CloudCompliance

PCI DSS in the cloud

The cheapest PCI DSS project in the cloud is the one where card data never touches your account. A hosted payment page or tokenization drops you to a short self-assessment. Everything else is a scoping exercise.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Under PCI DSS v4.0.1, the cloud provider's attestation covers its physical and platform layers. Everything in your account that stores, processes or transmits cardholder data, or can affect its security, is in your scope. The first decision is whether card data needs to enter your cloud at all. With a hosted payment page or iframe from your payment provider, most SaaS companies fill in SAQ A or SAQ A-EP instead of a full assessment.

How payment architecture changes PCI DSS scope
ArchitectureTypical validationCloud controls in scope
Redirect or iframe to payment providerSAQ AThe pages that host the redirect or iframe, and their scripts
Direct post or JavaScript collecting card data to providerSAQ A-EPThe web servers and scripts on the payment page, more requirements
Card data passes through your APISAQ D or a QSA assessmentEvery system in the cardholder data environment and connected systems

Since March 2025, requirements 6.4.3 and 11.6.1 apply to payment pages: inventory and authorize every script on the page, and detect unauthorized changes. SAQ A merchants have specific eligibility conditions for these; confirm with your acquirer.

What the provider's attestation covers

AWS, Azure and Google Cloud each hold a PCI DSS attestation of compliance as a service provider for listed services. Download it and the responsibility matrix. Your assessor will rely on it for physical security, hypervisor and managed service internals, and test your configuration.

If card data enters your cloud

  • Isolate the cardholder data environment in its own account or subscription.
  • Segmentation testing: annually for merchants, every six months for service providers, under requirement 11.4.5 and 11.4.6.
  • Logging: twelve months retained, three months immediately available (requirement 10.5.1).
  • MFA for all access into the cardholder data environment (requirement 8.4.2).
  • Encryption of stored account data and strong cryptography in transit.
  • Vulnerability scans: quarterly internal, and quarterly external by an Approved Scanning Vendor.

GetAudited covers PCI DSS for Canadian companies in general, and TrazTech's PCI DSS for SaaS page covers the SaaS-specific scoping.

Is AWS PCI compliant?

AWS is a PCI DSS Level 1 service provider for listed services, and its attestation is available in AWS Artifact. That covers AWS's responsibilities. You still validate your own compliance for what you build.

Does using Stripe or another payment provider remove PCI DSS?

It reduces scope a great deal but does not remove it. You still complete the relevant self-assessment questionnaire, usually SAQ A, and manage the pages and scripts that load the payment form.

Working out your PCI scope?

Firms in the network scope cardholder environments and prepare SAQs.

Get matched