Data handling and policy

Is the Applicant PCI-DSS compliant, and at what merchant level?

The merchant level comes from your annual transaction volume, and the compliance answer comes from a specific document. Both are checkable.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether you meet the Payment Card Industry Data Security Standard and at which merchant level, which is determined by annual card transaction volume. Level one requires an assessment by a qualified assessor; lower levels use a self-assessment questionnaire.

Why it is underwritten

Card brand fines and assessments following a breach flow through the acquiring bank to the merchant, and they are a distinct head of loss from notification and business interruption. Non-compliance at the time of a breach increases those assessments substantially, and many policies treat fines and penalties differently depending on compliance status.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Compliance status is evidenced by your attestation of compliance or completed questionnaire. Insurance Posture does not assess PCI scope, so this is attested.

PlatformWhere the setting livesWhat has to be true
Compliance documentsAttestation of compliance or self-assessment questionnaire, with its date and versionCurrent, signed, and covering the right questionnaire type for how you handle cards
AcquirerMerchant level as determined by your acquiring bankThe level your acquirer applies, since it is their determination rather than your estimate
Payment flowWhether card data enters your environment at allA hosted or redirected payment page reduces scope dramatically and changes which questionnaire applies
Scope documentationThe cardholder data environment boundary and its segmentationDocumented scope, since scope creep is the most common cause of an invalid attestation
Service providersAttestations from payment processors and any provider in the flowCurrent attestations on file from every provider that touches card data on your behalf
Outsourcing is the strong answer

If cards are handled entirely by a hosted payment provider and no card data enters your systems, say so explicitly and name the questionnaire type. It is a materially better position than in-scope compliance, and it is often understated because the form does not offer a field for it.

What a defensible yes requires

  • A current attestation or questionnaire exists, signed and dated within the last year.
  • The merchant level matches your acquirer's determination.
  • The scope boundary is documented and matches how payments actually flow.
  • Service provider attestations are collected and current.
  • Where card handling is fully outsourced, that is stated plainly rather than left implicit.

How this answer goes wrong

The questionnaire was completed for a payment flow that has since changed, most often because a new channel was added: a phone order taken on a headset, a saved card in a customer service tool, an email containing card details. Any of those pull systems back into scope that the assessment excluded.

Frequently asked

What if we do not take card payments?

Answer not applicable and say why. It removes a whole category of exposure from the submission, and it is worth being explicit rather than leaving the field blank.

Does using a hosted payment page make us compliant?

It reduces scope significantly and does not remove the obligation entirely; a shorter questionnaire still applies. It is a strong answer when described accurately.

Are PCI fines covered by cyber insurance?

Sometimes, often sub-limited, and frequently conditioned on compliance at the time of the breach. This answer therefore interacts directly with a coverage term worth reading.

How current does the attestation need to be?

Annual. An attestation more than a year old is not current, and a claims review will check the date against the incident.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture