Talk With an Expert

Contracting for PCI DSS Compliance

Contracting for PCI DSS Compliance (PDF, 2.43MB)Published: 15 Jul, 2010
Created by
Christian Moldes

PCI DSS Requirement 12.8.2 states that companies should maintain a written agreement with service providers that are responsible for the security of cardholder data the service provider possesses. Many people consider this requirement unnecessary or less important than most of the requirements. However, misunderstanding of this requirement may expose a company to serious liability. This paper intends to identify most of the risks a company may face when dealing with service providers. This paper provides sample clauses that an agreement should have in order to protect a company when dealing with other companies' cardholder data.