
Short answer: No host makes you PCI compliant on its own. A PCI compliant hosting provider is a third-party service provider whose assessment covers only the services it runs. You still need a written agreement, a responsibility matrix, a current Attestation of Compliance for the services you use, and your own controls above the host's layer.
Related guides:
- AWS PCI DSS compliance: what AWS covers and what you still own
- Everything you need to know about PCI DSS scope
- A deep dive into SAQ types
Key takeaways
- Your host is a third-party service provider (TPSP) under PCI DSS. Its compliance is evidence for your assessment, not a substitute for it.
- PCI DSS v4.0.1 Requirements 12.8.1 to 12.8.5 set out what you must do: list the host, sign a written agreement, do due diligence, check its compliance status at least every 12 months and document who owns which requirements.
- Read the host's Attestation of Compliance (AOC) carefully. The services you buy must be listed as in scope, and the assessment must be current.
- Shared and multi-tenant hosting carries extra risk. Providers in that model must also meet Appendix A1, including penetration testing of tenant separation at least every six months.
- The less of the stack you manage, the more the host owns. But application security, access to your accounts and your own data handling always stay with you.
Does PCI compliant hosting make you PCI compliant?
No. A host's PCI DSS validation covers its own systems and processes, and you are still assessed on yours. The PCI DSS glossary treats a hosting provider as a service provider: a business that stores, processes or transmits cardholder data on behalf of another entity, or that provides services that could affect the security of that data. You can find the glossary at the end of the PCI DSS v4.0.1 standard in the PCI SSC document library.
When a host says it is "PCI compliant", it usually means one of these:
- It has been assessed as a service provider and can give you an AOC for specific services.
- It runs on infrastructure from a provider that has been assessed, but has not been assessed itself.
- It offers features that help with PCI DSS, such as firewalls, TLS certificates or backups, without any formal validation.
Only the first gives your assessor evidence to rely on. The others leave you to prove the host's controls yourself.
PCI DSS v4.0.1, a limited revision published in June 2024, is the current version as of October 2026. The requirements that were future-dated until March 31, 2025 now apply in every assessment, so check that your host's AOC was assessed against them.
What does PCI DSS v4.0.1 require when you use a hosting provider?
Requirement 12.8 requires you to manage every TPSP that holds account data or could affect its security, and that includes your host. The five sub-requirements in PCI DSS v4.0.1 are:
| Requirement | What it asks of you | What it looks like for a host |
|---|---|---|
| 12.8.1 | Maintain a list of TPSPs with a description of the services each provides | Your host and the specific products you use |
| 12.8.2 | Keep written agreements in which TPSPs acknowledge responsibility for the security of account data they handle or could affect | A contract clause or addendum, not a marketing page |
| 12.8.3 | Follow an established process, including due diligence, before engaging a TPSP | A record that you reviewed the AOC and responsibility split before moving card data there |
| 12.8.4 | Monitor each TPSP's PCI DSS compliance status at least once every 12 months | Request the new AOC every year and confirm your services are still covered |
| 12.8.5 | Maintain information about which requirements the TPSP manages, which you manage and which are shared | A responsibility matrix, ideally the host's own |
Hosts that are service providers have matching duties of their own under Requirement 12.9. Under 12.9.1 they must acknowledge in writing to customers that they are responsible for the security of account data they handle or could affect. Under 12.9.2 they must, on request, give customers the compliance status information and responsibility details needed to meet 12.8.4 and 12.8.5. A host that will not provide either is a red flag.
A host that has not been assessed can still be used, but it is then typically included in your own assessment. The Council's FAQ on what evidence a TPSP is expected to provide to customers covers the options. The PCI SSC Third-Party Security Assurance information supplement gives practical guidance on due diligence, agreements and responsibility matrices, but it dates from 2016 (PCI DSS v3.x), so check requirement numbers against v4.0.1.
For how this fits a wider vendor program, see our guide to PCI DSS third-party risk management requirements.
How do you check a host's Attestation of Compliance?
Check that the services you use are in scope, that the assessment is current, and that the status is compliant. A "PCI Level 1" badge is not evidence. The AOC is.
- Ask for the service provider AOC. It is the formal, signed summary of the host's assessment.
- Check the services in scope. The AOC has a scope verification section listing services that were included in the assessment and services that were not. If your backup service or control panel is "not included", its controls are not covered.
- Check the locations. Confirm the data centers or regions you use are within the assessed facilities.
- Check the dates. Note when the assessment was completed and diarise the renewal for your 12.8.4 review.
- Check the version and status. Expect a v4.x form and a compliant status. Anything else needs a conversation with your assessor.
- Match it to the responsibility matrix, then file both. Requirements not tested at the host level usually land on you.
Who is responsible for what in each hosting model?
