The Vendor Handles It. Which Part?

Using a third-party service provider can change who performs a PCI DSS activity, but it does not remove the need to understand the applicable services, responsibilities, and evidence.

The architecture slide shows a cloud provider logo next to the words “PCI compliant.” The service list includes managed networking, identity, logging, hosting, and support. The AOC is current. Nobody has mapped which controls the provider performs, which controls remain with the customer, or where shared implementation begins.

PCI SSC guidance is direct: customers must manage and oversee TPSP relationships, identify which requirements apply to each party, and monitor provider compliance status. When a provider performs a requirement on the customer’s behalf, the provider’s evidence for that service affects the customer’s assessment story.

The risk is not outsourcing. The risk is outsourcing the activity while retaining an undocumented gap between service scope, control responsibility, configuration responsibility, and evidence availability.

  1. Which exact service is used, and is that service covered by the provider’s assessment?
  2. Which PCI DSS activities are provider, customer, or shared responsibilities?
  3. Who owns every customer-side configuration and operating task?
  4. What evidence will be available, when, and under which agreement?