Establishing secure connection…Loading editor…Preparing document…

PCI-DSS Compliance Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

PCI-DSS Compliance Agreement

This PCI-DSS Compliance Agreement ("Agreement") is entered into as of by and between Client Name: with principal address: and Service Provider Name: with principal address: .

RECITALS

WHEREAS, Client engages Service Provider to perform services that involve the storage, processing or transmission of cardholder data in connection with Client's payment card transactions; and

WHEREAS, the parties desire to allocate responsibilities for achieving and maintaining compliance with the Payment Card Industry Data Security Standard ("PCI-DSS") and to define the procedures and remedies in the event of non-compliance or a security incident affecting cardholder data.

WHEREAS, Service Provider represents that it has implemented, and will maintain, administrative, physical and technical safeguards designed to meet PCI-DSS requirements for the systems and services within the scope described below.

NOW, THEREFORE, in consideration of the mutual promises contained herein, the parties agree as follows:

1. DEFINITIONS

For purposes of this Agreement, the following terms have the meanings set forth below:

"Cardholder Data" means full primary account numbers (PAN), cardholder name, expiration date, and service code, as well as any sensitive authentication data as defined by PCI-DSS.

"PCI-DSS" means the Payment Card Industry Data Security Standard and any successor standards, together with associated testing, reporting and attestation protocols required by card brands or acquiring banks.

"In-Scope Systems" means the systems, networks, and services that are used to store, process or transmit Cardholder Data within the Services provided by Service Provider and as further described in the Scope of Compliance.

2. SCOPE OF COMPLIANCE

The Scope of Compliance includes all In-Scope Systems and processes owned or controlled by Service Provider that directly or indirectly store, process or transmit Cardholder Data on behalf of Client. Parties shall document the scope as follows:

Any subsequent changes to the Scope of Compliance that materially alter the systems or volume of Cardholder Data shall be subject to the change management and notification requirements set forth in this Agreement.

3. SERVICE PROVIDER OBLIGATIONS

Service Provider covenants and warrants that it shall:

a) Implement and maintain administrative, physical and technical controls necessary to meet all applicable PCI-DSS requirements for In-Scope Systems and to produce an Attestation of Compliance or other evidentiary documentation upon Client's reasonable request.

b) Conduct internal or external PCI-DSS assessments at least and provide to Client within days following completion the corresponding Attestation of Compliance or Report on Compliance.

c) Remediate any confirmed deficiencies identified in a PCI-DSS assessment in accordance with the remediation timeline below and certify completion in writing.

4. CLIENT OBLIGATIONS

Client shall: (a) maintain its own environment and controls outside the defined Scope of Compliance; (b) notify Service Provider promptly of changes to Cardholder Data flows or payment channels affecting scope; and (c) cooperate with Service Provider in connection with assessments, audits and incident response activities, including providing timely access to personnel and records.

5. AUDIT RIGHTS AND ATTESTATION

Client has the right, upon reasonable prior notice, to require Service Provider to allow a qualified assessor or auditor to perform an assessment of In-Scope Systems. Such assessments shall be conducted no more frequently than unless a credible security incident or material change in scope occurs.

Service Provider shall provide: (i) a current Attestation of Compliance, (ii) applicable Report on Compliance or summary of assessment findings, and (iii) evidence of remediation for any critical findings within days of Client's request.

6. INCIDENT RESPONSE; NOTIFICATION

In the event of any actual or suspected compromise of Cardholder Data, Service Provider shall: (a) notify Client without undue delay and in no event later than hours after discovery; (b) preserve forensic data and cooperate in investigation; and (c) implement interim containment measures.

Costs associated with investigation and notification attributable to Service Provider's failure to comply with PCI-DSS shall be borne by Service Provider, subject to the indemnification provisions below.

7. CONFIDENTIALITY AND DATA HANDLING

Cardholder Data and related reports, Attestations of Compliance, assessment reports, logs and forensic materials are Confidential Information. Each party shall protect Confidential Information with at least the same degree of care it uses to protect its own confidential information, but in no event less than reasonable care.

Service Provider shall not use or disclose Cardholder Data except to perform obligations under this Agreement or as required by law, and shall implement data retention and disposal procedures consistent with PCI-DSS requirements and the parties' documented policies.

8. INDEMNIFICATION

Service Provider shall indemnify, defend and hold harmless Client, its officers, directors and affiliates from and against any third-party claims, liabilities, losses, damages, costs and expenses (including reasonable attorneys' fees) arising from Service Provider's breach of its PCI-DSS obligations under this Agreement or resulting from Service Provider's negligence, willful misconduct or failure to safeguard Cardholder Data.

