Sunday, 13 September 2026
Nigeria Communications Week
E-Business

PCI SSC Releases New Measures for Third-party Security Assurance

Comms Week13 Aug 20140 Comments
PCI SSC Releases New Measures for Third-party Security Assurance
Kindly share this post

In response to the third-party threat, the PCI Security Standards Council has published a guide to help organizations and their business partners reduce risk by better understanding their respective…


In response to the third-party threat, the PCI Security Standards Council has published a guide to help organizations and their business partners reduce risk by better understanding their respective roles in securing card data.

Developed by a PCI Special Interest Group — including merchants, banks and third-party service providers — the document provides recommendations for meeting PCI Data Security Standard requirement 12.8 to ensure that payment data and systems entrusted to third parties are maintained in a secure and compliant manner.

The Third-Party Security Assurance Information Supplement provides guidance practical recommendations to help businesses and their partners protect data, including:

•Conduct due diligence and risk assessment when engaging third party service providers to help organizations understand the services provided and how PCI DSS requirements will be met for those services.

•Implement a consistent process for engaging third-parties that includes setting expectations, establishing a communication plan, and mapping third-party services and responsibilities to applicable PCI DSS requirements.

•Develop appropriate agreements, policies and procedures with third-party service providers that include considerations for the most common issues that arise in this type of relationship.

•Implement an ongoing process for maintaining and managing third-party relationships throughout the lifetime of the engagement, including the development of a robust monitoring program.

The guidance includes high-level suggestions and discussion points for clarifying how responsibilities for PCI DSS requirements may be shared between an entity and its third-party service provider, as well as a sample PCI DSS responsibility matrix that can assist in determining who will be responsible for each specific control area. 


As part of its initial proposal, the group also made specific recommendations that were incorporated into PCI DSS requirements 12.8 and 12.9 in version 3.0 of the standard.

“One of the big focus areas in PCI DSS 3.0 is security as a shared responsibility. This guidance is an excellent companion document to the standard in helping merchants and their business partners work together to protect consumers’ valuable payment information,” said Bob Russo, PCI SSC General Manager.

The Third-Party Security Assurance Information Supplement is available for download at the PCI SSC website.

As with all PCI Council information supplements, the guidance provided in this document is supplemental and does not supersede or replace any PCI DSS requirements.

C
Published by

Comms Week

Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

More in E-Business
E-Business

What Dollar Strength Cycle Mean for Traders

By Ugo Onwuaso21 Aug 2026

The USD still ranks among the major forces that drive financial markets all over the world. When the USD gains in value, it rarely affects currency pairs alone; it may have implications for commodities, stock market indices, capital movement, and risk appetite.