PCI DSS for contact centers
Verified 2026-09-30 · 60 sources · tier 1–2
Storing card validation codes (CAV2, CVC2, CVV2, or CID) in any form of digital audio recording after authorization violates PCI DSS Requirement 3.3.1 24. This prohibition applies even when the recording is encrypted 29.
Standard Lifecycle and Scoping
PCI SSC retired PCI DSS v3.2.1 on 31 March 2024 46. PCI SSC published PCI DSS v4.0.1 in June 2024, with the announcement post dated 11 June 2024 50. PCI DSS v4.0.1 is a limited revision that adds and deletes no requirements, functioning to correct and clarify existing text 49. PCI SSC retired PCI DSS v4.0 on 31 December 2024, leaving v4.0.1 as the only active version 47. Across PCI DSS v4.x, 51 of the 64 new requirements introduced in PCI DSS v4.0 were future-dated and became effective on 31 March 2025, a date unchanged by v4.0.1 14. PCI SSC held a Request for Comments on PCI DSS v4.0.1 from 3 June to 20 July 2026 to begin work on the next iteration of the standard 34. As of the June 2026 RFC announcement, PCI DSS v4.0.1 remained the published standard, and the announcement gave no name or date for a successor version 48.
VoIP traffic carrying payment card account data is in scope for applicable PCI DSS controls wherever it is stored, processed, or transmitted on an entity's own network 54. Inbound VoIP traffic from an external source is not within the entity's PCI DSS scope until it reaches the entity's infrastructure 53. For VoIP transmissions between a cardholder and an entity, the entity's systems are in scope, but securing the transmission outside the entity's infrastructure is not, because the entity cannot control how cardholders place calls 52. Similarly, for business-to-business VoIP carrying card data across multiple carriers, the traffic is in the entity's scope only while it resides on the entity's infrastructure 51.
Call Recording and SAD Controls
PCI SSC FAQ 1210 states that where sensitive authentication data (SAD) is collected during a call, entities should prevent it from being recorded, enabling audio suppression or redaction technology where it exists 30. If SAD cannot be kept out of a call recording, FAQ 1210 requires it to be securely deleted immediately after the transaction is authorized 28. Where secure deletion from recordings is not feasible, FAQ 1210 specifies minimum compensating controls: an annual risk assessment and one after significant change, protection of SAD under applicable PCI DSS requirements, controls preventing access to SAD and querying of recordings, and documented justification and evidence 27. These compensating controls are validated during the annual PCI DSS assessment and shared with acquirers or payment brands as needed 26. FAQ 1210 also states that PCI DSS does not override local or regional laws regarding audio recording retention 25.
PCI SSC guidance recommends implementing a policy that keeps materials and devices capable of recording card data out of the telephone payment environment 13. PCI SSC guidance also states that technology minimizing personnel exposure to account data should be considered for telephone payments 23. For remote personnel taking payments, PCI SSC guidance calls for multi-factor authentication (MFA) to access telephone systems or payment processing platforms 32. PCI SSC states that entities should assess the additional risk of processing account data at unsecured home locations and apply matching controls, noting that remote-working guidance does not replace PCI DSS requirements 31.
Third-Party Service Provider Management
A third-party service provider (TPSP) with a PCI DSS Attestation of Compliance (AOC) is expected to provide it to customers upon request, and customers may also request relevant sections of its Report on Compliance (ROC) or SAQ D for Service Providers 35. The TPSP's documentation must allow the customer to verify that the scope of the assessment covered the specific services used 37. Under PCI DSS Requirements 12.9.1 and 12.9.2, a TPSP documents responsibility division—typically in a responsibility matrix—clarifying which requirements belong to the TPSP and which remain with the customer 36. If a TPSP lacks its own PCI DSS assessment, it must provide specific evidence for applicable requirements so the customer or its assessor can confirm they are met 38.
