# PCI DSS for contact centers

Canonical: https://warmtransfer.net/knowledge/pci-dss-contact-center

Last verified: 2026-09-30

Storing card validation codes (CAV2, CVC2, CVV2, or CID) in any form of digital audio recording after authorization violates PCI DSS Requirement 3.3.1[^24]. This prohibition applies even when the recording is encrypted[^29].

## Standard Lifecycle and Scoping

PCI SSC retired PCI DSS v3.2.1 on 31 March 2024[^46]. PCI SSC published PCI DSS v4.0.1 in June 2024, with the announcement post dated 11 June 2024[^50]. PCI DSS v4.0.1 is a limited revision that adds and deletes no requirements, functioning to correct and clarify existing text[^49]. PCI SSC retired PCI DSS v4.0 on 31 December 2024, leaving v4.0.1 as the only active version[^47]. Across PCI DSS v4.x, 51 of the 64 new requirements introduced in PCI DSS v4.0 were future-dated and became effective on 31 March 2025, a date unchanged by v4.0.1[^14]. PCI SSC held a Request for Comments on PCI DSS v4.0.1 from 3 June to 20 July 2026 to begin work on the next iteration of the standard[^34]. As of the June 2026 RFC announcement, PCI DSS v4.0.1 remained the published standard, and the announcement gave no name or date for a successor version[^48].

VoIP traffic carrying payment card account data is in scope for applicable PCI DSS controls wherever it is stored, processed, or transmitted on an entity's own network[^54]. Inbound VoIP traffic from an external source is not within the entity's PCI DSS scope until it reaches the entity's infrastructure[^53]. For VoIP transmissions between a cardholder and an entity, the entity's systems are in scope, but securing the transmission outside the entity's infrastructure is not, because the entity cannot control how cardholders place calls[^52]. Similarly, for business-to-business VoIP carrying card data across multiple carriers, the traffic is in the entity's scope only while it resides on the entity's infrastructure[^51].

## Call Recording and SAD Controls

PCI SSC FAQ 1210 states that where sensitive authentication data (SAD) is collected during a call, entities should prevent it from being recorded, enabling audio suppression or redaction technology where it exists[^30]. If SAD cannot be kept out of a call recording, FAQ 1210 requires it to be securely deleted immediately after the transaction is authorized[^28]. Where secure deletion from recordings is not feasible, FAQ 1210 specifies minimum compensating controls: an annual risk assessment and one after significant change, protection of SAD under applicable PCI DSS requirements, controls preventing access to SAD and querying of recordings, and documented justification and evidence[^27]. These compensating controls are validated during the annual PCI DSS assessment and shared with acquirers or payment brands as needed[^26]. FAQ 1210 also states that PCI DSS does not override local or regional laws regarding audio recording retention[^25].

PCI SSC guidance recommends implementing a policy that keeps materials and devices capable of recording card data out of the telephone payment environment[^13]. PCI SSC guidance also states that technology minimizing personnel exposure to account data should be considered for telephone payments[^23]. For remote personnel taking payments, PCI SSC guidance calls for multi-factor authentication (MFA) to access telephone systems or payment processing platforms[^32]. PCI SSC states that entities should assess the additional risk of processing account data at unsecured home locations and apply matching controls, noting that remote-working guidance does not replace PCI DSS requirements[^31].

## Third-Party Service Provider Management

A third-party service provider (TPSP) with a PCI DSS Attestation of Compliance (AOC) is expected to provide it to customers upon request, and customers may also request relevant sections of its Report on Compliance (ROC) or SAQ D for Service Providers[^35]. The TPSP's documentation must allow the customer to verify that the scope of the assessment covered the specific services used[^37]. Under PCI DSS Requirements 12.9.1 and 12.9.2, a TPSP documents responsibility division—typically in a responsibility matrix—clarifying which requirements belong to the TPSP and which remain with the customer[^36]. If a TPSP lacks its own PCI DSS assessment, it must provide specific evidence for applicable requirements so the customer or its assessor can confirm they are met[^38].

