PCI compliance software for service providers
Service providers get one SAQ, not ten, plus 17 requirements merchants never see. What the five categories of PCI tool actually produce, and where each stops.
By the Scrutineer team
September 2026 · 9 min read
Try it while you read
No account, nothing to install.
Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.
›
Illustrative sample · not an audit attestation
Almost every "best PCI compliance software" roundup is written for merchants. If you are a service provider, most of what those articles compare does not apply to you: there is only one Self-Assessment Questionnaire you are permitted to use, and the questionnaire you complete contains seventeen requirements labeled for service providers only that a merchant never sees. Three of those run on a six-month or three-month clock rather than an annual one. That, not feature count, is what should decide which platform you buy.
Which SAQ do service providers use?
SAQ D for Service Providers, and nothing else. The PCI Security Standards Council puts it flatly: SAQ D for Service Providers is the only SAQ for SAQ-eligible service providers, and all other SAQs are for merchant use only. So the "which of the ten questionnaires is right for me" exercise that fills the first half of most PCI articles is a merchant exercise. For a SaaS company, a payment facilitator, a hosting provider or a BPO handling cardholder data, the real question is a different one: whether you are allowed to self-assess at all, or whether your level forces a Report on Compliance.
What are the PCI service provider levels?
The payment brands set these, not the Council, and Visa's are the ones most people mean. A service provider that stores, processes or transmits more than 300,000 Visa transactions a year is Level 1 and validates through an annual QSA-led Report on Compliance. Below that threshold you are Level 2 and may validate with SAQ D for Service Providers. Both levels still owe quarterly ASV scanning and penetration testing, so the level changes who signs your validation, not how much security work you do.
Two practical consequences fall out of this. First, your validation route can change mid-year as volume grows, and a company that budgeted a self-assessment can find itself owing a QSA engagement it did not price. Second, plenty of Level 2 providers choose to validate as Level 1 anyway, because an enterprise customer asked for a ROC or because they want the listing described further down this page.
The 17 requirements that apply to service providers only
This is the part worth reading closely, because it is measurable and it is rarely published. Searching the Council's own SAQ D for Service Providers for the phrase "Additional requirement for service providers only" returns seventeen requirements. Commentary on PCI DSS v4 usually cites eleven, but that figure counts only the requirements that were new in v4. The full set carried by the questionnaire is larger, and the older ones are just as capable of failing an assessment.
| Requirement | What it asks a service provider for | Cadence |
|---|---|---|
| 3.6.1.1 | A maintained written description of your cryptographic architecture, including algorithms, protocols and keys protecting stored account data | Kept current |
| 3.7.9 | Documented guidance to customers on secure transmission, storage and updating of any cryptographic keys you share with them | Kept current |
| 8.2.3 | Unique authentication factors for each customer premises where you hold remote access | Continuous |
| 8.3.10 and 8.3.10.1 | Password guidance to customer users, and enforced password controls where single-factor authentication reaches cardholder data | Continuous |
| 10.7.1 | Detection, alerting and prompt handling of failures in critical security control systems | Continuous |
| 11.4.6 | Penetration testing of segmentation controls at least once every six months and after any change to segmentation | Every 6 months |
| 11.5.1.1 | Intrusion detection or prevention that specifically addresses covert malware communication channels | Continuous |
| 12.4.1 | Executive accountability for cardholder data protection and a chartered PCI DSS compliance program | Kept current |
| 12.4.2 and 12.4.2.1 | Documented reviews confirming personnel are performing their security tasks, with records retained | Every 3 months |
| 12.5.2.1 | Scope documented and confirmed at least once every six months and on significant change | Every 6 months |
| 12.5.3 | A documented review of scope impact whenever organizational structure changes significantly | On change |
| 12.9.1 and 12.9.2 | Written acknowledgement to customers of your responsibility for their account data, and support for their requests for your compliance status | On request |
| A2.1.2 and A2.1.3 | A Risk Mitigation and Migration Plan where legacy SSL or early TLS still reaches POS POI terminals, and a secure service offering | Where applicable |
Read the cadence column rather than the requirement column. A service provider's PCI program is not an annual document. It is an annual attestation sitting on top of a six-month scope validation, a six-month segmentation penetration test and a quarterly personnel review. A platform that produces a beautiful yearly package and goes quiet in between is solving the wrong problem.
