Payment technology and security
Who is responsible for PCI compliance?
Direct answer
Every entity that stores, processes, transmits, or can affect the security of payment account data has responsibilities for its own environment. A merchant can outsource payment functions, but it cannot outsource accountability for selecting and monitoring providers, configuring systems safely, training staff, controlling access, and completing required validation. Exact obligations should be confirmed with the merchant’s acquirer.
- Author
- AMP Payment Systems
- Review status
- Primary sources checked; no named AMP subject-matter reviewer is claimed.
- Published
- Modified
Key facts
- Responsibility is shared, not transferred wholesale.
- Service providers must be managed and their scope understood.
- The acquirer communicates merchant validation requirements.
Merchant responsibilities
Merchants should maintain data-flow and provider inventories, secure their networks and devices, manage users, patch systems, respond to incidents, and verify that outsourced controls cover the expected functions.
Provider responsibilities
Gateways, processors, hosting companies, managed service providers, and software vendors are responsible for applicable controls in their environments, but service boundaries must be documented.
When the answer changes
- Responsibility changes with integrations and data flows.
- Franchise, marketplace, and managed-POS models need explicit allocation.
Common mistakes
- Assuming a compliant processor makes the merchant compliant.
- Failing to remove former employee access.
What to verify
- Create a responsibility matrix.
- Review provider attestations, contracts, shared controls, and validation instructions.
Primary sources
- PCI SSC Document LibraryPCI Security Standards Council
- PCI SSC Frequently Asked QuestionsPCI Security Standards Council
Apply the answer to your business
AMP can help organize your payment, POS, or statement questions. Any recommendation, availability, pricing, or approval depends on the final written configuration and provider terms.
Contact AMP