## Platform Implementations

Vendors document platform-specific configurations, limits, and customer obligations for payment processing:[^41][^2][^58][^16]

| Platform | Features and controls | Documented constraints |
| --- | --- | --- |
| Twilio | PCI Mode is enabled in the Twilio Console under Voice general settings[^41]. Supports Conversation Relay when configured with PCI-compliant TTS and transcription providers[^40]. Twilio provides a Responsibility Matrix for customer obligations[^44]. | PCI Mode is irreversible once enabled on an account[^42]. Native and Marketplace transcriptions are unavailable in PCI Mode[^45]. Conversation Intelligence (classic) is not PCI compliant and cannot be used in PCI workflows[^39]. PCI voice recordings are retained for 1 year by default and then deleted permanently[^43]. |
| Amazon Connect | Encrypted DTMF or Amazon Lex for speech input[^2]. DTMF can be encrypted in the Store customer input block via a customer X.509 certificate (.pem) with up to 2 active rotation keys[^12]; customer decrypts using AWS Encryption SDK[^1]. Sample flow puts agents on hold during input[^3]. MFA is recommended for card access[^4]. Screen recording is PCI DSS compliant under shared responsibility[^10]. | Captured card data must be scrubbed from recordings and obscured in logs and transcripts[^11]. Screen recording continues while a customer is on hold[^9]. Rule-based redaction masks whole windows, cannot mask single form fields, does not redact audio, generates a masked copy, and retains original unredacted screen recordings in S3[^6][^8][^7]. Screen recordings carry unredacted audio by default[^5]. |
| Webex Contact Center | Admins can enable agent pause of recordings on Agent Desktop[^58]. Admins can configure an automatic resume duration in seconds[^55]. Sensitive data masking is available on Agent Desktop[^57][^56]. Cisco's November 2021 Webex Contact Center 1.0 data sheet stated the platform is PCI DSS Level 1 certified through a third-party AOC audit reviewed annually[^60]. | Pause of recording is disabled by default[^58]. Metadata (duration, dialed number, routing) continues to log during pauses[^59]. UI masking does not encrypt backend data; network and console logs still contain the data[^57]. UI masking does not apply to Supervisor Desktop[^56]. |
| Genesys Cloud | Service Provider Level 1 compliant with PCI DSS version 4.0[^18]. Provides Secure Pause and Secure Call Flows to prevent capturing entry[^19]. | Customers must enable the PCI setting in Manage Organization and execute Secure Pause or Secure Flows prior to handling cardholder data[^16]. Genesys may share its AOC only under non-disclosure agreement[^15]. |

## See also

See also [Call recording consent laws](https://warmtransfer.net/knowledge/call-recording-consent-laws).
See also [Caller authentication and fraud prevention in contact centers](https://warmtransfer.net/knowledge/contact-center-caller-authentication).
See also [Webex contact center](https://warmtransfer.net/knowledge/webex-contact-center).
See also [CCaaS platforms compared](https://warmtransfer.net/knowledge/ccaas-platform-comparison).
See also [GDPR for contact centers and call recording](https://warmtransfer.net/knowledge/gdpr-contact-center).
See also [Speech and interaction analytics](https://warmtransfer.net/knowledge/speech-interaction-analytics).
See also [TLS certificates and secure SIP failures](https://warmtransfer.net/knowledge/sip-oauth-and-tls).
See also [CDR privacy redaction and evidence-safe reporting](https://warmtransfer.net/knowledge/cdr-privacy-redaction).
See also [Recording consent and AI processing privacy](https://warmtransfer.net/knowledge/ai-recording-privacy).
See also [Identity SSO and directory provisioning for UC](https://warmtransfer.net/knowledge/identity-sso-provisioning).
See also [Certificate lifecycle management for voice](https://warmtransfer.net/knowledge/certificate-lifecycle).
See also [Toll fraud prevention and voice security](https://warmtransfer.net/knowledge/voice-security-toll-fraud).
See also [Contact centre AI data residency retention and training boundaries](https://warmtransfer.net/knowledge/ai-data-residency-governance).
See also [Webex Contact Center data locality by country](https://warmtransfer.net/knowledge/webex-cc-data-locality).
See also [The Cisco Trust Portal as a monitorable document source](https://warmtransfer.net/knowledge/cisco-trust-portal-documents).
See also [Webex suite data residency and the GEO model](https://warmtransfer.net/knowledge/webex-suite-data-residency).
See also [Webex Contact Center recording and contact data retention](https://warmtransfer.net/knowledge/webex-cc-recording-retention).
See also [Cisco offer disclosures as an evidence class](https://warmtransfer.net/knowledge/cisco-offer-disclosures).
See also [Webex service level agreements and objectives](https://warmtransfer.net/knowledge/webex-sla-commitments).
See also [The Cisco AI transparency note set beyond the contact centre](https://warmtransfer.net/knowledge/cisco-ai-transparency-census).

