PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Glossary · PCI DSS v4.0.1

CDE — Cardholder Data Environment

The cardholder data environment (CDE) is the people, processes and technologies that store, process or transmit cardholder data or sensitive authentication data, plus any system components that connect to or could affect the security of those systems.

What it means in practice

Scoping starts by identifying every flow of account data. Connected-to and security-impacting systems are in scope even when no card data touches them.
Network segmentation is not required by PCI DSS, but it is the usual way to keep the CDE small; where segmentation is claimed it must be validated by testing.
An annual scope confirmation is required, and service providers must confirm scope every six months.

Not sure how this affects your assessment?

The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Definitions paraphrased from the PCI DSS v4.0.1 standard and the PCI SSC Glossary of Terms, Abbreviations and Acronyms. Independent summary; not endorsed by PCI SSC.