
Key takeaway
- Answering “Where does the cardholder data live?” shouldn’t require a diagnostic action. Fintechs need to answer this cleanly to avoid overrunning their budget.
- A vendor’s PCI Attestation of Compliance (AoC) only covers PCI DSS Requirement 9; the others are the customer organization’s responsibility.
- Scope reduction is the simplest way to lower compliance costs. Fintechs that reduce the CDE through tokenization and hosted payment pages will limit the scope of the PCI audit.
Picture this: you’re three weeks into the PCI assessment and the timelines are slipping. The QSA is still trying to establish the scope of the cardholder data environment (CDE). Teams are scrambling to get the answers, which consumes budget you don’t have. Every workstream seeks to answer the same question that should have already been known: “Where does the cardholder data live?”
The ops team is struggling to untangle the scope sprawl in the environment—how it got to this point, which servers, network segments, and boundaries exist, what controls are in place, and in which facilities they’ve been implemented. The assessment has transformed into a sizable effort just to understand the environment’s scope. All questions seem to lead to new questions and compound the problem.
Why the First Question in a PCI Audit Determines Everything
“Where does the cardholder data live?” is a seemingly simple question that should be easily answered. But it’s only possible if you have a defined scope, a maintained data-flow architecture, a current scope document, and a knowledgeable team.
The critical error many organizations make is treating a hosting vendor’s certification as if it were the company’s own compliance posture. When that happens and the answer is not what you thought it was, the audit reveals an undefined sprawl with multiple layers of complexity that are costly to unwind and fix.
What a PCI Facility Attestation of Compliance Actually Covers
A facility-level Attestation of Compliance (AoC) is a formal document issued following a PCI DSS assessment. There are 12 primary requirements in total across 6 control objectives. The customer’s QSA typically performs the assessment and issues a statement that the environment meets all 12 of the applicable PCI DSS requirements.
A colocation or hosting provider can produce evidence that attests that the physical building and its environmental controls meet PCI DSS Requirement 9. This includes areas such as physical access controls, surveillance systems, visitor management, and environmental protections.
The important distinction is that while the provider can deliver Requirement 9, and the QSA can reference this, all the other control objectives and their requirements sit within the customer’s CDE boundary, including network segmentation, server hardening, encryption and key management, access control, logging, vulnerability management, and application-layer controls.
Why “PCI-Compliant Hosting” Creates Audit Problems
We’ve all heard the phrase “PCI-compliant hosting,” which implies that workloads inherit compliance. But they do not. The workloads and anything outside of the Requirement 9 scope for PCI DSS are the customer’s responsibility.
Hivelocity, for example, holds a facility-level AoC for PCI DSS 4.0, with active work underway to extend the validated facility footprint. Those attestations apply to the facility environment. The CDE built on top of that foundation remains subject to the customer’s own PCI DSS assessment.
Why PCI Scope Is the Biggest Cost Lever in Compliance
If the boundary of the CDE scope is large, then more security controls and standards will need to be included in the assessment. A smaller scope for assessment means fewer controls, fewer dependencies, a smaller attack surface, and fewer items on the QSA’s checklist.
A long, drawn-out assessment for a level 1 (typically a merchant transacting over $6M in annual transactions) PCI DSS certification starts at $45,000 and can go over $200,000 for large, complex environments, including remediation and upgrades to fix problems.1
The One PCI Question Every Organization Must Answer
The most important question—where cardholder data actually lives—should not be hard to answer. A well-defined CDE has the foundation of the assessment ready: identifiable systems, documented data flows, established control ownership, and clear boundaries between provider and customer responsibilities.
An ambiguous boundary means the audit must change from validating controls to determining the actual scope. This will incur engineering effort, security changes, and operational disruption as teams work to establish the answers the assessment requires.
FAQ
Q: What is the difference between PCI DSS and an Attestation of Compliance (AoC)?
A: PCI DSS is the security standard organizations must meet when storing, processing, or transmitting cardholder data. An Attestation of Compliance is a formal document showing that a specific assessed environment met applicable PCI DSS requirements within a defined scope.
Q: What does a facility-level PCI AoC cover?
A: A facility-level PCI AoC typically covers physical security controls under PCI DSS Requirement 9, including access controls, surveillance systems, visitor management, and environmental protections within the assessed facility.
Q: Who is responsible for defining PCI DSS scope?
A: The organization that stores, processes, or transmits cardholder data is responsible for defining and maintaining PCI DSS scope. This responsibility cannot be delegated to a hosting provider, colocation provider, or cloud platform.
———-
Citations:
1. Defend My Business, How Much Does PCI Compliance Really Cost? (A Full Breakdown), Oct 2025


