Skip to content

What logging does PCI DSS expect?

PCI DSS logging is a shared duty: hosting can retain system and access logs and provide host-layer file-integrity monitoring, while the merchant must keep application-level evidence, review access, and preserve roughly a year of history with recent records readily available.

Know which layer produced a log

Host-layer records describe the infrastructure: system events, administrator access, and file-integrity changes observed by the hosting environment. The merchant's application records describe the shop and payment page: sign-ins, privilege changes, configuration changes, deployment events, and relevant security alerts. One layer cannot substitute for the other. Keep a clear note of which system generated each record and who is responsible for reviewing it.

Retain evidence in a usable form

The guide calls for retained system and access logs with roughly a year of history and the most recent period readily available. Choose a retention process that prevents silent overwriting, preserves timestamps, and lets an authorized reviewer find events when an acquirer or assessor asks. Keep a current administrator list beside the logs, and record reviews or investigations instead of relying on memory. Export or protect records before a planned application change.

Protect the payment-page trail

For SAQ A-EP, the merchant also tracks scripts, changes, and tamper-detection events on the payment page. For SAQ D, the merchant's wider control program includes systems that store, process, or transmit card data. Log the security event without copying sensitive card numbers into the log. Avoid recording full card numbers, security codes, or unnecessary payment details in application, support, or debugging output; logging should make an event explainable without creating another data store.

Use logs as evidence, not as a promise

Retained logs do not complete an SAQ and do not prove that every control worked. Review them, investigate anomalies, and keep the related patch or change record. Hosting is only one control domain; staff devices, payment-page code, external call centers, and paper processes stay within the merchant's responsibility when they affect scope.

Connect logging to the SAQ decision

Start with the SAQ guide to understand which payment flow you operate, then use the checklist to assemble evidence. If you need to ask where host logs end and merchant logs begin, use the support ticket form; the acquirer still makes the final determination.


Was this article helpful?

mood_bad Dislike 0
mood Like 0
visibility Views: 19