PCI-DSS 4.0 Compliance

PCI-DSS 4.0 — Requirement 12.8

PCI-DSS 4.0 Requirement 12.8 mandates documented oversight of all third-party service providers in the cardholder data environment. ThirdProof maps findings directly to this requirement.

Start Free Trial →

First investigation free · No credit card required

PCI-DSS 4.0 — Requirement 12.8

Requirement 12.8 mandates that organizations maintain a list of all third-party service providers with which account data is shared, document written agreements, and perform due diligence prior to engaging new service providers. ThirdProof automates this due diligence and produces QSA-accepted evidence packages.

ThirdProof uses a deterministic rules engine to assign risk tiers. AI writes the narrative — rules drive the decision.

PCI-DSS 4.0-specific findings

CriticalCardholder data environment (CDE) shared responsibility assessment
IncludedTPSP compliance responsibility matrix
FlaggedGLBA Safeguards Rule alignment for financial data
IncludedDORA (EU) concentration risk assessment where applicable

QSA-accepted documentation

ThirdProof reports satisfy PCI-DSS QSA requirements for third-party due diligence evidence — reducing assessment time and scope disputes.

// PCI-DSS 12.8.5 Evidence
CDE scope: In-scope (payment processing)
TPSP type: Payment gateway
PCI compliance attestation: Verified ✓
Responsibility matrix: Documented ✓
Annual review due: March 2027

How ThirdProof works for PCI-DSS 4.0

1
Enter the vendor

Name, domain, and data access level. ThirdProof auto-detects your industry context.

2
24 sources queried

Sanctions, cyber risk, business registry, adverse media, and more — with PCI-DSS 4.0-specific controls layered on top.

3
Download the report

PDF report with PCI-DSS 4.0 evidence statements, risk tier, confidence score, and individual findings.

Start your PCI-DSS 4.0 vendor assessment

Your first vendor investigation is completely free. Results in under 2 minutes.

Start Free Trial →

First investigation free · No credit card required

Read our full methodology · View pricing