attestation
PCI DSS evidence across 1,361 vendors
PCI DSS evidence that a buyer can verify is a registry listing or an attestation of compliance. CertReports mirrors the Visa Global Registry of Service Providers, counting only rows validated as PCI DSS with a validation date, and records the assessor and the date the validation runs through.
- Verified rows
- 1,361
- Vendor-stated
- 12
- Expired
- 158
- Last verified
- 17 Sep 2026
Marketing
Amazon
Cloud and hosting
Confluent
Data platforms
DocuSign
E-signature
Oracle
Data platforms
CVENT
Project management
Blackbaud
Nonprofit and fundraising
CGI
Business services
Chargebee
Finance and accounting
Expedient
Cloud and hosting
Forter
Payments
Spreedly
Payments
Sierra Technologies
AI assistants
Stripe
Payments
Economic infrastructure for the internet.
Twilio
Communications and CPaaS
Accenture
Business services
Ramp
Finance and accounting
Nuance
AI infrastructure
Mindbody
Scheduling
Recurly
Payments
BigCommerce
E-commerce
Vesta
Payments
Remitly
remitly.com
Travelport
travelport.com
Registry traps
Most Visa registry rows are Third Party Agent or ISO registrations, not PCI DSS validations. Those are excluded. The Mastercard SDP compliant service provider list is the second registry-grade source.
Level 1 service providers
Registries list Level 1 service providers with a QSA-signed ROC or AOC. Smaller merchants and service providers self-assess and do not appear.