## Applicability

Applies to: PCI SSC PCI DSS, PCI SSC Information Supplement: Protecting Telephone-Based Payment Card Data, Twilio Programmable Voice, Twilio Conversation Intelligence (classic), Twilio Conversation Relay, AWS Amazon Connect (Connect Customer), AWS Amazon Connect (Connect Customer) screen recording, Cisco Webex Contact Center, Cisco Webex Contact Center 1.0, and Genesys Cloud. Deployments: multi-tenant and any. Sources checked 2026-09-30. The claims cite PCI DSS releases v3.2.1, v4.0, and v4.0.1[^46][^47][^50]. Cisco's November 2021 Webex Contact Center 1.0 data sheet stated the platform is PCI DSS Level 1 certified through a third-party AOC audit reviewed annually[^60]. Genesys Cloud compliance claims apply to Service Provider Level 1 under PCI DSS version 4.0[^18].

## What remains uncertain

Card data in AI transcription, summaries, speech analytics, and redaction accuracy across CCaaS vendors is not covered by the sources below.
Current Webex Contact Center PCI DSS attestation scope and version, beyond the 2021 1.0 data sheet, is not covered by the sources below.
IVR self-service and agent-assisted payment descoping—such as Twilio Pay, Webex Contact Center flows, or Genesys secure flows—and what stays in scope are not covered by the sources below.
PCI DSS features and recording pause capabilities for telephony and contact center platforms not named in the claims are not covered by the sources below.
SAQ selection for telephone payments (such as SAQ C-VT versus SAQ D) with third-party payment capture is not covered by the sources below.
The name, timeline, and telephone-relevant changes of any successor to PCI DSS v4.0.1 are not covered by the sources below.
The PCI SSC Third-Party Security Assurance supplement Appendix B sample responsibility matrix is not covered by the sources below.
Storage of sensitive authentication data before authorization for callbacks and deferred payments is not covered by the sources below.

