Third-Party Service Provider
A Third-Party Service Provider (TPSP) is an outside company that a merchant or other organization hires to help handle or protect payment card data, or to support card-processing activities. Because these vendors can touch or affect the security of cardholder data, their practices can influence the hiring organization's own compliance obligations. Not every vendor an organization uses is a TPSP that falls within payment security scope; that depends on the services provided and how they relate to card data.
Within PCI contexts, a TPSP is a third-party entity acting as a service provider that supports another party in card-processing activities or in securing cardholder data, and whose services may affect the security of the cardholder data environment (CDE) or the outcome of a PCI DSS assessment. In ACH contexts (per Nacha), the term denotes an entity that provides services related to ACH processing on behalf of another party and may or may not transmit entries directly; this is a distinct usage and should not be conflated with the PCI meaning. Scope determination is service-specific: an organization may engage many vendors, but only those whose services can impact cardholder data or its security are treated as in-scope TPSPs. The specific responsibilities, validation obligations, and division of PCI DSS requirements between a TPSP and its customer depend on the services rendered and should be confirmed against the current published PCI DSS standard and relevant PCI SSC guidance rather than assumed.
Why it matters
Most organizations that accept payment cards do not build and operate every part of their payment environment in-house. They engage outside companies for functions such as payment processing, hosting, data storage, or security services. When those vendors can touch cardholder data or otherwise affect the security of the cardholder data environment (CDE), their practices become directly relevant to the hiring organization's own PCI DSS obligations. In other words, outsourcing an activity does not automatically outsource responsibility for its security or for demonstrating compliance.
The practical significance is that a merchant's compliance posture can depend in part on service providers it does not directly control. If a TPSP's controls are weak or its scope responsibilities are unclear, the customer organization may carry compliance and risk exposure it did not intend. This is why the division of PCI DSS responsibilities between a TPSP and its customer needs to be documented and confirmed rather than assumed, and why not every vendor relationship is treated the same: scope is service-specific, and only vendors whose services can impact cardholder data or its security are in-scope TPSPs.
A further complication is terminology. The same acronym is used differently across industries. In PCI contexts, a TPSP is a service provider that supports card-processing activities or the securing of card data. In ACH contexts, Nacha uses TPSP to mean an entity that provides ACH processing services on behalf of another party, whether or not it transmits entries directly. These are distinct usages, and conflating them can lead to misapplied controls and obligations.
Who it's relevant to
Inside TPSP
Common questions
Answers to the questions practitioners most commonly ask about TPSP.