PCI DSS 12.9.2 (service providers): TPSPs support their customers’ requests for information to meet Requirements 12.8.4 and 12.8.5

PCI DSS v4.0.1 control 12.9.2: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.9.

Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.9

Additional requirement for service providers only: TPSPs support their customers’ requests for information to meet Requirements 12.8.4 and 12.8.5 by providing the following upon customer request:

  • PCI DSS compliance status information (Requirement 12.8.4).
  • Information about which PCI DSS requirements are the responsibility of the TPSP and which are the responsibility of the customer, including any shared responsibilities (Requirement 12.8.5), for any service the TPSP provides that meets a PCI DSS requirement(s) on behalf of customers or that can impact security of customers’ cardholder data or sensitive authentication data.

Summary

Service providers: when a customer asks for your compliance status or the responsibility split, give it to them.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
12.9.2 Additional testing procedure for service provider assessments only: Examine policies and procedures to verify processes are defined for the TPSPs to support customers’ request for information to meet Requirements 12.8.4 and

The provider side of two customer obligations, and it names them: 12.8.4, where a customer monitors its providers' compliance status, and 12.8.5, where a customer records which requirements belong to whom. Neither is achievable if the provider does not answer, which is what this control fixes. The second element is the substantial one: information about which PCI DSS requirements are the responsibility of the TPSP and which are the customer's, including any shared responsibilities, for any service that meets a requirement on the customer's behalf or that can impact security. That is a responsibility matrix per service, and producing one on request without having prepared it is not realistic, so this control is met in advance or not at all.

What to prepare

  • Current compliance status information, such as an attestation of compliance with its date and scope.
  • A responsibility matrix per service, covering shared responsibilities explicitly.
  • The process by which a customer requests these, which the procedure examines.
  • Records of requests answered.

How to implement it

1. Prepare the responsibility matrix before anyone asks. It takes real work per service, and a request is not the moment to start.

2. Be explicit about shared responsibilities. They are named in the requirement and they are where customers most often assume the provider has it covered.

3. Publish rather than handle case by case. A customer trust page or a documented request route is easier to evidence and reduces the load.

4. Keep the attestation current and say what it covers, since a customer checking 12.8.4 needs the scope as much as the status.

Where this commonly fails

  • Compliance status provided and no responsibility matrix, meeting one element.
  • A matrix that assigns every requirement to one party, leaving shared ones unstated.
  • Requests handled ad hoc with no defined process for the procedure to examine.
  • An attestation shared without its scope, so the customer cannot tell what it covers.

This control refers to 12.8.4, 12.8.5.

Others in section 12.9:

Control What it requires
12.9.1 Service providers: TPSPs provide written agreements to customers that include acknowledgments that TPSPs…

12.9.1 · All controls · 12.10.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.