Skip to content
Winslow Compliance Partners
Our position, stated first. Winslow is not a Qualified Security Assessor, so we do not assess, sign Reports on Compliance or certify anybody. We prepare you and also introduce independent QSA firms.

Insight

How to check if a company is pci compliant before you trust it

Before a vendor touches your card data, check if a company is pci compliant with evidence, not a sales claim. So ask for documents and read them properly.

  • Not a QSA, stated first
  • Introductions to independent QSAs
  • Written answers, no call
Check if a company is pci compliant: ask for the aoc, read scope and date and check registries

Why you should check if a company is pci compliant

Your own compliance depends partly on your providers. Therefore PCI DSS asks merchants to monitor the status of service providers at least annually.

A logo on a website proves little. However, a current attestation tells you what was assessed and when.

Five steps to check if a company is pci compliant

Work through the steps in order. Also keep copies, because your own assessor will ask for them.

  • Ask for the Attestation of Compliance for service providers
  • Check the date, since attestations are annual
  • Confirm the services you buy are in its scope
  • Ask which requirements they manage for you
  • Check card brand registries where relevant

Provider evidence check

Tick what you hold for each provider.

Your result appears here as you tick, so you can see what is still open.

Reading the attestation when you check if a company is pci compliant

The attestation summarises the assessment. For example, it names the assessor and the services covered.

FieldWhat to look for
Assessment dateWithin the last 12 months
Services coveredIncludes what you actually use
AssessorA named QSA company, for larger providers
Compliance statusCompliant, not partially compliant

Red flags

Watch for vague answers. For example, a vendor that only sends a badge or a certificate from a scanning tool. Also be wary of attestations covering a different legal entity or service.

In addition, an expired attestation means the evidence is missing, even if the company is still secure.

Where Winslow helps

We review provider evidence and build your monitoring routine. We are not a QSA. Card brand listings include the Visa Global Registry of Service Providers.

Also file the evidence with a renewal date. So the annual recheck happens on time rather than when someone remembers.

Questions on how to check if a company is pci compliant

What document proves a provider's status?

The Attestation of Compliance for service providers is the standard evidence.

Can I check if a company is pci compliant online?

Card brand registries help, but always ask for the attestation too.

How often should we check if a company is pci compliant?

At least annually, and when you add services.

Is a scan certificate enough?

No. A scan covers one requirement only.

Related guides

Need help to check if a company is pci compliant?

Send the provider evidence you hold. We reply in writing, usually within one business day.

Ask us anything