Responsibility Matrix
PCIComplianceHubLast updated
The written allocation of each applicable PCI DSS requirement between an entity and its third-party service provider, recording for every requirement whether the provider, the customer, or both are responsible. Requirement 12.8.5 obliges the entity to maintain it, and the provider Attestation of Compliance evidences the provider side. The common failure is assuming a compliant provider covers a requirement end to end: most shared requirements leave a configuration or monitoring obligation with the customer, and a requirement nobody has been assigned is usually a requirement nobody is performing.
Applies to. Every entity that shares any PCI DSS requirement with a third-party service provider, which is nearly every merchant: hosting, payment processing, managed security and embedded payment forms all split requirements.
Example. For 6.4.3 on an embedded provider form: the provider authorises and inventories the scripts inside its form document; the merchant does the same for the scripts on the page around it; and the merchant records that split, with the provider's Attestation of Compliance as evidence for the provider's half.
Limits. 12.8.5 asks for information about which requirements each provider manages, which the entity manages and which are shared. A provider's AOC shows what the provider was assessed for, not what it does for this customer's configuration. Under 12.9.1 a provider must acknowledge in writing its responsibility for the security of account data it handles, and under 12.9.2 support the customer's requests for this information, but the 12.8 obligations sit with the entity. A requirement nobody has been assigned is usually a requirement nobody is performing.
Related. Third-Party Service Provider, Service Provider, Attestation of Compliance (AOC), Multi-Tenant Service Provider
Sources. PCI DSS v4.0.1 (June 2024)