Skip to main content

Industry standard · Worldwide, by card brand rules

What PCI DSS asks of your vendors

Merchants and service providers that store, process or transmit cardholder data, or can affect its security, under card brand and acquirer rules. Version 4.0.1 is current; the requirements that were future-dated in 4.0 became mandatory on 31 March 2025. PCI DSS v4.0.1, Requirement 12.8

Check my vendors

2 requirements that reach your vendors

Each provision, the evidence that usually supports it, and how many vendors in the index publish that evidence. Reviewed 21 Sep 2026.

Requirement 12.8.3

Due diligence before engaging a provider

An established process is implemented for engaging third-party service providers, including proper due diligence before engagement.

  • Independent security assurance

    758 vendors in the index

    A current SOC 2 report or ISO/IEC 27001 certificate is the usual evidence that a supplier operates appropriate security measures.

  • Current PCI DSS validation

    1,501 vendors in the index

    A current registry listing or attestation of compliance (AOC) shows the provider’s PCI DSS status for the year.

Requirement 12.8.4

Monitor PCI DSS status at least every 12 months

A program is implemented to monitor the PCI DSS compliance status of third-party service providers at least once every 12 months.

  • Current PCI DSS validation

    1,501 vendors in the index

    A current registry listing or attestation of compliance (AOC) shows the provider’s PCI DSS status for the year.

Vendors publishing the most PCI DSS evidence

Among the most-searched vendors in the index, ranked by how many of the requirements above their public evidence reaches. Open one to see each item with its date and source.

Questions buyers ask

What does PCI DSS require from vendors?

Due diligence before engaging a provider (Requirement 12.8.3); Monitor PCI DSS status at least every 12 months (Requirement 12.8.4). Each is listed below with the evidence that may support it.

Who does PCI DSS apply to?

Merchants and service providers that store, process or transmit cardholder data, or can affect its security, under card brand and acquirer rules. Version 4.0.1 is current; the requirements that were future-dated in 4.0 became mandatory on 31 March 2025.

Is a SOC 2 report enough for PCI DSS?

A SOC 2 report or ISO 27001 certificate may support the security parts of PCI DSS, but monitor pci dss status at least every 12 months need other evidence. Confirm sufficiency with your counsel or auditor.

Other regulations

All articles

This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.