## Sources

[^1]: Encrypted Stored customer input from Amazon Connect is decrypted by the customer with the AWS Encryption SDK and its private key; AWS provides a Java sample. Source: [Encrypt sensitive customer input in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/encrypt-data.html), 'How to decrypt data encrypted by Connect Customer' section. Checked 2026-09-30.
[^2]: AWS recommends collecting payment card information in Amazon Connect with encrypted DTMF, or with Amazon Lex for speech input. Source: [Best practices for PCI compliance in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/compliance-validation-best-practices-PCI.html), bullet 2. Checked 2026-09-30.
[^3]: Amazon Connect's sample agent-assisted secure-input flow conferences agent and customer, puts the agent on hold while the customer keys card data into an encrypting Store customer input block, then reconnects them; AWS recommends encryption over this sample in production. Source: [Sample secure customer data entry input in a call with a contact center agent](https://docs.aws.amazon.com/connect/latest/adminguide/sample-secure-input-with-agent.html), introduction and steps 2-6. Checked 2026-09-30.
[^4]: AWS recommends MFA for any access to card data in Amazon Connect because the service is a public endpoint. Source: [Best practices for PCI compliance in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/compliance-validation-best-practices-PCI.html), bullet 5. Checked 2026-09-30.
[^5]: By default an Amazon Connect screen recording carries unredacted call audio. Source: [Frequently asked questions about Connect Customer screen recording capabilities](https://docs.aws.amazon.com/connect/latest/adminguide/faq-screenrecording.html), Configuration > 'Is there a way to choose which audio (redacted or unredacted) gets used for screen recording?'. Checked 2026-09-30.
[^6]: Amazon Connect rule-based redaction masks whole browser or application windows that match URL or window-title rules and cannot redact a single form field. Source: [Frequently asked questions about Connect Customer screen recording capabilities](https://docs.aws.amazon.com/connect/latest/adminguide/faq-screenrecording.html), Rule-based redaction FAQ > 'Can I redact only part of a page, such as a single form field?'. Checked 2026-09-30.
[^7]: Amazon Connect rule-based redaction never pauses screen capture; it masks matching windows only in a separate redacted copy after the contact, and the unredacted recording is kept in the same S3 bucket. Source: [Frequently asked questions about Connect Customer screen recording capabilities](https://docs.aws.amazon.com/connect/latest/adminguide/faq-screenrecording.html), Rule-based redaction FAQ > 'Does rule-based redaction pause or stop the recording' and 'Does rule-based redaction affect storage costs?'. Checked 2026-09-30.
[^8]: Amazon Connect rule-based redaction applies only to screen video and does not redact audio; audio redaction needs conversational analytics sensitive data redaction. Source: [Frequently asked questions about Connect Customer screen recording capabilities](https://docs.aws.amazon.com/connect/latest/adminguide/faq-screenrecording.html), Rule-based redaction FAQ > 'Does rule-based redaction apply to call recordings?'. Checked 2026-09-30.
[^9]: Amazon Connect screen recording keeps recording when the agent puts the customer on hold. Source: [Frequently asked questions about Connect Customer screen recording capabilities](https://docs.aws.amazon.com/connect/latest/adminguide/faq-screenrecording.html), Screen recording FAQ > 'Does screen recording STOP when an agent places a customer on hold?'. Checked 2026-09-30.
[^10]: AWS states that Amazon Connect, including screen recording, is PCI DSS compliant, but the customer is responsible for deciding whether its own implementation meets its compliance requirements. Source: [Frequently asked questions about Connect Customer screen recording capabilities](https://docs.aws.amazon.com/connect/latest/adminguide/faq-screenrecording.html), Screen recording FAQ > General specifications > 'Is screen recording PCI compliant?'. Checked 2026-09-30.
[^11]: AWS says that if card data is captured in Amazon Connect call recordings it must be scrubbed from the recording and obscured in any logs or transcriptions. Source: [Best practices for PCI compliance in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/compliance-validation-best-practices-PCI.html), bullet 3. Checked 2026-09-30.