9. LIMITATION OF LIABILITY

Except for liability arising from willful misconduct, gross negligence or Service Provider's breach of its indemnification obligations, neither party shall be liable to the other for incidental, consequential, punitive or special damages, including lost profits or business interruption, even if advised of the possibility of such damages.

10. TERM AND TERMINATION

This Agreement shall commence on the Effective Date and continue for an initial term of unless earlier terminated in accordance with this Section. Either party may terminate this Agreement for material breach by the other party if the breaching party fails to cure such breach within days after written notice.

11. NOTICES

All notices required or permitted under this Agreement shall be in writing and delivered to the parties at the addresses set forth below or at such other address as either party may designate by notice to the other.

12. AMENDMENTS; WAIVER; COUNTERPARTS

No amendment or waiver of any provision of this Agreement shall be effective unless in writing and signed by authorized representatives of both parties. Failure to exercise any right shall not constitute a waiver. This Agreement may be executed in counterparts, each of which shall be deemed an original, and all of which together shall constitute one instrument.

13. SEVERABILITY; ENTIRE AGREEMENT; GOVERNING LAW

If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall remain in full force and effect. This Agreement constitutes the entire agreement between the parties with respect to its subject matter and supersedes all prior agreements and understandings. This Agreement shall be governed by and construed in accordance with the laws of the state or jurisdiction identified below:

14. MISCELLANEOUS PROVISIONS

The parties acknowledge that compliance with PCI-DSS is an ongoing obligation requiring periodic assessments, timely remediation and cooperation. Neither party's compliance with this Agreement shall limit any regulatory or contractual obligations owed to card brands, acquiring banks or other third parties.

Client:

By:

Date:

Service Provider:

By:

Date:

Enter text✕

What a PCI-DSS Compliance Agreement Is and When It Applies

A PCI-DSS Compliance Agreement is a written contract that documents the responsibilities, scope, and controls each party agrees to follow to protect cardholder data and meet PCI Security Standards Council obligations. It typically defines which systems and processes fall inside the cardholder data environment (CDE), assigns roles for card data handling, and sets reporting and remediation procedures for security incidents. The agreement complements a merchant’s PCI self-assessment or QSA report by creating contractual obligations between service providers, merchants, payment processors, and other third parties.

Why a Formal PCI-DSS Compliance Agreement Matters

A clear agreement reduces ambiguity about scope, assigns accountability for controls, and documents incident response obligations. It helps demonstrate due diligence to card brands, acquiring banks, and auditors while clarifying remediation responsibilities after a security event.

Why a Formal PCI-DSS Compliance Agreement Matters

Who Typically Prepares and Signs This Agreement

Common parties involved in a PCI-DSS Compliance Agreement include the merchant, payment processor, gateway provider, value-added service vendors, and any third-party hosts that store, process, or transmit cardholder data.

  • Merchants and acquiring banks: negotiate responsibilities for card processing and remediation.
  • Service providers and gateways: define technical and operational controls required of vendors.
  • Qualified Security Assessors (QSAs): often review scope and attestations tied to the agreement.

The signed agreement creates contractual evidence of each party’s commitments and supports compliance assessments and auditor inquiries.

Essential Sections to Include in Your PCI-DSS Compliance Agreement

A comprehensive agreement groups obligations into clear sections so auditors, card brands, and internal teams can quickly verify who is responsible for each control and what evidence is required.

Scope

Defines the systems, networks, and data flows included in the cardholder data environment and any segmentation controls used to limit scope.

Responsibilities

Allocates duties for encryption, logging, monitoring, patching, vulnerability scanning, and incident response between parties and sub-processors.

Control Standards

Specifies the version of PCI DSS to follow, applicable control objectives, acceptable encryption protocols, and change management requirements.

Audit & Evidence

Describes required artifacts (SARs, ROQAs, ASV scans, penetration test reports), access for QSAs, and timelines for producing evidence.

Incident Response

Sets notification timelines, roles for forensic analysis, breach remediation steps, and obligations to notify acquirers and card brands.

Liability & Remedies

Includes indemnities, limits on liability, insurance requirements, fines allocation, and contract termination rights for material noncompliance.

Required Data Points and Information Elements

Merchant Legal Name: Full registered entity name
Service Provider Name: Full legal name of vendor
Scope Definition: CDE systems and network segments
Contact Details: Security and escalation contacts
Applicable PCI Version: PCI DSS version number
Effective Date: Date agreement starts

Step-by-Step: Completing a PCI-DSS Compliance Agreement

Follow these sequential steps to prepare, review, and finalize a PCI-DSS Compliance Agreement so it aligns with technical scope and audit obligations.

