Wazuh Cloud Platform Achieves PCI DSS Compliance
![Post icon](https://wazuh.com/uploads/2020/02/pci-dss-compliance-post-icon.png)
The Wazuh Cloud platform has been validated as PCI DSS Level 1 Service Provider compliant. The Payment Card Industry Data Security Standard (PCI DSS) specifies best practices and security controls needed to keep credit card data safe and secure during transit, processing, and storage. Mainly, organizations must:
This validation was provided by a QSA (Qualified Security Assessor) firm qualified by the PCI Security Standards Council to validate an entity’s adherence to PCI DSS.
The Attestation of Compliance (AoC) serves as evidence for our customers that Wazuh Cloud is compliant with the PCI DSS v3.2.1 security standard. This AoC is effective as of November 3, 2019.
Update: This validation was renewed in October 26, 2021.
Launched by five global payment brands (American Express, Discover, MasterCard, Visa, and JCB), Payment Card Industry Data Security Standard (PCI DSS) is a set of standards that require merchants and service providers that store, process, or transmit customer payment card data to adhere to strict information security controls and processes. The standard includes 12 requirements:
Read more about the requirements in PCI Security Standards.
The top benefits that you can expect when an organization achieves PCI DSS compliance are:
In summary, PCI DSS is often considered as a good indicator of the ability of an organization to secure any type of sensitive data, even when the service is not processing, storing or transmitting credit card data.
Our main priority at Wazuh is keeping our customers safe. Extensive resources are dedicated to this purpose, and PCI DSS is just the beginning. We are in the process of new security certifications like SOC2. Contact us for more information.
If you have any questions about this, don’t hesitate to check out our documentation to learn more about Wazuh or join our community where our team and contributors will help you.