[^12]: Amazon Connect can encrypt DTMF captured by the Store customer input block with a customer-supplied public key and X.509 certificate in .pem format, with up to two encryption keys active at a time for rotation. Source: [Encrypt sensitive customer input in Connect Customer](https://docs.aws.amazon.com/connect/latest/adminguide/encrypt-data.html), introduction and note. Checked 2026-09-30.
[^13]: PCI SSC recommends a policy that keeps materials and devices that could record card data out of the telephone payment environment. Source: [Industry Guidance on Accepting Telephone Payments Securely](https://blog.pcisecuritystandards.org/industry-guidance-on-accepting-telephone-payments-securely), 'Process' best practice. Checked 2026-09-30.
[^14]: 51 of the 64 new requirements introduced in PCI DSS v4.0 were future-dated and became effective on 31 March 2025; v4.0.1 did not change that date. Source: [Now is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x](https://blog.pcisecuritystandards.org/now-is-the-time-for-organizations-to-adopt-the-future-dated-requirements-of-pci-dss-v4-x), opening paragraphs. Checked 2026-09-30.
[^15]: Genesys says it may share the Genesys Cloud PCI DSS AOC with interested parties after they sign a non-disclosure agreement. Source: [PCI DSS compliance - Genesys Cloud Resource Center](https://help.mypurecloud.com/?p=133895), Attestation of Compliance paragraph. Checked 2026-09-30.
[^16]: Genesys requires customers to enable the PCI setting on the Manage Organization page and to use Secure Pause or a Secure Flow before handling cardholder data. Source: [PCI DSS compliance - Genesys Cloud Resource Center](https://help.mypurecloud.com/?p=133895), customer responsibilities section. Checked 2026-09-30.
[^17]: When the PCI DSS compliance setting is enabled in Genesys Cloud, DTMF logging and media capture are disabled. Source: [PCI DSS compliance - Genesys Cloud Resource Center](https://help.mypurecloud.com/?p=133895), PCI setting effects section. Checked 2026-09-30.
[^18]: Genesys's PCI DSS page states that Genesys Cloud is Service Provider Level 1 compliant with PCI DSS version 4.0. Source: [PCI DSS compliance - Genesys Cloud Resource Center](https://help.mypurecloud.com/?p=133895), opening compliance statement. Checked 2026-09-30.
[^19]: Genesys Cloud provides Secure Pause, which temporarily stops recording during entry of sensitive data, and Secure Call Flows, to which agents transfer calls so the system and agent cannot capture the caller's entry. Source: [PCI DSS compliance - Genesys Cloud Resource Center](https://help.mypurecloud.com/?p=133895), Secure Pause and Secure Call Flows sections. Checked 2026-09-30.
[^20]: Because PCI SSC retired PCI DSS v4.0 on 31 December 2024, the v4.0 label on Genesys's compliance page probably lags the current attestation, and the AOC itself should be checked for the version and date assessed (inferred). Source: [PCI DSS compliance - Genesys Cloud Resource Center](https://help.mypurecloud.com/?p=133895), opening compliance statement, read against pcissc-blog-pci-dss-v4-0-1-published. Checked 2026-09-30.
[^21]: Agent-initiated recording pause (Webex Contact Center pause, Genesys Secure Pause) depends on the agent acting in time, so a missed pause leaves SAD in the recording and triggers the FAQ 1210 duty to delete it securely after authorization (inferred). Source: [FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data?](https://www.pcisecuritystandards.org/faqs/1210/), FAQ 1210 answer paragraph 2, read with the cisco-help-3srgv1-wxcc-security call recordings section and the genesys-help-pci-dss-compliance Secure Pause section. Checked 2026-09-30.
[^22]: A CCaaS vendor's PCI DSS attestation does not by itself make the customer's contact center compliant; the customer keeps the requirements that the vendor's responsibility matrix assigns to it, including how recording, pause and screen capture are configured (inferred). Source: [FAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance?](https://pcisecuritystandards.org/faq/articles/Frequently_Asked_Question/what-evidence-is-a-tpsp-expected-to-provide-to-customers-to-demonstrate-pci-dss-compliance), FAQ 1576 responsibility matrix paragraph, read with the aws-connect-screen-recording-faq PCI answer and twilio-docs-voice-pci-workflows responsibility paragraph. Checked 2026-09-30.
