The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard administered by the
PCI Security Standards Council
, which was founded by American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc.
PCI DSS applies to entities that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD), including merchants, processors, acquirers, issuers, and service providers. The PCI DSS is mandated by the card brands and administered by the Payment Card Industry Security Standards Council.
The PCI DSS Attestation of Compliance (AOC) and Responsibility Summary is available to customers through AWS Artifact, a self-service portal for on-demand access to AWS compliance reports. Sign in to
AWS Artifact in the AWS Management Console
, or learn more at
Getting Started with AWS Artifact
.
Yes, Amazon Web Services (AWS) is certified as a PCI DSS Level 1 Service Provider, the highest level of assessment available. The compliance assessment was conducted by Coalfire Systems Inc., an independent Qualified Security Assessor (QSA). The PCI DSS Attestation of Compliance (AOC) and Responsibility Summary are available to customers through AWS Artifact, a self-service portal for on-demand access to AWS compliance reports. Sign in to
AWS Artifact in the AWS Management Console
, or learn more at
Getting Started with AWS Artifact
.
Which AWS services are PCI DSS compliant?
For the list of AWS services that are PCI DSS compliant, see the PCI tab on the
AWS Services in Scope by Compliance Program
webpage. For more information about using these services,
contact us
.
What does this mean to me as a PCI DSS merchant or service provider?
As a customer who uses AWS services to store, process, or transmit cardholder data, you can rely on AWS technology infrastructure as you manage your own PCI DSS compliance certification.
AWS does not directly store, transmit, or process any customer cardholder data (CHD). However, you may create your own cardholder data environment (CDE) that can store, transmit, or process cardholder data using AWS services.
What does this mean to me as a non-PCI DSS merchant customer?
Even if you are a non-PCI DSS customer, our PCI DSS compliance demonstrates our commitment to information security at every level. Because the PCI DSS standard is validated by an external independent third party, it confirms that our security management program is comprehensive and follows leading industry practices.
As an AWS customer, can I rely on the AWS Attestation of Compliance (AOC) or will additional testing be required for to be fully compliant?
Customers must manage their own PCI DSS compliance certification, and additional testing will be required to verify that your environment satisfies all PCS DSS requirements. However, for the portion of the PCI cardholder data environment (CDE) that is deployed in AWS, your Qualified Security Assessor (QSA) can rely on AWS Attestation of Compliance (AOC) without further testing.
How can I learn which PCI DSS controls I am responsible for?
For detailed information please see "AWS PCI DSS Responsibility Summary" from the AWS PCI DSS Compliance Package, available to customers through AWS Artifact, a self-service portal for on-demand access to AWS compliance reports. Sign in to
AWS Artifact in the AWS Management Console
, or learn more at
Getting Started with AWS Artifact
. Customers can also request audit and compliance advisory services from the
AWS Security Assurance Services
team.
How can I obtain the AWS PCI Compliance Package?
The AWS PCI Compliance Package is available to customers through AWS Artifact, a self-service portal for on-demand access to AWS compliance reports. Sign in to
AWS Artifact
in the AWS Management Console
, or learn more at
Getting Started with AWS Artifact
.
What does the AWS PCI DSS Compliance Package contain?
The AWS PCI Compliance Package includes:
AWS PCI DSS 3.2.1 Attestation of Compliance (AOC)
AWS PCI DSS 3.2.1 Responsibility Summary
No. The AWS environment is a virtualized, multi-tenant environment. AWS has effectively implemented security management processes, PCI DSS requirements, and other compensating controls that effectively and securely segregate each customer into its own protected environment. This secure architecture has been validated by an independent QSA and was found to be in compliance with all applicable requirements of PCI DSS.
PCI Security Standards Council has published
PCI DSS Cloud Computing Guidelines
for customers, service providers, and assessors of cloud computing services. It also describes service models and how compliance roles and responsibilities are shared between providers and customers.
Do QSAs for Level 1 merchants require a physical walkthrough of AWS data centers?
