Entity

PCIComplianceHubLast updated

The Council's word for whichever organisation is being assessed: a merchant, a service provider, an issuer or anyone else to whom PCI DSS applies. The standard is written to 'the entity' so that one text serves all of them.

Applies to. Whoever is completing an SAQ or being assessed for a ROC. Where a requirement applies only to service providers, the standard says so in the requirement.
Example. A hosting company is the entity in its own assessment and a third-party service provider in its customers' assessments. The same company, two roles, two sets of obligations.
Limits. The entity defines and confirms its own scope (12.5.2), which is the decision every other control rests on. The standard also uses 'entity-defined' for frequencies and thresholds the entity sets through a targeted risk analysis; those are the entity's to justify, and an assessor will ask for the analysis rather than the number.
In PCI DSS v4.0.1. 12.5.2