[^23]: PCI SSC guidance says technology that minimizes personnel exposure to account data should be considered for telephone payments. Source: [Industry Guidance on Accepting Telephone Payments Securely](https://blog.pcisecuritystandards.org/industry-guidance-on-accepting-telephone-payments-securely), 'Technology' best practice. Checked 2026-09-30.
[^24]: Storing card validation codes (CAV2, CVC2, CVV2 or CID) in any form of digital audio recording after authorization violates PCI DSS Requirement 3.3.1. Source: [FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data?](https://www.pcisecuritystandards.org/faqs/1210/), FAQ 1210, answer paragraph 1. Checked 2026-09-30.
[^25]: FAQ 1210 states that PCI DSS does not override local or regional laws on retaining audio recordings. Source: [FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data?](https://www.pcisecuritystandards.org/faqs/1210/), FAQ 1210, final paragraph. Checked 2026-09-30.
[^26]: Compensating controls for SAD retained in call recordings are validated during the annual PCI DSS assessment and shared with acquirers or payment brands as needed. Source: [FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data?](https://www.pcisecuritystandards.org/faqs/1210/), FAQ 1210, paragraph after the compensating-control list. Checked 2026-09-30.
[^27]: Where secure deletion of SAD from recordings is not feasible, FAQ 1210 sets minimum compensating controls: a risk assessment annually and after significant change, protection of the SAD under applicable PCI DSS requirements, controls that prevent access to the SAD and querying of call recordings, and documented justification and evidence. Source: [FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data?](https://www.pcisecuritystandards.org/faqs/1210/), FAQ 1210, compensating-control list. Checked 2026-09-30.
[^28]: If sensitive authentication data cannot be kept out of a call recording, FAQ 1210 requires it to be securely deleted immediately after the transaction is authorized. Source: [FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data?](https://www.pcisecuritystandards.org/faqs/1210/), FAQ 1210, answer paragraph 2. Checked 2026-09-30.
[^29]: The PCI DSS prohibition on keeping sensitive authentication data in call recordings after authorization applies even when the recording is encrypted. Source: [FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data?](https://www.pcisecuritystandards.org/faqs/1210/), FAQ 1210, answer paragraph 1. Checked 2026-09-30.
[^30]: PCI SSC FAQ 1210 says that where sensitive authentication data is collected during a call, the entity should prevent it from being recorded, enabling audio suppression or redaction technology where it exists. Source: [FAQ 1210: Are audio/voice recordings permitted to contain sensitive authentication data?](https://www.pcisecuritystandards.org/faqs/1210/), FAQ 1210, answer paragraph 2. Checked 2026-09-30.
[^31]: PCI SSC says entities should assess the extra risk of processing account data at unsecured home locations and add controls to match, and that its remote-working guidance does not replace PCI DSS requirements. Source: [Protecting Payments While Working Remotely](https://blog.pcisecuritystandards.org/protecting-payments-while-working-remotely), 'Important note' and people controls. Checked 2026-09-30.
[^32]: PCI SSC guidance for remote workers who take payments calls for multi-factor authentication to access telephone systems or payment processing platforms. Source: [Protecting Payments While Working Remotely](https://blog.pcisecuritystandards.org/protecting-payments-while-working-remotely), 'Process controls' section. Checked 2026-09-30.
[^33]: The PCI SSC future-dated requirements post cites Requirement 12.5.2 as an annual exercise to confirm every aspect of PCI DSS scope. Source: [Now is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x](https://blog.pcisecuritystandards.org/now-is-the-time-for-organizations-to-adopt-the-future-dated-requirements-of-pci-dss-v4-x), list of example requirements. Checked 2026-09-30.
[^34]: PCI SSC held a Request for Comments on PCI DSS v4.0.1 from 3 June to 20 July 2026 to start work on the next iteration of the standard. Source: [Request for Comments: PCI Data Security Standard (PCI DSS) v4.0.1](https://blog.pcisecuritystandards.org/request-for-comments-pci-data-security-standard-pci-dss-v4.0.1), post body, RFC window paragraph. Checked 2026-09-30.