Platform Implementations
Vendors document platform-specific configurations, limits, and customer obligations for payment processing: 4125816
| Platform | Features and controls | Documented constraints |
|---|---|---|
| Twilio | PCI Mode is enabled in the Twilio Console under Voice general settings 41. Supports Conversation Relay when configured with PCI-compliant TTS and transcription providers 40. Twilio provides a Responsibility Matrix for customer obligations 44. | PCI Mode is irreversible once enabled on an account 42. Native and Marketplace transcriptions are unavailable in PCI Mode 45. Conversation Intelligence (classic) is not PCI compliant and cannot be used in PCI workflows 39. PCI voice recordings are retained for 1 year by default and then deleted permanently 43. |
| Amazon Connect | Encrypted DTMF or Amazon Lex for speech input 2. DTMF can be encrypted in the Store customer input block via a customer X.509 certificate (.pem) with up to 2 active rotation keys 12; customer decrypts using AWS Encryption SDK 1. Sample flow puts agents on hold during input 3. MFA is recommended for card access 4. Screen recording is PCI DSS compliant under shared responsibility 10. | Captured card data must be scrubbed from recordings and obscured in logs and transcripts 11. Screen recording continues while a customer is on hold 9. Rule-based redaction masks whole windows, cannot mask single form fields, does not redact audio, generates a masked copy, and retains original unredacted screen recordings in S3 687. Screen recordings carry unredacted audio by default 5. |
| Webex Contact Center | Admins can enable agent pause of recordings on Agent Desktop 58. Admins can configure an automatic resume duration in seconds 55. Sensitive data masking is available on Agent Desktop 5756. Cisco's November 2021 Webex Contact Center 1.0 data sheet stated the platform is PCI DSS Level 1 certified through a third-party AOC audit reviewed annually 60. | Pause of recording is disabled by default 58. Metadata (duration, dialed number, routing) continues to log during pauses 59. UI masking does not encrypt backend data; network and console logs still contain the data 57. UI masking does not apply to Supervisor Desktop 56. |
| Genesys Cloud | Service Provider Level 1 compliant with PCI DSS version 4.0 18. Provides Secure Pause and Secure Call Flows to prevent capturing entry 19. | Customers must enable the PCI setting in Manage Organization and execute Secure Pause or Secure Flows prior to handling cardholder data 16. Genesys may share its AOC only under non-disclosure agreement 15. |
See also
See also Call recording consent laws. See also Caller authentication and fraud prevention in contact centers. See also Webex contact center. See also CCaaS platforms compared. See also GDPR for contact centers and call recording. See also Speech and interaction analytics. See also TLS certificates and secure SIP failures. See also CDR privacy redaction and evidence-safe reporting. See also Recording consent and AI processing privacy. See also Identity SSO and directory provisioning for UC. See also Certificate lifecycle management for voice. See also Toll fraud prevention and voice security. See also Contact centre AI data residency retention and training boundaries. See also Webex Contact Center data locality by country. See also The Cisco Trust Portal as a monitorable document source. See also Webex suite data residency and the GEO model. See also Webex Contact Center recording and contact data retention. See also Cisco offer disclosures as an evidence class. See also Webex service level agreements and objectives. See also The Cisco AI transparency note set beyond the contact centre.
Applicability
Applies to: PCI SSC PCI DSS, PCI SSC Information Supplement: Protecting Telephone-Based Payment Card Data, Twilio Programmable Voice, Twilio Conversation Intelligence (classic), Twilio Conversation Relay, AWS Amazon Connect (Connect Customer), AWS Amazon Connect (Connect Customer) screen recording, Cisco Webex Contact Center, Cisco Webex Contact Center 1.0, and Genesys Cloud. Deployments: multi-tenant and any. Sources checked 2026-09-30. The claims cite PCI DSS releases v3.2.1, v4.0, and v4.0.1 464750. Cisco's November 2021 Webex Contact Center 1.0 data sheet stated the platform is PCI DSS Level 1 certified through a third-party AOC audit reviewed annually 60. Genesys Cloud compliance claims apply to Service Provider Level 1 under PCI DSS version 4.0 18.
What remains uncertain
Card data in AI transcription, summaries, speech analytics, and redaction accuracy across CCaaS vendors is not covered by the sources below. Current Webex Contact Center PCI DSS attestation scope and version, beyond the 2021 1.0 data sheet, is not covered by the sources below. IVR self-service and agent-assisted payment descoping—such as Twilio Pay, Webex Contact Center flows, or Genesys secure flows—and what stays in scope are not covered by the sources below. PCI DSS features and recording pause capabilities for telephony and contact center platforms not named in the claims are not covered by the sources below. SAQ selection for telephone payments (such as SAQ C-VT versus SAQ D) with third-party payment capture is not covered by the sources below. The name, timeline, and telephone-relevant changes of any successor to PCI DSS v4.0.1 are not covered by the sources below. The PCI SSC Third-Party Security Assurance supplement Appendix B sample responsibility matrix is not covered by the sources below. Storage of sensitive authentication data before authorization for callbacks and deferred payments is not covered by the sources below.
