PCI hosting can provide a defined infrastructure control domain—hardened servers, TLS-only transport, a web application firewall (WAF), log retention, a patch SLA, and support for merchant-commissioned ASV scans—but it cannot complete a merchant's SAQ or take ownership of the merchant's code, people, and payment process.
Controls in the hosting domain
The contracted hosting scope covers hardened server configurations, TLS-only connections, a WAF, retained system and access logs, and a defined patch SLA. The service also supports ASV scanning by allowing the merchant's Approved Scanning Vendor to test the agreed public scope. These controls can support the infrastructure portion of an assessment, but they are evidence only for the environment operated by the host. File-integrity monitoring, HSTS, and merchant network segmentation are not stated hosting deliverables; if a merchant's assessment requires them, ownership and evidence must be established separately.
Responsibilities that remain with the merchant
The merchant still completes, signs, and files the appropriate SAQ on the acquirer's schedule. The merchant owns payment-page code, script inventory, change and tamper detection for A-EP, CMS and plugin patching, application-level logs, administrator access, staff security habits, and any systems connected to the checkout. If SAQ D applies, the merchant must also address card-data protection, key management, segmentation testing, and the broader 12-requirement program.
When a merchant uses an external call center, paper form, or staff device in the payment process, that activity remains a merchant-side scope question. Treat the host's records as one evidence source and reconcile them with application and operational records before filing the SAQ.
- Confirm the processor's own validation and keep its Attestation of Compliance.
- Keep an access-control list and dated patch and change records.
- Commission, review, and remediate required ASV scans.
- Do not put card numbers into logs, tickets, spreadsheets, or recordings unless the applicable scope explicitly covers that handling.
- Include external call-center or paper-form processes in the merchant's own scope.
Why the boundary matters
A hardened host does not secure employee laptops, inspect a merchant's payment-page JavaScript, or fill in a questionnaire. Vendor validation for one control domain does not transfer automatically to the business. The acquirer remains the final authority, and the guides describe their content as guidance rather than a QSA opinion.
Use the guides to document the split
Compare the control ownership in the PCI DSS checklist with the decision questions in the SAQ guide. For commercial information, use the plans page. A support ticket can clarify the hosting boundary, but it cannot promise a compliance result.