PCI DSS · AWS
Published
PCI DSS compliance runs on hard dates. Version 4 became the only assessable standard in March 2024, its future-dated requirements became mandatory in March 2025, external ASV scans are due every quarter, and your assessment or self-assessment questionnaire falls due every year. If your platform touches cardholder data on AWS, those dates arrive whether the estate is ready or not.
What AWS’s certification buys you
AWS is certified as a PCI DSS Level 1 service provider, and its attestation of compliance and responsibility matrix are available through AWS Artifact. As with every shared responsibility arrangement, this settles the layers AWS operates: physical security, the hypervisor, the underlying network. It contributes nothing to the layers you build. Your network segmentation, access control, logging, encryption, vulnerability management and change control are assessed as yours, and the responsibility matrix exists precisely so an assessor can check you have not assumed otherwise.
The practical value of AWS’s certification is that it makes a compliant architecture achievable with managed services rather than racked appliances. The risk is the same as with every cloud framework: mistaking the provider’s certificate for your own, the same trap we describe in our ISO 27001 on AWS guide.
Scope is the whole game
The cost of PCI DSS is a function of scope: the cardholder data environment, plus every system connected to it or able to affect its security. The most effective compliance work on AWS is therefore architectural, and it happens before any control is implemented:
- Keep cardholder data out entirely if you can. Using a payment service provider with tokenisation or hosted payment fields can keep primary account numbers off your estate altogether, collapsing your obligations to one of the simpler self-assessment questionnaires. This is the single largest lever, and it is a design decision, not a security product.
- Segment ruthlessly. Where card data must exist, isolate the CDE in its own accounts and VPCs, with security groups and network controls that make the boundary provable. In AWS, account boundaries are the strongest segmentation primitive you have; an assessor can verify an account boundary far faster than a diagram of firewall rules. (They are also the most reliable cost allocation instrument you have, so the same structure pays twice.)
- Let managed services carry controls. KMS for encryption at rest and key management, ACM for transport encryption, CloudTrail and CloudWatch for the logging and daily review demanded by requirement 10, IAM with MFA for requirements 7 and 8, AWS Config for change detection. Each replaces a control you would otherwise operate by hand, and each generates evidence continuously.
Where AWS estates fail assessments
The failures we see are rarely exotic. Logging that was complete at the last assessment but not switched on in accounts created since. Access reviews that exist as a policy but not as a record. Segmentation eroded by a convenience peering connection. Quarterly scans that ran but whose findings nobody remediated within the required window. Version 4 sharpens this further, with requirements that are explicitly continuous, such as targeted risk analyses and expanded monitoring, so the gap between an annually-managed programme and a weekly-changing estate now shows up in the standard itself, not just in incidents.
The pattern behind all of these is the same one: PCI DSS describes a continuously operated environment, and most organisations operate it in the month before the assessment.
Holding compliance between assessments
A cardholder data environment that is monitored continuously, with findings remediated as they appear and evidence collected as it is generated, walks into its annual assessment as a formality. That is the model Cloudreason’s cloud compliance service applies to PCI DSS estates on AWS: monitoring against the standard’s controls, remediation carried out by engineers who run production infrastructure, and the compliance calendar of scans, reviews and attestations tracked so nothing is discovered late. If there is an assessment or a quarterly scan deadline ahead of you, talk to us before it gets close.