PCI DSS 12.8.3: An established process is implemented for engaging TPSPs
PCI DSS v4.0.1 control 12.8.3: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 12.8.
Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.8
An established process is implemented for engaging TPSPs, including proper due diligence prior to engagement.
Summary
Have a process for taking on a third-party service provider, and do the due diligence before you engage them rather than after.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 12.8.3.a | Examine policies and procedures to verify that processes are defined for engaging TPSPs, including proper due diligence prior to engagement. |
| 12.8.3.b | Examine evidence and interview responsible personnel to verify the process for engaging TPSPs includes proper due diligence prior to engagement. |
This is the only control in 12.8 that happens before the relationship exists. 12.8.1 is the list, 12.8.2 is the written agreement, 12.8.3 is what you do before signing it, 12.8.4 is monitoring their compliance status afterwards, and 12.8.5 is who is responsible for which requirement. Both procedures test that due diligence is prior to engagement, so evidence gathered at the first annual review is evidence of 12.8.4 and not of this control. The practical difficulty is rarely the process. It is that providers are engaged by people who do not know the process exists.
What to prepare
- The documented engagement process, showing due diligence as a step before contract signature.
- Completed due diligence for providers taken on since the last assessment, dated before the engagement date.
- What due diligence consists of for you: attestation of compliance, responsibility matrix, security questionnaire, references.
How to implement it
1. Put the check where the money is approved. Procurement and finance are the reliable choke points. A process that lives only in the security team is bypassed by every provider onboarded on a corporate card.
2. Ask for the attestation of compliance before signing, and read it. Check the version, the date, and that the services listed are the services you are buying. An attestation that covers a different product line is common and is worth nothing.
3. Scale the diligence to the exposure. A provider that stores account data and one that supplies a script to your payment page warrant different depth, and saying so in the process keeps it usable.
4. Date everything. The element being tested is that this happened first, so an undated questionnaire cannot prove the one thing it needs to prove.
Where this commonly fails
- Due diligence performed at the first annual review, which evidences monitoring and not engagement.
- Providers onboarded directly by a business team, so the process was followed for the ones procurement knew about and no others.
- Collecting an attestation of compliance without checking it covers the service being purchased.
- A process that exists in policy with no completed example, because every current provider predates it.
Related controls
Others in section 12.8:
| Control | What it requires |
|---|---|
| 12.8.1 | A list of all third-party service providers (TPSPs) with which account data is shared… |
| 12.8.2 | Written agreements with TPSPs are maintained… |
| 12.8.4 | A program is implemented to monitor TPSPs’ PCI DSS compliance status at least once every 12… |
| 12.8.5 | Information is maintained about which PCI DSS requirements are managed by each TPSP… |
← 12.8.2 · All controls · 12.8.4 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.