Get Demo
↑

What Is the Cardholder Data Environment (CDE)? PCI DSS Scoping Guide

PCI DSS CDE and scoping - glossary CDE definition, connected-to and security-impacting systems, annual scope confirmation, and flat-network risk.

Published: September 2026 Compliance · PCI DSS 8-12 min read

Per the PCI SSC Glossary, the cardholder data environment (CDE) comprises (1) system components, people, and processes that store, process, or transmit CHD and/or SAD, and (2) system components that may not store, process, or transmit CHD/SAD but have unrestricted connectivity to systems that do. PCI DSS applies to system components included in or connected to the CDE, and to environments that can impact CHD/SAD security - including some outsourced models.

Related: Scope reduction · Segmentation testing · SAQ types · Requirement 1 · Merchants vs service providers.

Gotcha: Best practice from PCI SSC Scoping Guidance: assume everything is in scope until verified otherwise. In a flat network, if any system stores, processes, or transmits account data, the entire network is in scope. Separate VLANs alone are not segmentation.

Scoping Categories

Illustrative categories from the Scoping and Network Segmentation Guidance:

  1. CDE systems - store, process, or transmit account data (or have unrestricted connectivity as defined in the glossary)
  2. Connected-to and/or security-impacting systems - have a path to the CDE or can impact CDE security (for example authentication servers, jump hosts, or network security controls managing the CDE)
  3. Out of scope - must meet all out-of-scope criteria and none of the higher categories; cannot impact CDE security even if compromised

Annual Scope Confirmation

At least annually and before assessment, the entity confirms scope (all CHD locations and flows; systems connected to the CDE or that could impact the CDE if compromised) and retains documentation. The assessor validates that scope was accurately defined. The entity keeps scope accurate on an ongoing basis.

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across scoping, cloud, and SAQ/ROC validation paths.

Frequently Asked Questions

Is encryption enough to take a system out of scope?

Encrypted CHD that coexists with keys, or is accessible to an entity that also has the keys, generally remains in scope considerations per PCI DSS encrypted-data notes. Tokenization, P2PE, and outsourcing are separate strategies - see the scope reduction guide.

Are people "in the CDE" for segmentation?

People who handle CHD are part of the CDE conceptually. Scoping Guidance notes people need not be physically segmented from non-CDE people if access controls enforce CDE-only access.

Who confirms scope - us or the QSA?

You define and document annually; the assessor validates the definition for the assessment.

Scope reduction · Segmentation testing · SAQ types · Requirement 1 · Merchants vs service providers

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!