Skip to content
Winslow Compliance Partners
Our position, stated first. Winslow is not a Qualified Security Assessor, so we do not assess, sign Reports on Compliance or certify anybody. We prepare you and also introduce independent QSA firms.

Platform guide

AWS PCI compliance: what Amazon covers, and what stays yours

AWS PCI compliance is shared. Amazon states that it is validated as a PCI DSS Level 1 service provider for in-scope services. However, everything you build and configure on top remains your responsibility.

  • Not a QSA, stated first
  • Introductions to independent QSAs
  • Written answers, no call
Aws pci compliance: get aws evidence, map duties and secure your config

What AWS covers in AWS PCI compliance

AWS covers the physical infrastructure and the services in scope of its assessment. Therefore you can rely on its evidence for that layer. See the AWS PCI DSS FAQs.

What stays yours in AWS PCI compliance

Your configuration is where most findings appear. So focus on these areas.

  • Network design and segmentation of the card environment
  • IAM users, roles and multi-factor
  • Encryption of card data at rest and in transit
  • Logging, monitoring and review
  • Patching of instances and containers

AWS PCI compliance check

Tick what is in place.

Your result appears here as you tick, so you can see what is still open.

Getting AWS PCI compliance evidence

AWS publishes its PCI attestation and responsibility guidance through AWS Artifact. Also, your assessor will want to see that the services you use are in scope.

EvidenceWhere it comes from
AWS attestationAWS Artifact.
Service scope listAWS compliance pages.
Your controlsYour own configuration and records.

Common AWS PCI compliance mistakes

A frequent mistake is a flat network where card systems share security groups with everything else. Therefore the whole account falls into scope. Another is broad IAM roles, which make access hard to justify.

Separate accounts for the card environment often solve both. As a result, scope shrinks and access becomes easier to explain.

Where we help

We design segmentation, map shared duties and prepare evidence. However, we are not a QSA, and we are not affiliated with AWS. The standard is in the PCI SSC document library.

Also tag resources that belong to the card environment. Tags make scope visible in billing, monitoring and access reviews, so it becomes easier to show an assessor exactly what is in scope and what is not.

AWS PCI compliance questions

Does AWS PCI compliance make our workload compliant?

No. It covers AWS's layer, while your configuration is assessed separately.

Where do we get the AWS attestation?

Through AWS Artifact in your account.

Are all services in scope for AWS PCI compliance?

No, so check the current list before using a service for card data.

Are you affiliated with AWS?

No. We are independent.

Related guides

Design your AWS card environment properly

Tell us your AWS setup. We reply in writing with gaps and a budget range.

Ask us anything