[^35]: A third-party service provider that has a PCI DSS Attestation of Compliance is expected to give it to customers on request, and customers may also ask for the relevant sections of its ROC or SAQ D for Service Providers. Source: [FAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance?](https://pcisecuritystandards.org/faq/articles/Frequently_Asked_Question/what-evidence-is-a-tpsp-expected-to-provide-to-customers-to-demonstrate-pci-dss-compliance), FAQ 1576, answer paragraphs 1-2. Checked 2026-09-30.
[^36]: Under PCI DSS Requirements 12.9.1 and 12.9.2, a TPSP documents which PCI DSS requirements it is responsible for and which are the customer's, typically as a responsibility matrix. Source: [FAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance?](https://pcisecuritystandards.org/faq/articles/Frequently_Asked_Question/what-evidence-is-a-tpsp-expected-to-provide-to-customers-to-demonstrate-pci-dss-compliance), FAQ 1576, responsibility matrix paragraph. Checked 2026-09-30.
[^37]: A TPSP's evidence must let the customer verify that the scope of the TPSP's PCI DSS assessment covered the services the customer actually uses. Source: [FAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance?](https://pcisecuritystandards.org/faq/articles/Frequently_Asked_Question/what-evidence-is-a-tpsp-expected-to-provide-to-customers-to-demonstrate-pci-dss-compliance), FAQ 1576, answer paragraph 1. Checked 2026-09-30.
[^38]: A TPSP without its own PCI DSS assessment must provide specific evidence for the applicable requirements so the customer or its assessor can confirm they are met. Source: [FAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance?](https://pcisecuritystandards.org/faq/articles/Frequently_Asked_Question/what-evidence-is-a-tpsp-expected-to-provide-to-customers-to-demonstrate-pci-dss-compliance), FAQ 1576, answer paragraph 3. Checked 2026-09-30.
[^39]: Twilio says Conversation Intelligence (classic) is not PCI compliant and must not be enabled in PCI workflows. Source: [Payment Card Industry Programmable Voice workflows](https://www.twilio.com/docs/voice/pci-workflows), excluded services section. Checked 2026-09-30.
[^40]: Twilio Conversation Relay supports PCI workflows only when configured with PCI-compliant text-to-speech and transcription providers. Source: [Payment Card Industry Programmable Voice workflows](https://www.twilio.com/docs/voice/pci-workflows), PCI-compliant products section. Checked 2026-09-30.
[^41]: Twilio PCI Mode is an account-wide setting turned on in the Twilio Console on the Voice general settings page. Source: [Payment Card Industry Programmable Voice workflows](https://www.twilio.com/docs/voice/pci-workflows), PCI Mode section. Checked 2026-09-30.
[^42]: Once PCI Mode is turned on for a Twilio account it cannot be turned off for that account. Source: [Payment Card Industry Programmable Voice workflows](https://www.twilio.com/docs/voice/pci-workflows), PCI Mode section. Checked 2026-09-30.
[^43]: By default Twilio keeps PCI voice recordings made in PCI Mode workflows for one year from creation and then deletes them permanently. Source: [Payment Card Industry Programmable Voice workflows](https://www.twilio.com/docs/voice/pci-workflows), PCI voice recordings section. Checked 2026-09-30.
[^44]: Twilio points customers to its Responsibility Matrix for their own obligations when using Programmable Voice in a PCI workflow. Source: [Payment Card Industry Programmable Voice workflows](https://www.twilio.com/docs/voice/pci-workflows), customer responsibility paragraph. Checked 2026-09-30.
[^45]: Twilio's native and Marketplace transcriptions are not available on an account with PCI Mode enabled. Source: [Payment Card Industry Programmable Voice workflows](https://www.twilio.com/docs/voice/pci-workflows), excluded services section. Checked 2026-09-30.
[^46]: PCI DSS v3.2.1 was retired on 31 March 2024. Source: [Now is the Time for Organizations to Adopt the Future-Dated Requirements of PCI DSS v4.x](https://blog.pcisecuritystandards.org/now-is-the-time-for-organizations-to-adopt-the-future-dated-requirements-of-pci-dss-v4-x), key context paragraph. Checked 2026-09-30.
[^47]: PCI SSC retired PCI DSS v4.0 on 31 December 2024, leaving v4.0.1 as the only active version. Source: [Just Published: PCI DSS v4.0.1](https://blog.pcisecuritystandards.org/just-published-pci-dss-v4-0-1), paragraph on v4.0 retirement. Checked 2026-09-30.
