Diff: FAQ #1221

Do shared hosting providers need to comply with PCI DSS?

Earlier Version
2008-12-29 00:00:00 UTC
Later Version
2014-05-28 00:00:00 UTC
Removed
Added
PCI DSS requirement 2.4 and a6 and Appendix A: ?Additional PCI DSS Requirements for Shared Hosting Providers? is applicabilityle to all shared hosting providers whose customers store, process, or transmit cardholder data. A shared hosting provider is one that houses multiple customers on the same server. These requirements for shared hosting providers? is are not applicable to all shared hostwhen servers are dedicated to a sing providers whose customers store, process, or transmit cardholder data. A shared hosting provider is one that houses numerous customers on the same server. These requirements for shared hosting providers are not applicable when servers are dedicated to ale customer (but otherall other applicable PCI DSS requirements do apply).

To determine the relevantapplicable PCI DSS requirements for a given shared hosting provider, please contact a Qualified Security Assessor (QSA). The list of QSAs can be found at
https://www.pcisecuritystandards.org/approved_companies_providers/qsa_companies.php

(Note: PCI DSS Requirement numbers refer to PCI DSS version 3)