The more of the stack you manage, the more PCI DSS requirements you own. This is a general pattern; your host's own matrix is the source of truth.
| Area | Shared hosting | VPS or dedicated server | Managed hosting | IaaS | PaaS |
|---|---|---|---|---|---|
| Physical security of data centers | Host | Host | Host | Host | Host |
| Network and firewall rules | Host | Shared | Mostly host | You | Mostly host |
| Operating system hardening and patching | Host | You | Host | You | Host |
| Web server, runtime and database configuration | Host | You | Shared | You | Shared |
| Your application code and payment page scripts | You | You | You | You | You |
| Your accounts, MFA and console access | You | You | Shared | You | You |
| Logging and log review | Host, little visibility for you | You | Shared | You | Shared |
| Vulnerability scans and penetration tests | Host platform, you for your site | You | Shared | You | You for your app |
| Encryption of stored account data and keys | Limited control | You | Shared | You | Shared |
| Policies, training and incident response | Both | Both | Both | Both | Both |
If you are building on AWS, the AWS guide linked at the top of this post covers that provider's shared responsibility model in detail.
Is shared hosting OK for PCI DSS?
Shared hosting is risky for anything in the cardholder data environment, and in our experience most teams are better off avoiding it there. Other customers' sites run alongside yours, and a compromise of a neighbour or of the shared platform can reach your data.
PCI DSS addresses this with Appendix A1: Additional PCI DSS Requirements for Multi-Tenant Service Providers in PCI DSS v4.0.1. It applies to providers whose customers share system resources such as servers, infrastructure, applications or databases. In summary, A1 requires the provider to:
- A1.1.1: keep logical separation so the provider cannot access customer environments without authorization, and customers cannot access the provider's environment without authorization.
- A1.1.2 and A1.1.3: ensure each customer can only access its own cardholder data, CDE and allocated resources.
- A1.1.4: confirm the effectiveness of logical separation with penetration testing at least once every six months.
- A1.2.1: enable audit logging for each customer's environment, consistent with Requirement 10.
- A1.2.2: support prompt forensic investigation of a suspected or confirmed incident for any customer.
- A1.2.3: provide a way for customers to report security incidents and vulnerabilities, and address them.
The Council has a dedicated FAQ on which types of service providers Appendix A1 applies to. If you are considering a shared or multi-tenant host for anything in scope, ask whether Appendix A1 was assessed and request evidence of the six-monthly separation testing.
How does your hosting choice affect SAQ eligibility?
Hosting decides whether card data touches your servers, which largely decides your self-assessment questionnaire (SAQ):
- Card data never touches your hosted servers. If all processing of account data is entirely outsourced to PCI DSS compliant TPSPs and every element of the payment page comes directly from them, you may be eligible for SAQ A. Check the full criteria in the current SAQ A. The web server that embeds or redirects to the payment form still matters, because tampering with it can redirect customers to a fake page.
- Your hosted site controls the payment page. If your site serves elements of the page that collects card data, SAQ A-EP may apply instead, and your web hosting moves further into scope.
- Your hosted servers receive or store PANs. Expect SAQ D or a full Report on Compliance, and the host's controls become a large part of your assessment.
Your acquirer or payment brand decides which validation you use, so confirm with them. Our SAQ types guide, linked above, walks through each questionnaire.
What questions should you ask a hosting provider?
Ask questions that produce documents, not reassurances, and keep the answers as 12.8.3 due diligence evidence.
| Question | What a good answer looks like |
|---|---|
| Are you assessed as a PCI DSS service provider, and can we have your AOC? | Yes, with a current v4.x service provider AOC available under NDA |
| Which of the services we plan to use are in the scope of that AOC? | The exact product names appear in the in-scope services list |
| Can you give us a responsibility matrix mapped to the PCI DSS requirements? | A matrix showing host, customer and shared responsibilities for all 12 requirements |
| Will you acknowledge your PCI DSS responsibilities in our written agreement? | Yes, as required by 12.9.1, in the contract or an addendum |
| Are we on shared infrastructure? If so, was Appendix A1 assessed? | Yes, with evidence of separation testing at least every six months |
| How will you notify us of security incidents affecting our environment? | A defined process, contact route and timeline |
| What logs can we access, and for how long? | The logs you need for Requirement 10, with adequate retention |
| When is your next assessment, and will you send us the new AOC? | A date and a commitment to share it, supporting your annual 12.8.4 review |
For a SaaS view of how hosting fits the rest of your PCI program, see PCI for SaaS.
How SecureSlate helps
SecureSlate helps SMB, SaaS and HealthTech teams run PCI DSS alongside SOC 2, ISO 27001 and HIPAA. PCI DSS is a built-in framework, and multi-framework control mapping reuses controls you already run. Vendor risk management keeps your host on your TPSP list with its AOC and review dates, so the annual 12.8.4 check is not missed. Risk management records your hosting decision, agentless read-only cloud integrations flag risky settings in accounts you manage, and audit management keeps evidence ready for your assessor.
Start your free SecureSlate trial
FAQ
What is PCI compliant hosting?
Usually, a host assessed against PCI DSS as a service provider that can show a current Attestation of Compliance. It covers only the provider's share of the controls.
Does my web host need to be PCI compliant if I use a payment provider's hosted checkout?
It may still matter. The site that embeds or redirects to a hosted checkout can affect payment security, and SAQ A still applies to it. Confirm with your acquirer.
How often should I check my hosting provider's PCI status?
At least once every 12 months under Requirement 12.8.4, and again when you add a product or region.
Can I use a host that does not have a PCI DSS AOC?
Yes, but its environment is then typically included in your own assessment, which usually means more work and cost.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds