Third-Party Service Provider

Also: TPSP

PCIComplianceHubLast updated

Any third party acting as a service provider on behalf of an entity: a processor, gateway, hosting company, managed security provider, or any other provider that handles account data for the entity or could affect its security. The Council uses TPSP for the relationship and service provider for the business; they describe the same companies from the customer's side and from their own.

Applies to. Every entity that shares account data with a third party or relies on one that could affect its security.
Example. A merchant lists its processor, its e-commerce platform host and its managed SOC provider. For each it keeps the written agreement, the due diligence from engagement, the annual check of PCI DSS status, and a record of which requirements each one manages.
Limits. Requirement 12.8 places five duties on the entity: keep a list (12.8.1), hold written agreements in which the provider acknowledges its responsibility (12.8.2), do due diligence before engaging (12.8.3), monitor compliance status at least every 12 months (12.8.4), and record who manages which requirement (12.8.5). A provider's AOC covers the services it was assessed for on the date it was signed; a service not named on it is not covered by it.
In PCI DSS v4.0.1. 12.8.1, 12.8.2, 12.8.3, 12.8.4, 12.8.5