Insight
Azure PCI compliance: what Microsoft covers, and what stays yours
Azure PCI compliance starts with a simple fact: Microsoft validates its platform, but not your workloads. So the services you choose and how you configure them decide your result.
- Not a QSA, stated first
- Introductions to independent QSAs
- Written answers, no call
How Azure PCI compliance responsibility splits
Cloud security is shared. Microsoft protects the physical data centres and core infrastructure. However, you protect your configuration, identities and data.
| Layer | Usually responsible |
|---|---|
| Physical data centres | Microsoft |
| Platform services in scope | Microsoft, per its attestation |
| Network rules and identities | You |
| Application and data | You |
Where to find Azure PCI compliance evidence
Microsoft publishes its attestation through its trust documentation. Also, it lists which services are in scope. Therefore check that every service you use appears there.
Your QSA will ask for this evidence. So download it early and note its date.
Azure PCI compliance check
Tick what you can show your assessor.
Your result appears here as you tick, so you can see what is still open.
Customer tasks in Azure PCI compliance
Most findings come from configuration. For example, an overly broad role or an open storage account.
- Network segmentation around card data workloads
- Least-privilege access and MFA
- Logging and monitoring
- Encryption key management
- Vulnerability scanning and testing
Reducing scope in Azure
Keep card data in a small, separate environment. Also use a provider's hosted payment page where possible, because then card data may never reach Azure at all.
In addition, document data flows clearly, because assessors need to see where card data travels.
Where Winslow helps
We review configuration, scope and evidence before assessment. We are not a QSA. Gap analysis generally runs $8,000 to $40,000. Microsoft's material is on the Microsoft Azure PCI DSS documentation page.
Also review policies and tagging. For example, Azure Policy can flag resources that drift from your baseline, so problems surface early. In addition, tag every resource in the card data environment, because clear tags make scoping and evidence much easier. As a result, the assessor sees a tidy, well-defined environment rather than a sprawling subscription.
Azure PCI compliance questions
Does Azure PCI compliance make us compliant?
No. It covers Microsoft's share, while your configuration remains yours.
Where is Microsoft's Azure PCI compliance attestation?
In Microsoft's trust documentation, alongside the list of services in scope.
Can serverless services help Azure PCI compliance?
They can reduce what you manage, but you still configure access and data protection.
Do we need our own testing?
Yes. Scanning and penetration testing of your environment remain your responsibility.
Related guides
Review your Azure PCI compliance position
Describe your Azure setup. We reply in writing, usually within one business day.
Ask us anything