# Payment Card Industry Digital Security Standard (PCI DSS) Compliance

SOC reports offer a confirmation of services provided by a service organization including information that users need to assess and address the risks associated with an outsourced service. They are designed to help Information Technology service organizations build trust and confidence in their service delivery processes and controls through a report by an independent Certified Public Accountant.

Source: https://expedient.com/services/managed-services/compliance-security/pci-dss/

# Payment Card Industry Digital Security Standard (PCI DSS) Compliance

#### What is PCI DSS Compliance?

The Payment Card Industry (PCI) Security Standards Council (SSC) is an industry forum for the ongoing management of security standards for account data protection. The PCI Data Security Standard (DSS) provides an actionable framework for developing a robust payment card security process – including prevention, detection and appropriate reaction to security incidents.

#### Ensuring PCI DSS compliance for your organization

Organizations handling credit card account data – including merchants and processors – are required to be compliant with PCI DSS. Some organizations are additionally required to validate compliance through a third-party audit of the following requirements:

**Build and Maintain a Secure Network**

- Requirement 1: Install and Maintain Network Security Controls
- Requirement 2: Apply Secure Configurations to All System Components

**Protect Account Data**

- Requirement 3: Protect Stored Account Data
- Requirement 4: Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks

**Maintain a Vulnerability Management Program**

- Requirement 5: Protect All Systems and Networks from Malicious Software
- Requirement 6: Develop and Maintain Secure Systems and Software

**Implement Strong Access Control Measures**

- Requirement 7: Restrict Access to System Components and Cardholder Data by Business Need to Know
- Requirement 8: Identify Users and Authenticate Access to System Components
- Requirement 9: Restrict Physical Access to Cardholder Data

**Regularly Monitor and Test Networks**

- Requirement 10: Log and Monitor All Access to System Components and Cardholder Data
- Requirement 11: Test Security of Systems and Networks Regularly

**Maintain an Information Security Policy**

- Requirement 12: Support Information Security with Organizational Policies and Programs

#### Expedient is your managed services data center provider for PCI DSS compliance.

In addition to a wide range of complementary managed data center services, Expedient can assist with the PCI DSS compliance process by providing the following documentation offering written assurances:

- Service Organization Control (SOC) 1 Report (aka SSAE-18)
- Service Organization Control (SOC) 2 (availability, confidentiality & security) + Health Information Trust (HITRUST) Report
- Attestation of Compliance (AOC) for Report on Compliance (ROC)
- [Visa Global Registry of PCI DSS Compliant Service Providers Listing](https://www.visa.com/splisting/viewSPDetail.do?spId=1972&coName=Expedient&HeadCountryList=UNITED%20STATES%20OF%20AMERICA&reset=yes&pageInfo=1%3B30%3BASC%3BcoName)

Hosting with Expedient doesn’t exclusively make an organization compliant with PCI, however, it does reduce the time and expense associated with many of the requirements.

More information about PCI DSS is available from the [SSC](https://www.pcisecuritystandards.org/).

### Other Attestations
[Cloud Security Alliance Security, Trust & Assurance Registry (CSA STAR) Program](https://cloudsecurityalliance.org/star/registry/expedient/)[EU-U.S. Privacy Shield](/services/managed-services/compliance-security/privacy-framework/)[Health Insurance Portability and Accountability Act (HIPAA) Compliance](/services/managed-services/compliance-security/hipaa/)[Service Organization Control (SOC) Reporting](/services/managed-services/compliance-security/soc-reports/)

## The best of Expedient delivered to your inbox.

Sign up for more technical briefs, stories, and special offers from Expedient.

Submit →

VMware

September 29th, 2026 at 1:00 PM ET
## It’s Time to Decide Your VMware Path

[Join us →](https://go.expedient.com/VMWarePath)

### VMware

September 29th, 2026 at 1:00 PM ET
## It’s Time to Decide Your VMware Path

[Join us →](https://go.expedient.com/VMWarePath)
