For VoIP between a cardholder and an entity, the entity's systems are in scope but securing the transmission outside the entity's infrastructure is not, because the entity cannot control how the cardholder places calls.

Checked 2026-09-30

Vendor
PCI SSC
Product
PCI DSS
Subsystem
VoIP scoping
Deployment
any
Region
not restricted
Release range
current as of 2026-09-30
Checked
2026-09-30

Sources

Cite this note

APA

WarmTransfer. (2026, September 30). PCI DSS for contact centers: source note pci-dss-contact-center-voip-cardholder-leg. WarmTransfer. https://warmtransfer.net/knowledge/claims/pci-dss-contact-center-voip-cardholder-leg

BibTeX

@misc{warmtransfer-claim-pci-dss-contact-center-voip-cardholder-leg,
  title  = {PCI DSS for contact centers: source note pci-dss-contact-center-voip-cardholder-leg},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/pci-dss-contact-center-voip-cardholder-leg},
  note   = {Source note pci-dss-contact-center-voip-cardholder-leg, checked 2026-09-30}
}

Read in context