Cardholder Data Environment
The Cardholder Data Environment (CDE) is the part of a business that handles payment card information, including the systems, people, and processes that store, process, or transmit that data. It also covers connected components that could affect the security of that data. Defining the CDE helps an organization know which areas fall under PCI DSS requirements.
The CDE comprises the system components, people, and processes that store, process, or transmit cardholder data or sensitive authentication data, along with connected or supporting system components. Cardholder data (such as PAN, cardholder name, expiration date, and service code) and sensitive authentication data (such as full track data, CAV2/CVC2/CVV2/CID, and PINs/PIN blocks) are the data elements whose handling brings systems into the CDE; note that sensitive authentication data must not be stored after authorization, even when encrypted, whereas certain cardholder data may be stored under defined controls. The boundary of the CDE determines PCI DSS applicability and scope, and practitioners should confirm scoping and control requirements against the current published PCI DSS, as requirement numbering and wording differ between versions.
Why it matters
The Cardholder Data Environment defines the boundary of PCI DSS applicability. Because PCI DSS requirements apply to the system components, people, and processes that store, process, or transmit cardholder data or sensitive authentication data — as well as connected or supporting components — an inaccurate or overly narrow CDE definition can leave in-scope systems unassessed and unprotected. Conversely, an unnecessarily broad CDE increases the assessment burden and the number of systems subject to controls. Getting the scope right is therefore foundational to a defensible compliance posture.
The composition of the CDE is driven by the data elements it handles. Cardholder data such as PAN, cardholder name, expiration date, and service code brings systems into scope, and certain cardholder data may be stored under defined controls. Sensitive authentication data — including full track data, CAV2/CVC2/CVV2/CID, and PINs or PIN blocks — must not be stored after authorization, even when encrypted. Systems that retain such data in violation of this principle expand risk and can indicate scoping or control failures that would surface during an assessment or, in the worst case, a breach.
Because connected or supporting system components fall within the CDE, organizations should account for how network segmentation, shared services, and administrative access paths affect the boundary. Practitioners should confirm scoping and applicable control requirements against the current published PCI DSS, since requirement numbering and wording differ between versions and should not be assumed from memory.
Who it's relevant to
Inside CDE
Common questions
Answers to the questions practitioners most commonly ask about CDE.