Data classification
Cardholder Data
Cardholder data includes Primary Account Numbers (PAN), cardholder names, service codes, and expiration dates. Any vendor who stores, processes, or transmits cardholder data must comply with PCI DSS.
Risk profile
Non-compliance with PCI DSS can result in card brand fines, chargeback liability, and loss of card acceptance privileges. Vendors handling cardholder data should be PCI DSS Level 1 certified (or equivalent) and produce a Report on Compliance (ROC) on request.
Common questions
Does tokenization eliminate PCI DSS scope?
Tokenization can significantly reduce PCI DSS scope but does not eliminate it. The tokenization system itself is in scope, and the vendor providing tokenization must be PCI DSS compliant.
What is a SAQ vs a ROC?
A Self-Assessment Questionnaire (SAQ) is for lower-volume merchants and service providers. A Report on Compliance (ROC) is required for Level 1 merchants and service providers (over 6M transactions/year for merchants; over 300K for service providers). ROCs are performed by a Qualified Security Assessor (QSA).
Which of your vendors handle Cardholder Data?
TrustVendor tracks data class exposure across your entire vendor portfolio and computes residual risk per relationship.
Book a demo