Skip to main content

PCI DSS

Where PCI DSS evidence actually lives: the Visa and Mastercard registries

Why a badge is not evidence, how the Visa Global Registry works, and the Third Party Agent trap that mislabels three quarters of it.

Last updated 17 Sep 2026

PCI DSS has no public certification registry, but the card brands publish lists of validated service providers. Those lists, and an attestation of compliance signed by a QSA, are the only strong evidence.

The Visa Global Registry

The registry lists service providers with the validation type, the assessor and the date the validation runs through. Only rows validated as PCI DSS with a date count; most rows are Third Party Agent or ISO registrations, which CertReports excludes.

The Mastercard SDP list

A PDF of Level 1 service providers with AOC date and assessor, republished irregularly. CertReports keeps each snapshot and diffs them.

What to ask the vendor for

The attestation of compliance for the services you use, the ROC executive summary if they will share it, and the responsibility matrix that says which requirements are yours.