See also
Related to
- CCaaS platforms comparedstub — The vendor PCI features documented here (Twilio PCI Mode; Amazon Connect encrypted input; Genesys Secure Pause) feed platform comparisons
- Call recording consent lawsstub — PCI SSC FAQ 1210 says it does not override local or regional audio retention law; consent and retention law is a separate topic
- Caller authentication and fraud prevention in contact centers — Adjacent security-identity topic; card data used for identity verification falls under the same recording rules
- Webex contact center — Webex Contact Center pause and resume recording and UI-level sensitive data masking are covered here only as PCI controls
Referenced by
- Call recording consent lawsstub — Recorded contact-center calls may capture payment card data; consent law and PCI DSS both shape pause-and-resume and retention design
- Caller authentication and fraud prevention in contact centers — IVR OTP and payment-card handling controls overlap with caller verification flows
- GDPR for contact centers and call recording — Parallel compliance regime for recordings containing card data
- HIPAA for contact centers and UC — Sibling regulatory-compliance topic for contact centers; both cover recordings and transcripts holding regulated data. No claims in this packet are tagged to it.
- Speech and interaction analyticsstub — Redaction limits and PCI secure-flow restrictions on audio streaming
Sources
- 1Encrypted Stored customer input from Amazon Connect is decrypted by the customer with the AWS Encryption SDK and its private key; AWS provides a Java sample.Encrypt sensitive customer input in Connect Customer · 'How to decrypt data encrypted by Connect Customer' section · Checked 2026-09-30
- 2AWS recommends collecting payment card information in Amazon Connect with encrypted DTMF, or with Amazon Lex for speech input.Best practices for PCI compliance in Connect Customer · bullet 2 · Checked 2026-09-30
- 3Amazon Connect's sample agent-assisted secure-input flow conferences agent and customer, puts the agent on hold while the customer keys card data into an encrypting Store customer input block, then reconnects them; AWS recommends encryption over this sample in production.Sample secure customer data entry input in a call with a contact center agent · introduction and steps 2-6 · Checked 2026-09-30
- 4AWS recommends MFA for any access to card data in Amazon Connect because the service is a public endpoint.Best practices for PCI compliance in Connect Customer · bullet 5 · Checked 2026-09-30
- 5By default an Amazon Connect screen recording carries unredacted call audio.Frequently asked questions about Connect Customer screen recording capabilities · Configuration > 'Is there a way to choose which audio (redacted or unredacted) gets used for screen recording?' · Checked 2026-09-30
- 6Amazon Connect rule-based redaction masks whole browser or application windows that match URL or window-title rules and cannot redact a single form field.Frequently asked questions about Connect Customer screen recording capabilities · Rule-based redaction FAQ > 'Can I redact only part of a page, such as a single form field?' · Checked 2026-09-30
- 7Amazon Connect rule-based redaction never pauses screen capture; it masks matching windows only in a separate redacted copy after the contact, and the unredacted recording is kept in the same S3 bucket.Frequently asked questions about Connect Customer screen recording capabilities · Rule-based redaction FAQ > 'Does rule-based redaction pause or stop the recording' and 'Does rule-based redaction affect storage costs?' · Checked 2026-09-30
- 8Amazon Connect rule-based redaction applies only to screen video and does not redact audio; audio redaction needs conversational analytics sensitive data redaction.Frequently asked questions about Connect Customer screen recording capabilities · Rule-based redaction FAQ > 'Does rule-based redaction apply to call recordings?' · Checked 2026-09-30
- 9Amazon Connect screen recording keeps recording when the agent puts the customer on hold.Frequently asked questions about Connect Customer screen recording capabilities · Screen recording FAQ > 'Does screen recording STOP when an agent places a customer on hold?' · Checked 2026-09-30
- 11AWS says that if card data is captured in Amazon Connect call recordings it must be scrubbed from the recording and obscured in any logs or transcriptions.Best practices for PCI compliance in Connect Customer · bullet 3 · Checked 2026-09-30
- 12Amazon Connect can encrypt DTMF captured by the Store customer input block with a customer-supplied public key and X.509 certificate in .pem format, with up to two encryption keys active at a time for rotation.Encrypt sensitive customer input in Connect Customer · introduction and note · Checked 2026-09-30