No. The AWS Attestation of Compliance (AOC) demonstrates an extensive assessment of physical security controls of AWS data centers. It is not necessary for a merchant’s QSA to verify the security of the AWS data centers.
Does AWS support forensic investigations?
AWS is not considered a "Shared Hosting Provider" under PCI-DSS. As such, DSS requirement A1.4 is not applicable. Under our
Shared Responsibility Model
, we enable our customers to perform digital forensics investigations in their own AWS environments without requiring additional assistance from AWS. This enablement is provided through the use of both AWS services and third-party solutions available via AWS Marketplace. For more information, see the following resources:
Simplify Security Incident Response and Digital Forensics on AWS
AWS Security Incident Response Guide
Is there a special PCI DSS compliant environment I need to specify when connecting servers or uploading objects to store?
As long as you are using AWS services that are PCI DSS compliant, the entire infrastructure that supports in-scope services is compliant and there is no separate environment or special API to use. Any server or data object deployed in or using these services is in a PCI DSS compliant environment, globally. For the list of AWS services that are PCI DSS compliant, see the PCI tab on the
AWS Services in Scope by Compliance Program
webpage.
Is AWS compliance applicable internationally?
Yes. Please refer to the latest PCI DSS AOC in AWS Artifact to get the full list of locations that are compliant.
Is the PCI DSS standard public?
Yes. You can download the PCI DSS standard from the
PCI Security Standards Council Document Library
.
Yes, numerous AWS customers have successfully deployed and certified part or all of their cardholder environments on AWS. AWS does not disclose the customers who have achieved PCI DSS certification, but does regularly work with customers and their PCI DSS assessors in planning for, deploying, certifying, and performing quarterly scanning of a cardholder environment on AWS.
How do companies comply with PCI DSS?
There are two primary approaches that companies take to validate their PCI DSS compliance on an annual basis. The first approach is to have an external Qualified Security Assessor (QSA) assess your applicable environment and then create a Report on Compliance (ROC) and Attestation of Compliance (AOC); this approach is most common for entities that handle large volumes of transactions. The second approach is to perform a Self-Assessment Questionnaire (SAQ); this approach is most common for entities that handle smaller volumes of transaction.
It is important to note that the payment brands and acquirers are responsible for enforcing compliance, not the PCI council.
What are the requirements for PCI DSS compliance?
Below is a high-level overview of the PCI DSS requirements.
Build and Maintain a Secure Network and Systems
1.
Install and Maintain Network Security Controls.
2.
Apply Secure Configurations to All System Components.
Protect Account Data
3.
Protect Stored Account Data.
4.
Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks.
Maintain a Vulnerability Management Program
5.
Protect All Systems and Networks from Malicious Software.
6.
Develop and Maintain Secure Systems and Software.
Implement Strong Access Control Measures
7.
Restrict Access to System Components and Cardholder Data by Business Need to Know.
8.
Identify Users and Authenticate Access to System Components.
9.
Restrict Physical Access to Cardholder Data.
Regularly Monitor and Test Networks
10.
Log and Monitor All Access to System Components and Cardholder Data.
11.
Test Security of Systems and Networks Regularly
Maintain an Information Security Policy
12.
Support Information Security with Organizational Policies and Programs.
What is Artificial Intelligence (AI)?
What is Generative AI?
What is Machine Learning (ML)?
AWS Cloud Security
What's New
Blogs
Press Releases
Resources for AWS
Getting Started
Training and Certification
AWS Solutions Library
Architecture Center
Product and Technical FAQs
Analyst Reports
AWS Partners
Developers on AWS
Developer Center
SDKs & Tools
.NET on AWS
Python on AWS
Java on AWS
PHP on AWS
JavaScript on AWS
Contact Us
Get Expert Help
File a Support Ticket
AWS re:Post
Knowledge Center
AWS Support Overview
Legal
AWS Careers
AWS support for Internet Explorer ends on 07/31/2022. Supported browsers are Chrome, Firefox, Edge, and Safari.
Learn more »
Got it