Is the Applicant PCI-DSS compliant, and at what merchant level?
The merchant level comes from your annual transaction volume, and the compliance answer comes from a specific document. Both are checkable.
What the carrier is actually asking
The carrier is asking whether you meet the Payment Card Industry Data Security Standard and at which merchant level, which is determined by annual card transaction volume. Level one requires an assessment by a qualified assessor; lower levels use a self-assessment questionnaire.
Why it is underwritten
Card brand fines and assessments following a breach flow through the acquiring bank to the merchant, and they are a distinct head of loss from notification and business interruption. Non-compliance at the time of a breach increases those assessments substantially, and many policies treat fines and penalties differently depending on compliance status.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Compliance status is evidenced by your attestation of compliance or completed questionnaire. Insurance Posture does not assess PCI scope, so this is attested.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Compliance documents | Attestation of compliance or self-assessment questionnaire, with its date and version | Current, signed, and covering the right questionnaire type for how you handle cards |
| Acquirer | Merchant level as determined by your acquiring bank | The level your acquirer applies, since it is their determination rather than your estimate |
| Payment flow | Whether card data enters your environment at all | A hosted or redirected payment page reduces scope dramatically and changes which questionnaire applies |
| Scope documentation | The cardholder data environment boundary and its segmentation | Documented scope, since scope creep is the most common cause of an invalid attestation |
| Service providers | Attestations from payment processors and any provider in the flow | Current attestations on file from every provider that touches card data on your behalf |
If cards are handled entirely by a hosted payment provider and no card data enters your systems, say so explicitly and name the questionnaire type. It is a materially better position than in-scope compliance, and it is often understated because the form does not offer a field for it.
What a defensible yes requires
- A current attestation or questionnaire exists, signed and dated within the last year.
- The merchant level matches your acquirer's determination.
- The scope boundary is documented and matches how payments actually flow.
- Service provider attestations are collected and current.
- Where card handling is fully outsourced, that is stated plainly rather than left implicit.
How this answer goes wrong
The questionnaire was completed for a payment flow that has since changed, most often because a new channel was added: a phone order taken on a headset, a saved card in a customer service tool, an email containing card details. Any of those pull systems back into scope that the assessment excluded.
Frequently asked
What if we do not take card payments?
Answer not applicable and say why. It removes a whole category of exposure from the submission, and it is worth being explicit rather than leaving the field blank.
Does using a hosted payment page make us compliant?
It reduces scope significantly and does not remove the obligation entirely; a shorter questionnaire still applies. It is a strong answer when described accurately.
Are PCI fines covered by cyber insurance?
Sometimes, often sub-limited, and frequently conditioned on compliance at the time of the breach. This answer therefore interacts directly with a coverage term worth reading.
How current does the attestation need to be?
Annual. An attestation more than a year old is not current, and a claims review will check the date against the incident.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture