Source record · tier 1 standards and regulators
FAQ 1153: How does PCI DSS apply to VoIP?
- Publisher
- PCI Security Standards Council
- URL
- https://www.pcisecuritystandards.org/faq/articles/Frequently_Asked_Question/is-voip-in-scope-for-pci-dss/
- Published
- 2012-10-01
- Updated
- unknown
- Accessed
- 2026-09-30
- HTTP status
- 200
- License
- PCI SSC website terms; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- For business-to-business VoIP carrying card data across multiple carriers, the traffic is in the entity's scope only while it is on the entity's infrastructure. in context
- For VoIP between a cardholder and an entity, the entity's systems are in scope but securing the transmission outside the entity's infrastructure is not, because the entity cannot control how the cardholder places calls. in context
- Inbound VoIP traffic from an external source is not in the entity's PCI DSS scope until it reaches the entity's infrastructure. in context
- VoIP traffic that carries payment card account data is in scope for applicable PCI DSS controls wherever it is stored, processed or transmitted on the entity's own network. in context
Cite this source record
APA
WarmTransfer. (2012, October 1). FAQ 1153: How does PCI DSS apply to VoIP?. WarmTransfer. https://warmtransfer.net/knowledge/sources/pcissc-faq-1153-voip-scope
BibTeX
@misc{warmtransfer-pcissc-faq-1153-voip-scope,
title = {FAQ 1153: How does PCI DSS apply to VoIP?},
author = {{WarmTransfer}},
year = {2012},
url = {https://warmtransfer.net/knowledge/sources/pcissc-faq-1153-voip-scope},
note = {PCI Security Standards Council, accessed 2026-09-30}
}