[^48]: As of the June 2026 RFC announcement, PCI DSS v4.0.1 was still the published standard, and the post gave no name or date for a successor version. Source: [Request for Comments: PCI Data Security Standard (PCI DSS) v4.0.1](https://blog.pcisecuritystandards.org/request-for-comments-pci-data-security-standard-pci-dss-v4.0.1), post body. Checked 2026-09-30.
[^49]: PCI DSS v4.0.1 is a limited revision that adds and deletes no requirements; it corrects and clarifies existing text. Source: [Just Published: PCI DSS v4.0.1](https://blog.pcisecuritystandards.org/just-published-pci-dss-v4-0-1), paragraph describing the nature of the revision. Checked 2026-09-30.
[^50]: PCI SSC published PCI DSS v4.0.1 in June 2024; the announcement post is dated 11 June 2024. Source: [Just Published: PCI DSS v4.0.1](https://blog.pcisecuritystandards.org/just-published-pci-dss-v4-0-1), post date and opening paragraph. Checked 2026-09-30.
[^51]: For business-to-business VoIP carrying card data across multiple carriers, the traffic is in the entity's scope only while it is on the entity's infrastructure. Source: [FAQ 1153: How does PCI DSS apply to VoIP?](https://www.pcisecuritystandards.org/faq/articles/Frequently_Asked_Question/is-voip-in-scope-for-pci-dss/), FAQ 1153, business-to-business bullet. Checked 2026-09-30.
[^52]: For VoIP between a cardholder and an entity, the entity's systems are in scope but securing the transmission outside the entity's infrastructure is not, because the entity cannot control how the cardholder places calls. Source: [FAQ 1153: How does PCI DSS apply to VoIP?](https://www.pcisecuritystandards.org/faq/articles/Frequently_Asked_Question/is-voip-in-scope-for-pci-dss/), FAQ 1153, cardholder transmissions bullet. Checked 2026-09-30.
[^53]: Inbound VoIP traffic from an external source is not in the entity's PCI DSS scope until it reaches the entity's infrastructure. Source: [FAQ 1153: How does PCI DSS apply to VoIP?](https://www.pcisecuritystandards.org/faq/articles/Frequently_Asked_Question/is-voip-in-scope-for-pci-dss/), FAQ 1153, inbound external traffic bullet. Checked 2026-09-30.
[^54]: VoIP traffic that carries payment card account data is in scope for applicable PCI DSS controls wherever it is stored, processed or transmitted on the entity's own network. Source: [FAQ 1153: How does PCI DSS apply to VoIP?](https://www.pcisecuritystandards.org/faq/articles/Frequently_Asked_Question/is-voip-in-scope-for-pci-dss/), FAQ 1153, internal transmissions bullet. Checked 2026-09-30.
[^55]: Webex Contact Center admins can set a duration in seconds after which a paused call recording resumes automatically. Source: [Set up security for Webex Contact Center](https://help.webex.com/en-us/article/3srgv1), Call recordings section. Checked 2026-09-30.
[^56]: Webex Contact Center sensitive data masking applies only to Agent Desktop, not Supervisor Desktop users. Source: [Set up security for Webex Contact Center](https://help.webex.com/en-us/article/3srgv1), Sensitive Data section. Checked 2026-09-30.
[^57]: Webex Contact Center sensitive data masking only hides data in the UI; Cisco says the data is not encrypted in the backend and network and console logs still contain it. Source: [Set up security for Webex Contact Center](https://help.webex.com/en-us/article/3srgv1), Sensitive Data section. Checked 2026-09-30.
[^58]: In Webex Contact Center, agent pause of call recording is disabled by default; when an admin enables it, agents can pause recording from Agent Desktop while a customer shares sensitive data. Source: [Set up security for Webex Contact Center](https://help.webex.com/en-us/article/3srgv1), Call recordings section. Checked 2026-09-30.
[^59]: While a Webex Contact Center call recording is paused, the system still records call metadata such as duration, dialed number and routing path in the Contact Center database. Source: [Set up security for Webex Contact Center](https://help.webex.com/en-us/article/3srgv1), Call recordings section. Checked 2026-09-30.
[^60]: Cisco's November 2021 Webex Contact Center 1.0 data sheet states the platform is PCI DSS Level 1 certified through a third-party AOC audit reviewed annually. Source: [Webex Contact Center 1.0 Data Sheet](https://www.cisco.com/c/en/us/products/collateral/contact-center/webex-contact-center/datasheet-c78-742822.html), Security and compliance section. Checked 2026-09-30.
