Skip to main content

Explainers

Where PCI DSS evidence actually lives: the Visa and Mastercard registries

There is no PCI SSC list of compliant companies. Public PCI DSS evidence lives on the Visa Global Registry and the Mastercard SDP list. How each works, the twelve-month clock, and what an AOC must say.

CertReports ResearchPublished 3 Sep 2026Updated 18 Sep 202610 min read

A payment card being tapped on a terminal
Photo by Clay Banks on Unsplash

PCI DSS is a contractual standard set by the card brands through the PCI Security Standards Council. The Council publishes the standard and lists assessors; it does not list compliant companies. Public evidence lives in two places: the Visa Global Registry of Service Providers and the Mastercard Site Data Protection (SDP) compliant service provider list. Both are maintained by the card brands from Attestations of Compliance submitted by Qualified Security Assessors. Everything else, including the "PCI compliant" badge on a checkout page, is a claim until one of those lists confirms it.

v4.0.1
Current PCI DSS version
Published June 2024; v4.0 retired 31 December 2024
31 Mar 2025
Future-dated v4 requirements became mandatory
The 51 requirements marked best practice until then
43.4%
of organisations maintained full compliance after initial validation
Verizon Payment Security Report

Why there is no central registry

The PCI SSC is a standards body owned by the card brands. It maintains the standard, the assessor programmes (QSA, ASV, PCI Forensic Investigator) and the lists of those assessors. Compliance obligations flow through the card brands’ rules and the acquiring banks’ contracts, so the card brands keep the lists of validated service providers. A merchant checks its own acquirer’s requirements; a buyer of a payment-adjacent service checks the brand registries.

The Visa Global Registry of Service Providers is the source for listing service providers that have validated compliance with the PCI DSS.

How the Visa registry works

A service provider that stores, processes or transmits cardholder data on behalf of Visa clients must validate PCI DSS compliance and register. Level 1 providers, those handling over 300,000 transactions a year, need an on-site assessment by a QSA and an Attestation of Compliance. The registry lists the provider, the services validated, the assessor, the region and the validation date. Providers must revalidate every twelve months, with the AOC and Report on Compliance due to Visa one year from the validation date, which is why a listing older than twelve months is treated as expired.

Registry fieldWhat it tells youWhat CertReports records
Validation dateWhen the AOC was acceptedThe as-of date; expiry twelve months later
Services validatedWhich services were in the assessment scopeKept verbatim in the row detail
Assessor (QSA)Who performed the assessmentLinked to the auditor page
RegionVisa region of registrationKept in the row detail
Third Party AgentRegistered agent, not necessarily PCI-validated for the service you useRecorded as an agent registration; no framework state without a validation date
A laptop displaying an analytics dashboard
Visa publishes the registry as monthly PDF snapshots as well as the searchable site; CertReports mirrors the site nightly. · Photo by Luke Chesser on Unsplash

The Third Party Agent trap

The Visa registry mixes two populations: providers with a PCI DSS validation date, and Third Party Agents registered with Visa for other reasons, such as merchant servicers, encryption support organisations and independent sales organisations. Roughly three quarters of the rows are agent registrations with no validation date. Treat every row as PCI compliant and you mislabel most of the registry. CertReports creates a verified PCI DSS row only when the registry shows a validation date, and records agents separately. The full analysis has the counts.

The Mastercard SDP list

Mastercard publishes its own list of compliant service providers under the Site Data Protection programme. It relies on the same AOC as evidence but is maintained separately, so a provider can appear on one list and not the other. CertReports records both where public; a vendor on either list with a current validation date is registry-verified.

What the AOC must say

The Attestation of Compliance is a short signed summary of the assessment. The Report on Compliance is the full document and is rarely shared. For a buyer the AOC is enough, provided it says four things: the PCI DSS version assessed, the services in scope, the assessor and the date. An AOC for "payment gateway services" does not cover a reporting dashboard or a customer support tool that sees card data.

SituationWhat it meansWhat to ask
Badge on the website, no registry rowVendor-statedSend the AOC with version, scope, assessor and date
Registry row with a validation date within 12 monthsVerified by registryConfirm the service you buy is in the services validated
Registry row older than 12 monthsExpiredHas the AOC been renewed? Please share the current one
Agent registration onlyNo framework stateAsk whether the service is PCI-validated at all
SAQ instead of AOCSelf-assessmentAppropriate for smaller providers; ask which SAQ and whether an ASV scan is current

What changed in PCI DSS v4

Version 4.0 introduced 64 new requirements, most of them future-dated as best practice until 31 March 2025, when they became mandatory. Version 4.0.1, published in June 2024, corrected and clarified 4.0 without adding requirements, and 4.0 itself was retired on 31 December 2024. An AOC should now cite v4.0.1. Verizon’s Payment Security Report has found for years that compliance decays between assessments; its 2023 edition put full compliance after initial validation at 43.4 percent, which is the strongest argument for checking the validation date rather than the badge.

Code on a laptop screen
A responsibility matrix says which of the twelve requirements are the provider’s and which are yours. Ask for it with the AOC. · Photo by Ilya Pavlov on Unsplash

What to ask the vendor for

  1. 1

    The AOC, not the ROC

    A short signed summary naming the version, the assessor and the services in scope.

  2. 2

    Scope match

    Confirm the service you buy is in the services validated list. Payment gateways often validate the gateway and not the dashboard.

  3. 3

    Date

    An AOC older than twelve months is expired for registry purposes.

  4. 4

    Responsibility matrix

    Which requirements are the provider’s and which are yours. Browse validated providers on the Visa PCI registry mirror.

Never "PCI certified"

There is no PCI certificate. CertReports records "validated, listed on the Visa registry" with the validation date and the assessor. A badge on a website with no registry row is vendor-stated.

People also ask

Is there an official list of PCI DSS compliant companies?

Not from the PCI SSC. The card brands keep the lists: the Visa Global Registry of Service Providers and the Mastercard SDP compliant service provider list. Both are built from Attestations of Compliance submitted by assessors.

How long is a PCI DSS validation valid?

Twelve months. Service providers on the Visa registry must revalidate annually, with the AOC and ROC due one year from the validation date; a listing older than that is treated as expired.

What is the difference between an AOC and a ROC?

The Report on Compliance is the assessor’s full report; the Attestation of Compliance is the signed summary that states the version, scope, assessor and date. Buyers normally receive the AOC.

What is a Third Party Agent on the Visa registry?

An entity registered with Visa for activities such as merchant solicitation, device deployment or encryption key management. Registration is not a PCI DSS validation; only rows with a validation date are.

Can a company be PCI certified?

No. PCI DSS validation produces an AOC and, for service providers, a registry listing with a date. There is no certificate, which is why CertReports records "validated and listed" rather than "certified".

What version of PCI DSS should an AOC cite in 2026?

v4.0.1. Version 4.0 was retired on 31 December 2024 and the future-dated requirements became mandatory on 31 March 2025. An AOC still citing v3.2.1 is out of date.

PCI DSSVisaMastercardregistriesAOC
C

CertReports Research · Index and methodology

Notes from the team that runs the nightly registry syncs, the snapshot pipeline and the state resolver. Every figure quoted is reproducible from the index on the date given.

You might also like