renewed? Please share the current one |
| Agent registration only | No framework state | Ask whether the service is PCI-validated at all |
| SAQ instead of AOC | Self-assessment | Appropriate for smaller providers; ask which SAQ and whether an ASV scan is current |
What changed in PCI DSS v4
Version 4.0 introduced 64 new requirements, most of them future-dated as best practice until 31 March 2025, when they became mandatory. Version 4.0.1, published in June 2024, corrected and clarified 4.0 without adding requirements, and 4.0 itself was retired on 31 December 2024. An AOC should now cite v4.0.1. Verizon’s Payment Security Report has found for years that compliance decays between assessments; its 2023 edition put full compliance after initial validation at 43.4 percent, which is the strongest argument for checking the validation date rather than the badge.
What to ask the vendor for
- 1
The AOC, not the ROC
A short signed summary naming the version, the assessor and the services in scope.
- 2
Scope match
Confirm the service you buy is in the services validated list. Payment gateways often validate the gateway and not the dashboard.
- 3
Date
An AOC older than twelve months is expired for registry purposes.
- 4
Responsibility matrix
Which requirements are the provider’s and which are yours. Browse validated providers on the Visa PCI registry mirror.
Never "PCI certified"
There is no PCI certificate. CertReports records "validated, listed on the Visa registry" with the validation date and the assessor. A badge on a website with no registry row is vendor-stated.
People also ask
Is there an official list of PCI DSS compliant companies?
Not from the PCI SSC. The card brands keep the lists: the Visa Global Registry of Service Providers and the Mastercard SDP compliant service provider list. Both are built from Attestations of Compliance submitted by assessors.
How long is a PCI DSS validation valid?
Twelve months. Service providers on the Visa registry must revalidate annually, with the AOC and ROC due one year from the validation date; a listing older than that is treated as expired.
What is the difference between an AOC and a ROC?
The Report on Compliance is the assessor’s full report; the Attestation of Compliance is the signed summary that states the version, scope, assessor and date. Buyers normally receive the AOC.
What is a Third Party Agent on the Visa registry?
An entity registered with Visa for activities such as merchant solicitation, device deployment or encryption key management. Registration is not a PCI DSS validation; only rows with a validation date are.
Can a company be PCI certified?
No. PCI DSS validation produces an AOC and, for service providers, a registry listing with a date. There is no certificate, which is why CertReports records "validated and listed" rather than "certified".
What version of PCI DSS should an AOC cite in 2026?
v4.0.1. Version 4.0 was retired on 31 December 2024 and the future-dated requirements became mandatory on 31 March 2025. An AOC still citing v3.2.1 is out of date.
CertReports Research · Index and methodology
Notes from the team that runs the nightly registry syncs, the snapshot pipeline and the state resolver. Every figure quoted is reproducible from the index on the date given.
Read next on CertReports
You might also like
Three quarters of the Visa registry is not a PCI DSS validation
CertReports Research · 17 Sep 2026 · 10 min read
FedRAMP in 2026: Certified replaces Authorized, Ready is retired, 20x goes live
CertReports Research · 5 Sep 2026 · 10 min read
The state of public compliance evidence in 2026: what 3,000 vendors actually publish
CertReports Research · 18 Sep 2026 · 12 min read