  • 01
    Identify Scope: Map systems that store, process, or transmit cardholder data.
  • 02
    Assign Roles: Document which party manages controls and monitoring.
  • 03
    List Evidence: Specify required scans, reports, and access for auditors.
  • 04
    Sign and Retain: Execute by authorized signers and store secure copies.

How to Configure an Online Agreement Workflow

Design an electronic workflow that mirrors contract sign-off, routes approvers in order, and captures audit metadata for PCI validation.

Field Configuration
Signer Order Sequential routing with signer email and role
Authentication Email plus SMS code or stronger KBA as needed
Evidence Collection Attach scans, ROQAs, ASV results required
Retention Define retention and export settings

Where to Send and Store the Executed Agreement

After signing, route executed copies to key stakeholders and secure repositories that meet PCI and internal recordkeeping policies.

  • Payment Processor: Send an executed copy to acquirer or gateway for their records
  • Merchant Security Team: Store in encrypted internal document repository
  • Third-Party Vendor: Provide vendor-signed copy to the service provider
  • Auditor / QSA: Supply evidence package and signed agreement on request

Digital Signing and eSubmission Considerations

Ensure the signing platform supports enforceable e-signatures, secure storage, and an immutable audit trail appropriate for compliance evidence.

  • Authentication: Use email+SMS or stronger multi-factor methods
  • Audit Trail: Capture IP, timestamp, and action history
  • File Formats: Support PDF/A and export of certificate of completion

Store signed copies in an encrypted archive with restricted access and export options for auditors and QSAs.

Timelines, Deadlines, and Expected Processing

Set explicit deadlines for deliverables, vendor attestations, and remediation milestones so parties can measure compliance progress.

Agreement Effective Date:

Date when obligations and monitoring begin

Evidence Delivery:

ASV scans and penetration results due within 30 days

Quarterly Scanning:

ASV scan cadence typically every 90 days

Remediation Window:

30–90 days depending on severity

Annual Attestation:

Annual ROC or SAQ submission requirement

Common Preparation Mistakes to Avoid

  • Undefined scope that omits cloud or outsourced components, resulting in gaps in control ownership and failed assessments.
  • Vague responsibility clauses that do not specify technical controls, monitoring frequency, or evidence types for QSAs.
  • Relying on image overlays or scanned signatures without a verifiable audit trail can weaken proof of execution.
  • Failing to update the agreement after environment changes, such as new payment integrations or third-party sub-processors.

Consequences of an Incomplete or Noncompliant Agreement

Card Brand Fines: Monetary fines assessed by card brands
Liability Exposure: Liability for fraud, chargebacks, and remediation
Acquirer Sanctions: Suspension or termination of processing rights
Increased Audit Scrutiny: Mandatory PCI assessments or forensic reviews
Legal Claims: Breach-related lawsuits and indemnity claims
Reputational Harm: Loss of customer trust and business disruption

Illustrative Examples of Compliance Agreements in Practice

These short examples show how organizations document security and signing practices when working with vendors and processors.

Tech Data

Tech Data required vendor-assigned responsibilities and audit access for processors.

  • The agreement tied evidence delivery to quarterly scans.
  • This clarity helped streamline auditor requests and reduced time-to-provide artifacts during a QSA review.

Martin Properties

Martin Properties added explicit tokenization and POS segmentation language to vendor contracts.

  • They required signed attestations after major updates.
  • The change reduced scope disputes and improved the merchant's ability to demonstrate controls during merchant bank inquiries.

eSignature Vendor Comparison for Executing PCI-DSS Agreements

Compare common plan and capability dimensions relevant to executing and retaining a PCI-DSS Compliance Agreement. Pricing and feature availability vary by plan tier.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial, no credit card required Varies by vendor Varies by vendor Varies by vendor Varies by vendor
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year No cap No cap No cap

Practical Tips for Accurate and Efficient Completion

Follow these best practices to reduce negotiation time, support auditability, and limit scope creep.

Define Scope Precisely
Map IP addresses, service names, and data flows explicitly. Use architecture diagrams and network segmentation evidence to limit what auditors consider in-scope.
Standardize Evidence Types
Specify exact file types and retention windows for ASV scans, pen tests, and logs so both parties know what to produce during assessments.
Use Strong Authentication
Require multi-factor or SMS verification for signer authentication when agreeing to security obligations or acknowledgments, and capture the audit trail.
Review Annually
Schedule yearly reviews of the agreement and update scope after system changes, new integrations, or shifts in processing responsibilities.

Frequently Asked Questions About the PCI-DSS Compliance Agreement

Answers to common questions about enforceability, signature methods, evidence, and post-signature changes.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users