In July 2025, Qantas, Australia’s flagship airline, was hit with a cyber attack that exposed the sensitive data of 5.7 million customers

How did the cyber criminals access this data? Through a third-party customer service platform used by an outsourced call centre. It’s a stark reminder of the additional cyber risk inherent to engaging service providers – and that outsourcing critical business functions doesn’t mean outsourcing responsibility in the event of a data breach

No matter the size of your organisation, it’s likely you’ll deal with service providers. It might be an IT support company, a marketing agency, or a vendor that supplies and maintains critical parts of your tech stack.

While these partners help keep your organisation running, they can also introduce unexpected security risks. This is especially true if they have access to systems connected to your cardholder data environment (CDE).

When organisations think about PCI DSS compliance, it’s natural to focus on the obvious partners: payment processors, POS vendors, or anyone directly handling credit card transactions. But that’s a common misconception. Many service providers that never touch a credit card still need to pay close attention to PCI compliance. And organisations that accept card payments must make sure they do to maintain their own compliance. 

These are known as “connected-to” service providers.

 

What is a Connected-To Service Provider?

Connected-to service providers are service providers with access to your systems that are on the same network as the cardholder data environment (CDE). This access is typically necessary for them to deliver their services – whether it’s managing networks, maintaining applications, or providing specialist support.

It doesn’t stop there. These connected-to providers might also engage their own subcontractors (often called nested service providers), who in turn may have some level of access to your environment.

 

Why Service Providers are a Security Risk – Even if They Don’t Process Payments

While you may trust your service provider, they’re not part of your organisation. As such, their environment is outside your direct control. No matter how strong your own security posture is, cyber criminals could still gain access to your systems by exploiting weaknesses in your service provider’s systems.

Think of it this way: your office might have top-tier security and rigorous access controls. But if your cleaning subcontractor doesn’t secure their office properly, a criminal could steal their keys and gain easy access to your building – bypassing all your careful safeguards. In this case, it doesn’t matter that the cleaner doesn’t have direct access to customer payment details. A criminal with intent will simply use whatever access they can get to find and reach those sensitive assets.

That’s why PCI Compliance applies to service providers – regardless of whether they have access to cardholder data. 

Any entity with access – even if it’s indirect – to the same systems that store, process, or transmit cardholder data can impact the security of that environment.

For example:

  • A managed IT service provider might have admin credentials to your network, which includes your CDE.
  • A vendor managing your HVAC or physical access controls might have connections that could be exploited to pivot into your cardholder environment.

If these connections aren’t properly secured and governed, they can introduce serious risks.

 

What Should Organisations with Service Providers do to Ensure PCI DSS Compliance?

It starts with rigorous due diligence. Before engaging any service provider, confirm they can support your security policies and your PCI DSS obligations. Where possible, work with providers that can demonstrate PCI DSS compliance across all the services they deliver to you.

Also, before granting access to a service provider:

  • Understand exactly what kind of access each service provider requires, and why.
  • Keep track of all service providers (including nested providers) who have the ability to connect to your network.
  • Only grant access that’s truly necessary.

 

Minimum PCI DSS Requirements For Service Providers

At a bare minimum, PCI DSS requires organisations to maintain:

  • Documented policies and procedures for managing service provider relationships (PCI DSS Requirement 12.8).
  • Due diligence processes for initial and ongoing engagement.
  • Written agreements clearly outlining PCI responsibilities.
  • Ongoing confirmation that the service provider’s controls remain effective.

This means PCI DSS isn’t just about your own environment. It’s also about ensuring anyone connected to your environment is living up to the same security standards.

In today’s interconnected world, many organisations underestimate how much their own PCI compliance depends on third parties. Even if a service provider never handles card data directly, their access could still be a doorway into your most sensitive systems. 

Ultimately, your customers trust you to protect their data, regardless of which vendor or platform you use behind the scenes. That’s why it’s essential to thoroughly vet third parties, build strong security requirements into contracts, and continuously monitor how they handle your information.

Selecting suppliers and service providers is hard enough. But monitoring PCI DSS compliance doesn’t have to add to it. If you’d like guidance on vendor selection, or need help getting longstanding partners up to code, our expert team is here to help. 

 

Contact us or book a complimentary security review