Get Demo
↑

PCI DSS on AWS: Shared Responsibility and Compliant Architecture

PCI DSS on AWS - Level 1 service provider validation, Artifact.

Published: September 2026 Compliance · PCI DSS 8-12 min read

AWS states it is certified as a PCI DSS Level 1 Service Provider. Packages (Attestation of Compliance plus Responsibility Summary) are available via AWS Artifact. AWS compliance materials emphasize: customers must manage their own PCI DSS certification; AWS does not directly store, transmit, or process customer CHD, but customers may build a CDE on AWS that does.

Related: CDE scoping · Scope reduction · PCI on Azure · SAQ D · Merchants vs service providers.

Gotcha: Additional testing is required to verify your environment meets all PCI DSS requirements. For the portion of the CDE deployed on AWS, a QSA can rely on the AWS AOC without further testing of that AWS-provided portion - that is not a free pass for customer-configured operating systems, applications, IAM, logging, or data flows. Use only services in scope for PCI DSS. Consult the Artifact Responsibility Summary for control-by-control ownership - do not invent a matrix from marketing copy.

Shared Responsibility in Practice

Architecture Cues

Define customer PCI DSS scope; maintain network and data-flow diagrams and inventories; segment CDE VPCs or accounts; and treat AWS's validation as coverage of the AWS layer only. Prefer the live Artifact documents over third-party summaries when preparing for a QSA.

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across scoping, cloud, and SAQ/ROC validation paths.

Frequently Asked Questions

Does deploying on AWS make us PCI compliant?

No. AWS's validation covers AWS's scope. You remain responsible for your CDE configuration, applications, and validation.

Must our QSA tour AWS data centers?

Per AWS FAQ guidance, the AOC covers physical security assessment of AWS data centers; a merchant QSA generally need not re-verify AWS data center physical security.

Is every AWS service PCI DSS in scope?

No. Check the current Services in Scope list and design the CDE only on validated services for the controls you intend to inherit.

CDE scoping · Scope reduction · PCI on Azure · Requirement 10 · Requirement 11 · Merchants vs service providers

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!