PCI DSS 12.5.3 (service providers): Significant changes to organizational structure result in a documented (internal) review
PCI DSS v4.0.1 control 12.5.3: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 12.5.
Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.5
Additional requirement for service providers only: Significant changes to organizational structure result in a documented (internal) review of the impact to PCI DSS scope and applicability of controls, with results communicated to executive management.
Summary
Service providers only: when the shape of the organisation changes, review what that does to PCI DSS scope, write it down, and tell executive management.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 12.5.3.a | Additional testing procedure for service provider assessments only: Examine policies and procedures to verify that processes are defined such that a significant change to organizational structure results in documented review of the impact to PCI DSS scope and applicability of controls. |
| 12.5.3.b | Additional testing procedure for service provider assessments only: Examine documentation (for example, meeting minutes) and interview responsible personnel to verify that significant changes to organizational structure resulted in documented reviews that included all elements specified in this requirement, with results communicated to executive management. |
Service providers only. The trigger here is organisational change, not technical change, which is what separates it from 12.5.2, where the scope review is annual and on significant changes to the environment. An acquisition, a merger, a reorganisation, outsourcing a function, or moving a team under different management can all change scope without a single system changing. The last element is a separate test and the one most often missing: results communicated to executive management. A thorough review that stayed inside the security team does not satisfy it.
What to prepare
- The documented process, showing which organisational changes trigger a review.
- The reviews themselves for any structural change since the last assessment.
- Evidence the results reached executive management, such as board or executive meeting minutes.
How to implement it
1. Define what counts as a significant change to organisational structure, in advance. Acquisitions and mergers are obvious. Outsourcing a function, insourcing one, and consolidating two teams under one owner are the ones that get missed.
2. Hook it to the events that already have a process. Corporate development and HR know about these changes before security does, so the trigger belongs in their checklist, not in a security calendar.
3. Do the review as part of deciding, not after integrating. A scope review that arrives once the acquired environment is already connected documents a problem rather than preventing one.
4. Record the communication, not just the review. Minutes naming the item are the cleanest evidence, because the element being tested is that executive management received it.
Where this commonly fails
- Treating an acquisition as an IT integration project, so the scope review happens after the networks are joined.
- A review performed and never presented, failing the element about executive management while satisfying the rest.
- Only counting mergers and acquisitions, so a reorganisation that moved the CDE under a different team goes unreviewed.
- A merchant applying this control to itself, which is effort spent on a requirement that does not apply.
Related controls
Others in section 12.5:
| Control | What it requires |
|---|---|
| 12.5.1 | An inventory of system components that are in scope for PCI DSS… |
| 12.5.2 | PCI DSS scope is documented and confirmed by the entity at least once every 12 months and upon… |
| 12.5.2.1 | Service providers: PCI DSS scope is documented and confirmed by the entity at least once every six months and upon… |
← 12.5.2.1 · All controls · 12.6.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.