PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Glossary · PCI DSS v4.0.1

TPSP — Third-Party Service Provider

A third-party service provider (TPSP) is any external party that stores, processes or transmits account data on the entity's behalf, or that could otherwise affect the security of account data.

What it means in practice

Requirement 12.8 requires a TPSP inventory, written agreements acknowledging responsibility for account data, due diligence before engagement, annual monitoring of compliance status, and a documented split of responsibilities.
Outsourcing a payment channel moves the work, not the accountability.

Not sure how this affects your assessment?

The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Definitions paraphrased from the PCI DSS v4.0.1 standard and the PCI SSC Glossary of Terms, Abbreviations and Acronyms. Independent summary; not endorsed by PCI SSC.