Service Provider
In payment security, a service provider is a business that handles cardholder data on behalf of another company, or that could otherwise affect the security of that data, without itself being one of the payment card brands. Examples include companies that store, process, or transmit card data for merchants, as well as vendors whose services touch the systems that handle such data. A general service provider in other contexts simply means any person or organization that supplies services to another party under a contract, but the payment-industry meaning is narrower and more specific.
Under PCI DSS, a Service Provider is a business entity (not a payment brand) that is directly involved in storing, processing, or transmitting cardholder data on behalf of another entity, or that can otherwise affect the security of cardholder data. This includes entities providing services that control or could impact the security of cardholder data, such as managed hosting, tokenization, or transaction processing. Notably, exclusions apply: for example, a telecommunications company that provides only the public network link (and does not access the cardholder data traversing it) is not, for that service alone, considered a service provider. This term is distinct from the broader, general usage in which a service provider is any individual or entity supplying services under a service agreement; the PCI DSS definition is limited to business entities and tied to cardholder data handling or its security. Service providers typically carry PCI DSS validation obligations and may be required to demonstrate compliance (for example, via an Attestation of Compliance). Practitioners should confirm the exact definitional wording, scope, and any associated validation requirements against the current published PCI DSS glossary and standard, as terminology and requirements differ between versions.
Why it matters
The service provider designation matters because responsibility for cardholder data does not end at a merchant's own perimeter. When a business entity stores, processes, or transmits cardholder data on another company's behalf, or can otherwise affect the security of that data, weaknesses in that entity's environment can expose data belonging to many downstream merchants at once. Getting the classification right determines who carries which PCI DSS validation obligations and where controls must be demonstrated, rather than assumed.
The precision of the definition also affects scope decisions. Because a service provider under PCI DSS must be a business entity (not one of the payment card brands) that is directly involved in handling cardholder data or able to affect its security, the label cannot be applied casually. Exclusions are equally consequential: a telecommunications company that provides only the public network link and does not access the cardholder data traversing it is not, for that service alone, treated as a service provider. Misclassifying such a relationship in either direction can lead to gaps in coverage or to validation effort spent where it is not required.
Because definitional wording, scope, and associated validation requirements differ between PCI DSS versions, practitioners should confirm classifications against the current published PCI DSS glossary and standard rather than relying on a prior version's language. Exact obligations depend on the service delivered and how it touches cardholder data, so classification is a fact-specific exercise.
Who it's relevant to
Inside SP
Common questions
Answers to the questions practitioners most commonly ask about SP.