attestation
PCI DSS evidence across 158 vendors
PCI DSS evidence that a buyer can verify is a registry listing or an attestation of compliance. CertReports mirrors the Visa Global Registry of Service Providers, counting only rows validated as PCI DSS with a validation date, and records the assessor and the date the validation runs through.
- Verified rows
- 1,361
- Vendor-stated
- 12
- Expired
- 158
- Last verified
- 17 Sep 2026
BLOOM FINANCE
pion.finance
Platform Factory
platformfactory.io
Prysym
prysym.com
Qolo
qolo.io
UAB Coinpal
rampeasy.com
Rebilly
rebilly.com
Unibanca
redunicard.com
Unibanca S.A. Miraflores
redunicard.pe
Rycor Solutions
rycor.net
satim
satim.dz
LNW Gaming
scientificgames.com
Simplepay Gateway Sdn Bhd
senangpay.my
Sensedia S/A
sensedia.com
Shanghai FFT Information Service
shfft.com
Shopline US
shopline.com
SHOPLINE M SDN. BHD
shopline.my
Smart Glocal Services
smart-glocal.com
somosredcompanies
somosredcompanies.com
Stitch Money Pty
stitch.money
SWIFTPAY
swiftpay.one
Tarlan Payments
tarlanpayments.kz
Cardtronics Canada Operations
threshold-fti.com
tkpay
tkpay.com
Toss Payments
tosspayments.com
Registry traps
Most Visa registry rows are Third Party Agent or ISO registrations, not PCI DSS validations. Those are excluded. The Mastercard SDP compliant service provider list is the second registry-grade source.
Level 1 service providers
Registries list Level 1 service providers with a QSA-signed ROC or AOC. Smaller merchants and service providers self-assess and do not appear.