Best PCI compliance software for service providers
There are five genuinely different things sold under this heading, and they produce different documents. Comparing them on feature lists is how people end up buying two of the same thing and none of the third.
| Category | What it produces | Handles the sub-annual cadences | Best fit | Where it stops |
|---|---|---|---|---|
| QSA firms (Coalfire, Schellman, SecurityMetrics and others) | The Report on Compliance and the signed AOC | No, this is a point-in-time engagement | Level 1 service providers, who have no alternative | The report describes a moment. Everything between engagements is yours |
| ASV scanning providers | The quarterly external scan attestation | Quarterly by definition, for scanning only | Everyone. This is not optional at either level | Scans one requirement family. It says nothing about scope, keys or personnel reviews |
| Compliance automation platforms (Vanta, Drata, Secureframe, Sprinto and similar) | Continuous evidence collection and control monitoring across several frameworks | Partly, through recurring tasks and monitors | SaaS companies already carrying SOC 2 or ISO 27001 who are adding PCI | Coverage is built around the frameworks most of their customers buy, so PCI service provider specifics are usually shallower than SOC 2 |
| Enterprise GRC suites (Archer, OneTrust, AuditBoard and similar) | A program of record with workflow, risk and audit modules | Yes, if you configure it | Large regulated organizations running many obligations at once | Configuration is the project. Time to a working PCI program is measured in quarters |
| Control-linked readiness platforms, including Scrutineer | One mapped control library, the evidence behind each requirement, and the calendar the requirements actually run on | Yes, that is the design point | Service providers who hold SAQ D alongside SOC 2, ISO 27001 or HIPAA and are tired of evidencing the same control four times | Not a QSA and not an ASV. A Level 1 provider still engages both, and no platform signs your attestation |
The honest summary is that a Level 1 service provider buys from at least three of these rows, and the only decision with real money in it is how much of the year-round work you keep in one place. Our own row has a genuine limit worth stating plainly: Scrutineer prepares and holds evidence, and it cannot validate compliance or replace either of the two parties who must.
What PCI requirements do service providers have to meet more than once a year?
Three, and they are the ones that quietly break annual-cycle programs. Scope has to be documented and confirmed at least once every six months and on significant change, under 12.5.2.1, against twelve months for everyone else. Segmentation penetration testing runs at least once every six months and after any change to segmentation controls, under 11.4.6. And reviews confirming that personnel are actually performing their assigned security tasks happen at least once every three months, under 12.4.2, with the records kept.
None of these are hard individually. They fail because nobody owns the calendar. If your evidence lives in whatever format the last audit asked for, each of these becomes a small excavation, four to eight times a year, forever. That is the specific cost that PCI SAQ software is supposed to remove, and it is a reasonable test to put to any vendor demo: ask them to show you the next six months of scheduled PCI obligations, not the dashboard.
Do service providers need a QSA?
Level 1 providers do, because the validation route is a QSA-led Report on Compliance. Level 2 providers can self-assess with SAQ D, but "can" is doing a lot of work in that sentence. Enterprise customers routinely require a ROC in their vendor security review regardless of what your acquirer accepts, and a growing service provider who self-assessed in March can be asked for a ROC in September by a single large prospect. Budgeting as though the level threshold is the only trigger is a common and expensive assumption.
Requirement 12.9.2 is the one that turns this into a commercial issue rather than a compliance one. It obliges you to support your customers' requests for information about your PCI DSS compliance status for any service you perform on their behalf. In practice that means your compliance evidence is customer-facing, and how fast you can answer it shows up in sales cycles. The same evidence set usually answers the security questionnaires those customers send alongside it.
What is the Visa Global Registry of Service Providers?
It is Visa's public list of service providers that have validated as Level 1 and been registered by an acquirer or a Visa client. Getting on it requires the ROC, which is why some Level 2 providers deliberately validate as Level 1 despite being under the transaction threshold. The registry functions as procurement shorthand: a prospective customer can check it without asking you for anything. If you sell into large merchants or banks, being absent from it is a question you will answer repeatedly.
How to shortlist without wasting a quarter
Start from your validation route, because it removes whole categories. If you are Level 1, the QSA engagement and the ASV scanning are fixed costs and the only open question is what carries the year-round program. If you are Level 2 and intend to stay there, the open question is whether anything you buy also covers the frameworks your customers ask about, since PCI rarely arrives alone.
Then ask three concrete things of every vendor. Can it show the seventeen service-provider-only requirements as distinct items with evidence attached, rather than folding them into a generic PCI checklist. Can it schedule and evidence the six-month and three-month obligations rather than only the annual one. And can it reuse the same control evidence for SOC 2, ISO 27001 and HIPAA, because a service provider that evidences access control four separate times a year is paying for the same work four times. That last point is the entire economic argument for PCI compliance software over a spreadsheet and a consultant, and it is easy to test in a trial.
One thing worth separating out: none of this is financial control work. Confirming that the money actually landed, matching settlement files from your processors against your ledger, is a different job with different tooling, and teams that try to run it through a compliance platform usually end up with neither done well. Handle that with something built for account reconciliation and keep your PCI evidence set focused on what an assessor will ask for.
Finally, resist buying on the annual report. Every product in this category can produce a document once a year. The service providers who find PCI cheap are the ones whose scope confirmation in month six is a review rather than a rediscovery, and that difference is decided by how the evidence was stored in months one through five. The PCI DSS compliance checklist is a reasonable place to sanity-check what you are being asked to evidence before you shortlist anything.
See Scrutineer scrutinize your posture
Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.