Security Questionnaire Mapper

Cardholder data and PCI DSS: the clause the question tests

Whether card data passes through the service, and on what PCI DSS attestation.

How the customer usually asks it

example

"Do you store, process or transmit cardholder data?"

Read this question

Anchor clauses

1 framework
FrameworkAnchor clause
PCI DSS v4.0.13.2.1 Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the following · 12.5.2 PCI DSS scope documented and confirmed annually

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The PCI DSS attestation of compliance or self-assessment for the service, with its scope, and the data flow showing where account data goes.

The clauses, with what an assessor asks for

PCI DSS 3.2.1 Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the following

What it asks for, in one line (the standard's own text is not quoted here):

Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the following:; Coverage for all locations of stored account data.

Evidence an assessor expects: Retention schedule by data type; Secure deletion procedure and logs; Data discovery scan results; Quarterly purge job evidence; Legal hold exception register
Where answers usually fall short: Indefinite retention by default; No deletion proof
Source: PCI DSS v4.0.1
PCI DSS 12.5.2 PCI DSS scope documented and confirmed annually

What it asks for, in one line (the standard's own text is not quoted here):

PCI DSS scope is documented and confirmed at least once every 12 months by identifying all data flows, system components, and segmentation controls in use.

Evidence an assessor expects: Scope document with named components; Data flow diagrams covering all CHD flows; Network and segmentation diagrams; Annual scoping exercise minutes and sign-off; Inventory cross-references
Where answers usually fall short: Diagrams stale; Annual scoping skipped
Source: PCI DSS v4.0.1
No ISO 27001 clause anchors this family, so with ISO 27001 held the register marks the question "beyond your certificate". That is a fact about where the clause sits, not about the controls you run.

Other families in data protection and encryption