Source record · tier 1 standards and regulators
FAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance?
- Publisher
- PCI Security Standards Council
- URL
- https://pcisecuritystandards.org/faq/articles/Frequently_Asked_Question/what-evidence-is-a-tpsp-expected-to-provide-to-customers-to-demonstrate-pci-dss-compliance
- Published
- 2024-02-01
- Updated
- unknown
- Accessed
- 2026-09-30
- HTTP status
- 200
- License
- PCI SSC website terms; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- A CCaaS vendor's PCI DSS attestation does not by itself make the customer's contact center compliant; the customer keeps the requirements that the vendor's responsibility matrix assigns to it, including how recording, pause and screen capture are configured. inferred in context
- A third-party service provider that has a PCI DSS Attestation of Compliance is expected to give it to customers on request, and customers may also ask for the relevant sections of its ROC or SAQ D for Service Providers. in context
- Under PCI DSS Requirements 12.9.1 and 12.9.2, a TPSP documents which PCI DSS requirements it is responsible for and which are the customer's, typically as a responsibility matrix. in context
- A TPSP's evidence must let the customer verify that the scope of the TPSP's PCI DSS assessment covered the services the customer actually uses. in context
- A TPSP without its own PCI DSS assessment must provide specific evidence for the applicable requirements so the customer or its assessor can confirm they are met. in context
Cite this source record
APA
WarmTransfer. (2024, February 1). FAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance?. WarmTransfer. https://warmtransfer.net/knowledge/sources/pcissc-faq-1576-tpsp-evidence
BibTeX
@misc{warmtransfer-pcissc-faq-1576-tpsp-evidence,
title = {FAQ 1576: What evidence is a TPSP expected to provide to customers to demonstrate PCI DSS compliance?},
author = {{WarmTransfer}},
year = {2024},
url = {https://warmtransfer.net/knowledge/sources/pcissc-faq-1576-tpsp-evidence},
note = {PCI Security Standards Council, accessed 2026-09-30}
}