PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

PCI DSS Requirement 12.8 — Managing third-party service providers

Requirement 12.8 governs how an entity manages third-party service providers (TPSPs) that can affect the security of cardholder data. It covers the inventory, written agreements, due diligence before engagement, annual monitoring of compliance status, and a documented split of PCI DSS responsibilities.Timing: Applies in PCI DSS v4.0.1. 12.8.2 responsibility matrices and 12.8.5 responsibility documentation are assessed at every annual assessment.

Who it applies to

Any entity that shares account data with, or whose account data security depends on, a third party
Every SAQ type that involves an outsourced payment channel

What Requirement 12.8 asks for

Paraphrased from PCI DSS v4.0.1. Read the standard itself for the authoritative wording and testing procedures.

Maintain a list of all TPSPs with which account data is shared or that could affect the security of account data.
Maintain written agreements in which TPSPs acknowledge responsibility for the security of account data they possess, store, process or transmit.
Follow an established due diligence process before engaging a TPSP.
Monitor each TPSP's PCI DSS compliance status at least once every 12 months.
Maintain information about which PCI DSS requirements are managed by each TPSP, which by the entity, and which are shared.

Evidence an assessor expects

TPSP register with service description, data shared and compliance status
Signed agreements containing the account-data security acknowledgement
Current AoCs, or equivalent evidence, collected within the last 12 months
A responsibility matrix covering every PCI DSS requirement for each provider

Common mistakes

Collecting an AoC once and never refreshing it — the review is annual.
Omitting providers that never touch card data but can affect its security (hosting, managed DNS, CDN, script delivery).
Having no responsibility matrix, then discovering that neither party covered a requirement.

Not sure whether Requirement 12.8 is in your scope?

Which requirements you must answer depends on the SAQ that applies to your environment. The free SAQ selector walks the official PCI SSC decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Paraphrased from PCI DSS v4.0.1 (PCI Security Standards Council). Independent summary; not endorsed by PCI SSC. Refer to the PCI SSC Document Library for the authoritative standard.