- 13PCI SSC recommends a policy that keeps materials and devices that could record card data out of the telephone payment environment.Industry Guidance on Accepting Telephone Payments Securely · 'Process' best practice · Checked 2026-09-30
- 1451 of the 64 new requirements introduced in PCI DSS v4.0 were future-dated and became effective on 31 March 2025; v4.0.1 did not change that date.Now is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x · opening paragraphs · Checked 2026-09-30
- 15Genesys says it may share the Genesys Cloud PCI DSS AOC with interested parties after they sign a non-disclosure agreement.PCI DSS compliance - Genesys Cloud Resource Center · Attestation of Compliance paragraph · Checked 2026-09-30
- 16Genesys requires customers to enable the PCI setting on the Manage Organization page and to use Secure Pause or a Secure Flow before handling cardholder data.PCI DSS compliance - Genesys Cloud Resource Center · customer responsibilities section · Checked 2026-09-30
- 17When the PCI DSS compliance setting is enabled in Genesys Cloud, DTMF logging and media capture are disabled.PCI DSS compliance - Genesys Cloud Resource Center · PCI setting effects section · Checked 2026-09-30
- 18Genesys's PCI DSS page states that Genesys Cloud is Service Provider Level 1 compliant with PCI DSS version 4.0.PCI DSS compliance - Genesys Cloud Resource Center · opening compliance statement · Checked 2026-09-30
- 19Genesys Cloud provides Secure Pause, which temporarily stops recording during entry of sensitive data, and Secure Call Flows, to which agents transfer calls so the system and agent cannot capture the caller's entry.PCI DSS compliance - Genesys Cloud Resource Center · Secure Pause and Secure Call Flows sections · Checked 2026-09-30
- 20Because PCI SSC retired PCI DSS v4.0 on 31 December 2024, the v4.0 label on Genesys's compliance page probably lags the current attestation, and the AOC itself should be checked for the version and date assessed.inferredPCI DSS compliance - Genesys Cloud Resource Center · opening compliance statement, read against pcissc-blog-pci-dss-v4-0-1-published · Checked 2026-09-30
- 21Agent-initiated recording pause (Webex Contact Center pause, Genesys Secure Pause) depends on the agent acting in time, so a missed pause leaves SAD in the recording and triggers the FAQ 1210 duty to delete it securely after authorization.inferredFAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data? · FAQ 1210 answer paragraph 2, read with the cisco-help-3srgv1-wxcc-security call recordings section and the genesys-help-pci-dss-compliance Secure Pause section · Checked 2026-09-30
- 22A CCaaS vendor's PCI DSS attestation does not by itself make the customer's contact center compliant; the customer keeps the requirements that the vendor's responsibility matrix assigns to it, including how recording, pause and screen capture are configured.inferredFAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance? · FAQ 1576 responsibility matrix paragraph, read with the aws-connect-screen-recording-faq PCI answer and twilio-docs-voice-pci-workflows responsibility paragraph · Checked 2026-09-30
- 23PCI SSC guidance says technology that minimizes personnel exposure to account data should be considered for telephone payments.Industry Guidance on Accepting Telephone Payments Securely · 'Technology' best practice · Checked 2026-09-30
- 24Storing card validation codes (CAV2, CVC2, CVV2 or CID) in any form of digital audio recording after authorization violates PCI DSS Requirement 3.3.1.FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data? · FAQ 1210, answer paragraph 1 · Checked 2026-09-30
- 25FAQ 1210 states that PCI DSS does not override local or regional laws on retaining audio recordings.FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data? · FAQ 1210, final paragraph · Checked 2026-09-30
- 26Compensating controls for SAD retained in call recordings are validated during the annual PCI DSS assessment and shared with acquirers or payment brands as needed.FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data? · FAQ 1210, paragraph after the compensating-control list · Checked 2026-09-30
- 27Where secure deletion of SAD from recordings is not feasible, FAQ 1210 sets minimum compensating controls: a risk assessment annually and after significant change, protection of the SAD under applicable PCI DSS requirements, controls that prevent access to the SAD and querying of call recordings, and documented justification and evidence.FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data? · FAQ 1210, compensating-control list · Checked 2026-09-30
