Scope
Clearly identify systems, networks, applications, and merchant IDs in scope. Include any segmentation or excluded assets and how cardholder-data environments are defined.
A written agreement reduces ambiguity about cardholder-data scope, minimizes legal and operational risk, and records security responsibilities and acceptance criteria. It supports auditability, helps manage vendor risk, and underpins contractual obligations to acquirers and card brands.
Ensure each signing party has decision authority for their area (technical, legal, financial) to avoid later disputes over scope and costs.
Clearly identify systems, networks, applications, and merchant IDs in scope. Include any segmentation or excluded assets and how cardholder-data environments are defined.
List artifacts such as scoping worksheets, SAQ/QSA reports, vulnerability scan results, penetration test reports, remediation plans, and final attestation of compliance.
Assign tasks to each party, including data access, scheduling windows, remediation ownership, and who provides required documentation or evidence.
State control baselines to be tested (e.g., network segmentation, encryption, access controls) and testing methods to validate PCI-DSS requirements.
Define pricing model (fixed, time-and-materials), payment milestones, expense reimbursement, and change-order procedures for out-of-scope work.
Include confidentiality, liability caps, indemnification, data breach notification timelines, and governing law for disputes.
| Field | Configuration |
|---|---|
| Signature Order | Enable sequential signing for technical → legal → finance |
| Authentication | Use email + SMS OTP or higher for vendor signers |
| Conditional Fields | Show payment terms only when variable pricing selected |
| Retention | Enable audit trail and export to secure storage |
Ensure the chosen solution captures timestamps, signer attribution, an audit trail, and allows export of signed files to secure long-term storage.
30 days to accept or request changes
Schedule within 60 days of agreement signature
Provider delivers draft report within 10 business days
Client typically has 30–90 days, per contract
Complete within 14 days after remediation verification
Agreement executed and project authorized
Final list of in-scope assets approved
Testing and evidence collection finished
Final report and attestation provided
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
Tech Data standardized vendor agreements to align security and procurement
A healthcare provider secured HIPAA and PCI controls in a single proposal