Scope
Defines the systems, networks, and data flows included in the cardholder data environment and any segmentation controls used to limit scope.
A clear agreement reduces ambiguity about scope, assigns accountability for controls, and documents incident response obligations. It helps demonstrate due diligence to card brands, acquiring banks, and auditors while clarifying remediation responsibilities after a security event.
Common parties involved in a PCI-DSS Compliance Agreement include the merchant, payment processor, gateway provider, value-added service vendors, and any third-party hosts that store, process, or transmit cardholder data.
The signed agreement creates contractual evidence of each party’s commitments and supports compliance assessments and auditor inquiries.
Defines the systems, networks, and data flows included in the cardholder data environment and any segmentation controls used to limit scope.
Allocates duties for encryption, logging, monitoring, patching, vulnerability scanning, and incident response between parties and sub-processors.
Specifies the version of PCI DSS to follow, applicable control objectives, acceptable encryption protocols, and change management requirements.
Describes required artifacts (SARs, ROQAs, ASV scans, penetration test reports), access for QSAs, and timelines for producing evidence.
Sets notification timelines, roles for forensic analysis, breach remediation steps, and obligations to notify acquirers and card brands.
Includes indemnities, limits on liability, insurance requirements, fines allocation, and contract termination rights for material noncompliance.
| Field | Configuration |
|---|---|
| Signer Order | Sequential routing with signer email and role |
| Authentication | Email plus SMS code or stronger KBA as needed |
| Evidence Collection | Attach scans, ROQAs, ASV results required |
| Retention | Define retention and export settings |
Ensure the signing platform supports enforceable e-signatures, secure storage, and an immutable audit trail appropriate for compliance evidence.
Store signed copies in an encrypted archive with restricted access and export options for auditors and QSAs.
Date when obligations and monitoring begin
ASV scans and penetration results due within 30 days
ASV scan cadence typically every 90 days
30–90 days depending on severity
Annual ROC or SAQ submission requirement
Tech Data required vendor-assigned responsibilities and audit access for processors.
Martin Properties added explicit tokenization and POS segmentation language to vendor contracts.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no credit card required | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | No cap | No cap | No cap |