Cardholder Data Environment (CDE)

PCIComplianceHubLast updated

The people, processes and system components that store, process or transmit cardholder data or sensitive authentication data. Abbreviated CDE. It is narrower than the assessment scope, and treating the two as one term is a common error: systems connected to the CDE, or able to affect its security, are in scope for PCI DSS and must meet the applicable requirements without being part of the CDE itself. Segmentation is what keeps everything else outside both.

Applies to. The system components, people and processes that store, process or transmit CHD or SAD, plus any system component with unrestricted connectivity to them. Everything in the CDE is in scope; the reverse is not true.
Example. A payment application server and its database are in the CDE. A monitoring server that can reach both without restriction is in the CDE under the Council's second bullet. A directory server that authenticates administrators to the CDE is in scope as security-impacting, but not part of the CDE.
Limits. The Council's definition has two bullets, and the second, unrestricted connectivity, pulls in systems that never touch account data. Scope is wider still: connected-to and security-impacting systems must meet the applicable requirements without being in the CDE. The entity confirms its scope at least every 12 months and after significant change (12.5.2), every six months for service providers (12.5.2.1). Segmentation keeps the rest out, and only if it is tested (11.4.5).
In PCI DSS v4.0.1. 12.5.2, 12.5.2.1, 11.4.5