Service Provider
PCIComplianceHubLast updated
A business entity, other than a payment brand, directly involved in processing, storing or transmitting cardholder data on behalf of another entity, or providing services that control or could affect the security of cardholder data. The second half is the half that gets missed: a managed firewall provider, a hosting company, an identity provider or a support vendor with access into the environment is a service provider even though card data never passes through it. Service providers carry their own validation obligations and a set of PCI DSS requirements that apply only to them.
Applies to. Any business, other than a payment brand, that handles account data for another entity or provides services that control or could affect the security of that data: processors, gateways, hosting, managed security, and others with access into the environment.
Example. A managed firewall provider never sees a card number. It configures the network security controls around the CDE, so it is a service provider under the Council's definition, and its customers must manage it as a third-party service provider under Requirement 12.8.
Limits. The 'could affect the security' half is the one that gets missed, and it is where hosting companies, identity providers and support vendors with remote access sit. A merchant can also be a service provider if it hosts or processes for other merchants. Service providers carry the requirements marked 'additional requirement for service providers only', validate at levels set by the brands, and if eligible to self-assess use SAQ D for Service Providers and no other.