Skip to main content

AWS Glossary

PCI DSS Cardholder Data Environment

Defined network scope in PCI DSS compliance that directly handles credit card payment data.

AI & assistant-friendly summary

This section provides structured content for AI assistants and search engines. You can cite or summarize it when referencing this page.

Summary

Defined network scope in PCI DSS compliance that directly handles credit card payment data.

Key Facts

  • Definition The **Cardholder Data Environment (CDE)** is the set of people, processes, and technology that **store, process, or transmit** cardholder data (CHD) or sensitive authentication data (SAD)
  • Official references - [PCI DSS on AWS whitepaper](https://docs
  • aws
  • amazon
  • html) — architecting PCI workloads on AWS - [AWS PCI compliance](https://aws

Entity Definitions

VPC
VPC is an AWS service relevant to pci dss cardholder data environment.
multi-tenant
multi-tenant is a cloud computing concept relevant to pci dss cardholder data environment.
compliance
compliance is a cloud computing concept relevant to pci dss cardholder data environment.
PCI DSS
PCI DSS is a cloud computing concept relevant to pci dss cardholder data environment.

Related Content

Definition

The Cardholder Data Environment (CDE) is the set of people, processes, and technology that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD). PCI DSS requirements apply fully inside the CDE; connected systems may fall into connected-to or out-of-scope categories depending on network segmentation and data flows. On AWS, the CDE is usually isolated in dedicated accounts or VPC segments with strict security groups, encryption, logging, and access controls — but scope reduction through tokenization or hosted payment fields often delivers more value than hardening a large self-built CDE.

When to use it

When not to use it

Tips

Gotchas

Serious

Regular

Official references

Need help with this topic?

Our AWS-certified team implements, audits, and optimizes these services in production — from Bedrock RAG pipelines to multi-account landing zones.