Skip to content
Winslow Compliance Partners
Our position, stated first. Winslow is not a Qualified Security Assessor, so we do not assess, sign Reports on Compliance or certify anybody. We prepare you and also introduce independent QSA firms.

Insight

Azure PCI compliance: what Microsoft covers, and what stays yours

Azure PCI compliance starts with a simple fact: Microsoft validates its platform, but not your workloads. So the services you choose and how you configure them decide your result.

  • Not a QSA, stated first
  • Introductions to independent QSAs
  • Written answers, no call
Azure pci compliance: read the attestation, configure your share and prove it

How Azure PCI compliance responsibility splits

Cloud security is shared. Microsoft protects the physical data centres and core infrastructure. However, you protect your configuration, identities and data.

LayerUsually responsible
Physical data centresMicrosoft
Platform services in scopeMicrosoft, per its attestation
Network rules and identitiesYou
Application and dataYou

Where to find Azure PCI compliance evidence

Microsoft publishes its attestation through its trust documentation. Also, it lists which services are in scope. Therefore check that every service you use appears there.

Your QSA will ask for this evidence. So download it early and note its date.

Azure PCI compliance check

Tick what you can show your assessor.

Your result appears here as you tick, so you can see what is still open.

Customer tasks in Azure PCI compliance

Most findings come from configuration. For example, an overly broad role or an open storage account.

  • Network segmentation around card data workloads
  • Least-privilege access and MFA
  • Logging and monitoring
  • Encryption key management
  • Vulnerability scanning and testing

Reducing scope in Azure

Keep card data in a small, separate environment. Also use a provider's hosted payment page where possible, because then card data may never reach Azure at all.

In addition, document data flows clearly, because assessors need to see where card data travels.

Where Winslow helps

We review configuration, scope and evidence before assessment. We are not a QSA. Gap analysis generally runs $8,000 to $40,000. Microsoft's material is on the Microsoft Azure PCI DSS documentation page.

Also review policies and tagging. For example, Azure Policy can flag resources that drift from your baseline, so problems surface early. In addition, tag every resource in the card data environment, because clear tags make scoping and evidence much easier. As a result, the assessor sees a tidy, well-defined environment rather than a sprawling subscription.

Azure PCI compliance questions

Does Azure PCI compliance make us compliant?

No. It covers Microsoft's share, while your configuration remains yours.

Where is Microsoft's Azure PCI compliance attestation?

In Microsoft's trust documentation, alongside the list of services in scope.

Can serverless services help Azure PCI compliance?

They can reduce what you manage, but you still configure access and data protection.

Do we need our own testing?

Yes. Scanning and penetration testing of your environment remain your responsibility.

Related guides

Review your Azure PCI compliance position

Describe your Azure setup. We reply in writing, usually within one business day.

Ask us anything