- 28If sensitive authentication data cannot be kept out of a call recording, FAQ 1210 requires it to be securely deleted immediately after the transaction is authorized.FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data? · FAQ 1210, answer paragraph 2 · Checked 2026-09-30
- 29The PCI DSS prohibition on keeping sensitive authentication data in call recordings after authorization applies even when the recording is encrypted.FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data? · FAQ 1210, answer paragraph 1 · Checked 2026-09-30
- 30PCI SSC FAQ 1210 says that where sensitive authentication data is collected during a call, the entity should prevent it from being recorded, enabling audio suppression or redaction technology where it exists.FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data? · FAQ 1210, answer paragraph 2 · Checked 2026-09-30
- 31PCI SSC says entities should assess the extra risk of processing account data at unsecured home locations and add controls to match, and that its remote-working guidance does not replace PCI DSS requirements.Protecting Payments While Working Remotely · 'Important note' and people controls · Checked 2026-09-30
- 32PCI SSC guidance for remote workers who take payments calls for multi-factor authentication to access telephone systems or payment processing platforms.Protecting Payments While Working Remotely · 'Process controls' section · Checked 2026-09-30
- 33The PCI SSC future-dated requirements post cites Requirement 12.5.2 as an annual exercise to confirm every aspect of PCI DSS scope.Now is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x · list of example requirements · Checked 2026-09-30
- 34PCI SSC held a Request for Comments on PCI DSS v4.0.1 from 3 June to 20 July 2026 to start work on the next iteration of the standard.Request for Comments: PCI Data Security Standard (PCI DSS) v4.0.1 · post body, RFC window paragraph · Checked 2026-09-30
- 35A third-party service provider that has a PCI DSS Attestation of Compliance is expected to give it to customers on request, and customers may also ask for the relevant sections of its ROC or SAQ D for Service Providers.FAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance? · FAQ 1576, answer paragraphs 1-2 · Checked 2026-09-30
- 36Under PCI DSS Requirements 12.9.1 and 12.9.2, a TPSP documents which PCI DSS requirements it is responsible for and which are the customer's, typically as a responsibility matrix.FAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance? · FAQ 1576, responsibility matrix paragraph · Checked 2026-09-30
- 37A TPSP's evidence must let the customer verify that the scope of the TPSP's PCI DSS assessment covered the services the customer actually uses.FAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance? · FAQ 1576, answer paragraph 1 · Checked 2026-09-30
- 38A TPSP without its own PCI DSS assessment must provide specific evidence for the applicable requirements so the customer or its assessor can confirm they are met.FAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance? · FAQ 1576, answer paragraph 3 · Checked 2026-09-30
- 39Twilio says Conversation Intelligence (classic) is not PCI compliant and must not be enabled in PCI workflows.Payment Card Industry Programmable Voice workflows · excluded services section · Checked 2026-09-30
- 40Twilio Conversation Relay supports PCI workflows only when configured with PCI-compliant text-to-speech and transcription providers.Payment Card Industry Programmable Voice workflows · PCI-compliant products section · Checked 2026-09-30
- 41Twilio PCI Mode is an account-wide setting turned on in the Twilio Console on the Voice general settings page.Payment Card Industry Programmable Voice workflows · PCI Mode section · Checked 2026-09-30
- 42Once PCI Mode is turned on for a Twilio account it cannot be turned off for that account.Payment Card Industry Programmable Voice workflows · PCI Mode section · Checked 2026-09-30
- 43By default Twilio keeps PCI voice recordings made in PCI Mode workflows for one year from creation and then deletes them permanently.Payment Card Industry Programmable Voice workflows · PCI voice recordings section · Checked 2026-09-30
- 44Twilio points customers to its Responsibility Matrix for their own obligations when using Programmable Voice in a PCI workflow.Payment Card Industry Programmable Voice workflows · customer responsibility paragraph · Checked 2026-09-30
- 45Twilio's native and Marketplace transcriptions are not available on an account with PCI Mode enabled.Payment Card Industry Programmable Voice workflows · excluded services section · Checked 2026-09-30
