attestation
PCI DSS evidence across 1,361 vendors
PCI DSS evidence that a buyer can verify is a registry listing or an attestation of compliance. CertReports mirrors the Visa Global Registry of Service Providers, counting only rows validated as PCI DSS with a validation date, and records the assessor and the date the validation runs through.
- Verified rows
- 1,361
- Vendor-stated
- 12
- Expired
- 158
- Last verified
- 17 Sep 2026
spaymentservices
spaymentservices.com
Spenda
spenda.co
SP.LINKS
splinks.co.jp
SpotOn Transact
spoton.com
Software Shop
sslwireless.com
STAAH
staah.com
STAR SAAS
star-saas.com
Starnikpay
starnik.com
StarRez
IT management
Statebank JSC
statebank.mn
Stax Canada
staxpayments.com
Sticky.IO
sticky.io
Stova
stova.io
Straal Sp. Z.o.o
straal.com
Stratsol
strat-sol.net
Stratus Payment Solutions
stratuspay.com
Zero Technologies
strictlyzero.com
Strivve
strivve.com
PAYONE DMCC
stspayone.com
Martingale Media
sublytics.com
SUMUP CHILE
sumup.cl
SumUp Peru
sumup.pe
Sunday App
sundayapp.com
Suntone Technology
suntone.com
Registry traps
Most Visa registry rows are Third Party Agent or ISO registrations, not PCI DSS validations. Those are excluded. The Mastercard SDP compliant service provider list is the second registry-grade source.
Level 1 service providers
Registries list Level 1 service providers with a QSA-signed ROC or AOC. Smaller merchants and service providers self-assess and do not appear.
