PCI DSS 12.5.2.1 (service providers): PCI DSS scope is documented and confirmed by the entity at least once every six months and upon

PCI DSS v4.0.1 control 12.5.2.1: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 12.5.

Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.5

Additional requirement for service providers only: PCI DSS scope is documented and confirmed by the entity at least once every six months and upon significant change to the in-scope environment. At a minimum, the scoping validation includes all the elements specified in Requirement 12.5.2.

Summary

Service providers: confirm the scope every six months, not every twelve.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
12.5.2.1.a Additional testing procedure for service provider assessments only: Examine documented results of scope reviews and interview personnel to verify that reviews per Requirement
12.5.2.1.b Additional testing procedure for service provider assessments only: Examine documented results of scope reviews to verify that scoping validation includes all elements specified in Requirement 12.5.2.

Identical in substance to 12.5.2 with one difference that is the whole control: at least once every six months rather than annually, plus on significant change. It is one of the semi-annual cadences entities schedule yearly out of habit, alongside 1.2.7 and 11.4.6, and a scope validation performed once in the year fails on frequency however thorough it is. The reason for the shorter cycle is worth stating: a service provider's scope changes when its customers change, which happens continuously and without any internal project to prompt a review. The scoping validation must include all the elements specified in 12.5.2, so this control adds a cadence and inherits the substance.

What to prepare

  • The last two scope validations, dated, so the interval is visible.
  • The elements from 12.5.2, covered in each.
  • Significant changes to the in-scope environment, with a validation after each.
  • Customer onboarding and offboarding, as a trigger.

How to implement it

1. Schedule both with fixed dates at the start of the year. Two validations in the same half meet the count and not the interval.

2. Treat customer change as a scope trigger. New customers, new services and offboarding all change what is in scope, and none of them is an internal project.

3. Read 12.5.2 for the substance. Everything there applies; this control only changes when.

4. Confirm you are a service provider for this purpose, since entities handling account data for others often do not think of themselves that way.

Where this commonly fails

  • Annual validation carried over from a merchant-shaped programme.
  • Both validations in the same half of the year.
  • Customer changes not treated as significant changes to the in-scope environment.
  • The cadence met while the 12.5.2 elements are only partly covered.

This control refers to 12.5.2.

Others in section 12.5:

Control What it requires
12.5.1 An inventory of system components that are in scope for PCI DSS…
12.5.2 PCI DSS scope is documented and confirmed by the entity at least once every 12 months and upon…
12.5.3 Service providers: Significant changes to organizational structure result in a documented (internal) review…

12.5.2 · All controls · 12.5.3

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.