- 46PCI DSS v3.2.1 was retired on 31 March 2024.Now is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x · key context paragraph · Checked 2026-09-30
- 47PCI SSC retired PCI DSS v4.0 on 31 December 2024, leaving v4.0.1 as the only active version.Just Published: PCI DSS v4.0.1 · paragraph on v4.0 retirement · Checked 2026-09-30
- 48As of the June 2026 RFC announcement, PCI DSS v4.0.1 was still the published standard, and the post gave no name or date for a successor version.Request for Comments: PCI Data Security Standard (PCI DSS) v4.0.1 · post body · Checked 2026-09-30
- 49PCI DSS v4.0.1 is a limited revision that adds and deletes no requirements; it corrects and clarifies existing text.Just Published: PCI DSS v4.0.1 · paragraph describing the nature of the revision · Checked 2026-09-30
- 50PCI SSC published PCI DSS v4.0.1 in June 2024; the announcement post is dated 11 June 2024.Just Published: PCI DSS v4.0.1 · post date and opening paragraph · Checked 2026-09-30
- 51For business-to-business VoIP carrying card data across multiple carriers, the traffic is in the entity's scope only while it is on the entity's infrastructure.FAQ 1153: How does PCI DSS apply to VoIP? · FAQ 1153, business-to-business bullet · Checked 2026-09-30
- 52For VoIP between a cardholder and an entity, the entity's systems are in scope but securing the transmission outside the entity's infrastructure is not, because the entity cannot control how the cardholder places calls.FAQ 1153: How does PCI DSS apply to VoIP? · FAQ 1153, cardholder transmissions bullet · Checked 2026-09-30
- 53Inbound VoIP traffic from an external source is not in the entity's PCI DSS scope until it reaches the entity's infrastructure.FAQ 1153: How does PCI DSS apply to VoIP? · FAQ 1153, inbound external traffic bullet · Checked 2026-09-30
- 54VoIP traffic that carries payment card account data is in scope for applicable PCI DSS controls wherever it is stored, processed or transmitted on the entity's own network.FAQ 1153: How does PCI DSS apply to VoIP? · FAQ 1153, internal transmissions bullet · Checked 2026-09-30
- 55Webex Contact Center admins can set a duration in seconds after which a paused call recording resumes automatically.Set up security for Webex Contact Center · Call recordings section · Checked 2026-09-30
- 56Webex Contact Center sensitive data masking applies only to Agent Desktop, not Supervisor Desktop users.Set up security for Webex Contact Center · Sensitive Data section · Checked 2026-09-30
- 57Webex Contact Center sensitive data masking only hides data in the UI; Cisco says the data is not encrypted in the backend and network and console logs still contain it.Set up security for Webex Contact Center · Sensitive Data section · Checked 2026-09-30
- 58In Webex Contact Center, agent pause of call recording is disabled by default; when an admin enables it, agents can pause recording from Agent Desktop while a customer shares sensitive data.Set up security for Webex Contact Center · Call recordings section · Checked 2026-09-30
- 59While a Webex Contact Center call recording is paused, the system still records call metadata such as duration, dialed number and routing path in the Contact Center database.Set up security for Webex Contact Center · Call recordings section · Checked 2026-09-30
- 60Cisco's November 2021 Webex Contact Center 1.0 data sheet states the platform is PCI DSS Level 1 certified through a third-party AOC audit reviewed annually.Webex Contact Center 1.0 Data Sheet · Security and compliance section · Checked 2026-09-30
Documents
FAQ 1153: How does PCI DSS apply to VoIP?
FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data?
FAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance?
Industry Guidance on Accepting Telephone Payments Securely
Just Published: PCI DSS v4.0.1
Now is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x
Protecting Payments While Working Remotely
Request for Comments: PCI Data Security Standard (PCI DSS) v4.0.1
Best practices for PCI compliance in Connect Customer
Encrypt sensitive customer input in Connect Customer
Frequently asked questions about Connect Customer screen recording capabilities
Payment Card Industry Programmable Voice workflows
PCI DSS compliance - Genesys Cloud Resource Center
Sample secure customer data entry input in a call with a contact center agent
Set up security for Webex Contact Center
Webex Contact Center 1.0 Data Sheet
Cite this page
APA
WarmTransfer. (2026, September 30). PCI DSS for contact centers. WarmTransfer. https://warmtransfer.net/knowledge/pci-dss-contact-center
BibTeX
@misc{warmtransfer-pci-dss-contact-center,
title = {PCI DSS for contact centers},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/pci-dss-contact-center},
note = {Verified 2026-09-30}
}