PCI DSS 12.9.1 (service providers): TPSPs provide written agreements to customers that include acknowledgments that TPSPs

PCI DSS v4.0.1 control 12.9.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.9.

Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.9

Additional requirement for service providers only: TPSPs provide written agreements to customers that include acknowledgments that TPSPs are responsible for the security of account data the TPSP possesses or otherwise stores, processes, or transmits on behalf of the customer, or to the extent that the TPSP could impact the security of the customer’s cardholder data and/or sensitive authentication data.

Summary

Service providers: give customers a written acknowledgement that you are responsible for the account data you hold.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
12.9.1 Additional testing procedure for service provider assessments only: Examine TPSP policies, procedures, and templates used for written agreements to verify processes are defined for the TPSP to provide written acknowledgments to customers in accordance with all elements specified in this requirement.

Service providers only, and it is the mirror image of 12.8.2. That control requires a customer to obtain a written agreement from its providers; this requires the provider to give one. The acknowledgement covers account data the provider possesses or otherwise stores, processes, or transmits on behalf of the customer, and also extends to the extent that the TPSP could impact the security of the customer's cardholder data, which is broader than holding data: a provider that never touches account data but supplies a script to the customer's payment page is within that phrase. The procedure examines policies, procedures and templates used for written agreements, so it is answered by the standard contract rather than by individual negotiations.

What to prepare

  • The standard customer agreement or template containing the acknowledgement.
  • The wording, checked against both halves: data held, and security impacted.
  • Which services fall under each half.
  • Evidence customers receive it.

How to implement it

1. Put it in the standard template, since the procedure examines templates. A clause negotiated per customer is harder to evidence and easy to lose.

2. Cover the impact half, not just the possession half. Services that never touch account data can still affect its security, and the wording names that.

3. Keep it consistent with the responsibility matrix in 12.9.2. Customers use both, and they should not disagree.

4. Review it when services change. A new offering may fall under a clause written for a different one.

Where this commonly fails

  • An acknowledgement covering data held while services that affect security are unaddressed.
  • The clause present in some contracts and absent from the template.
  • Legal wording that disclaims rather than acknowledges responsibility, which is the opposite of the requirement.
  • A merchant applying this, when it is a service provider requirement.

Others in section 12.9:

Control What it requires
12.9.2 Service providers: TPSPs support their customers’ requests for information to meet Requirements 12.8.4 and 12.8.5…

12.8.5 · All controls · 12.9.2

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.