Multi-Tenant Service Provider
A multi-tenant service provider is a company that uses one shared system or platform to serve many different customers at the same time, with each customer kept logically separate as a 'tenant.' Because multiple businesses rely on the same underlying infrastructure, the provider takes on added responsibility to keep each customer's data and environment isolated from the others. In the payment security world, these providers face specific expectations designed to address the risks of sharing infrastructure across many clients.
A multi-tenant service provider operates a shared infrastructure or single instance of an application in which multiple customers (tenants) operate independently within logically isolated environments. Under PCI DSS, multi-tenant service providers are addressed by a dedicated appendix (Appendix A1), which sets out additional requirements intended to help ensure separation and appropriate isolation between tenant environments and to protect each customer's hosted data. Practitioners should note that the specific controls, requirement numbering, and wording differ between PCI DSS versions and should be confirmed against the current published standard; the applicability and scope of these requirements depend on the provider's architecture and validated implementation, not on the multi-tenant label alone.
Why it matters
Multi-tenant service providers concentrate risk: because many independent customers rely on the same underlying infrastructure or a single application instance, a weakness in tenant isolation can potentially affect multiple businesses at once rather than a single environment. This shared model is why PCI DSS addresses these providers through a dedicated appendix (Appendix A1), which sets out additional expectations intended to help ensure appropriate separation between tenant environments and to protect each customer's hosted data.
The compliance implications extend beyond the provider itself. A merchant or other customer that hosts its cardholder data environment with a multi-tenant provider inherits dependencies on that provider's controls, and responsibility for specific requirements is typically divided between the provider and its customers. Misunderstandings about who is accountable for which control can leave gaps, so the boundaries of that shared responsibility need to be documented and validated rather than assumed.
Practitioners should note that the specific controls, requirement numbering, and wording associated with multi-tenant service providers differ between PCI DSS versions and should be confirmed against the current published standard. The applicability and scope of these requirements depend on the provider's actual architecture and validated implementation, not on the multi-tenant label alone; being described as multi-tenant does not by itself establish whether a given control applies or how it must be met.
Who it's relevant to
Inside Multi-Tenant Service Provider
Common questions
Answers to the questions practitioners most commonly ask about Multi-Tenant Service Provider.