PCI DSS v4.0 Shared Responsibility Matrix

Auctria.com Inc. | Issued for customer use under PCI DSS Requirement 12.9

Version 1.1 | May 29, 2026

How to Read This Document

This matrix describes the division of PCI DSS v4.0 responsibilities between Auctria and its customers. It is provided in accordance with PCI DSS Requirement 12.9.2 to support customers' own compliance programs.

  • ✓ Auctria — Auctria owns and is solely responsible for this requirement within the platform.
  • ✓ Customer — The customer owns and is solely responsible for this requirement within their environment.
  • ✓ Shared — Both parties have responsibilities. See the Notes column for the specific split.

Customers may present this document to their own QSA or assessor as evidence of Auctria's responsibilities. Auctria's current Attestation of Compliance (AOC) is available on request.


Requirement 1 — Install and Maintain Network Security Controls

ReqRequirement / Control AreaAuctriaCustomerSharedNotes
1.1Security policies and operational procedures for network security controlsEach party maintains policies covering their own environment
1.2Network security control (NSC) configuration, change management, and review for the Auctria platformAuctria manages all platform-side firewall/NSC rules; customers must manage NSCs on their own networks
1.3Network access controls restricting inbound/outbound traffic to what is necessaryAuctria enforces CDE network segmentation
1.4Controls between trusted and untrusted networks, including CDE boundary protectionAuctria's cloud infrastructure (AWS) provides this boundary
1.5Risks from connecting to untrusted networks managed on customer-controlled devicesCustomers are responsible for security controls on their own devices connecting to Auctria

Requirement 2 — Apply Secure Configurations to All System Components

ReqRequirement / Control AreaAuctriaCustomerSharedNotes
2.1Security policies and procedures for system configurationEach party maintains policies for their own systems
2.2System components configured per hardening standards; unnecessary services removedAuctria manages configuration of all platform components
2.3Wireless environments configured securelyCustomers are responsible for any wireless access on their premises

Requirement 3 — Protect Stored Account Data

ReqRequirement / Control AreaAuctriaCustomerSharedNotes
3.1–3.7Protection of cardholder data — tokenization and storage by payment partnersFor online/hosted payment flows and card-present transactions using encrypted hardware readers (Stripe Terminal WisePad, M2), card numbers are encrypted or tokenized at point of entry and never transmitted through Auctria's application layer. For card-present transactions using USB keyboard-wedge (HID) readers, the PAN transits the Auctria application layer prior to tokenization — Auctria ensures it is never logged or persisted. Customers must not store card data outside the designated payment flow.

Requirement 4 — Protect Cardholder Data with Strong Cryptography During Transmission

ReqRequirement / Control AreaAuctriaCustomerSharedNotes
4.1Security policies and procedures for data-in-transit protectionEach party maintains policies covering their own transmission paths
4.2Strong cryptography (TLS 1.2+) used for all transmissions over open/public networksAuctria enforces TLS on all platform endpoints. For online payment flows and encrypted hardware readers (WisePad, M2), card numbers never traverse Auctria's application layer. For USB keyboard-wedge (HID) readers, the PAN transits the application layer in transit to tokenization — Auctria ensures it is protected and never exposed beyond that handoff. Customers must use HTTPS for all integrations.

Requirement 5 — Protect All Systems Against Malware

ReqRequirement / Control AreaAuctriaCustomerSharedNotes
5.1–5.2Anti-malware policies and solution deployment on Auctria platform componentsAuctria manages threat detection on platform infrastructure
5.3–5.4Anti-malware solution management on customer-controlled systems and end-user devicesCustomers are responsible for anti-malware on their own workstations and systems

Requirement 6 — Develop and Maintain Secure Systems and Software

ReqRequirement / Control AreaAuctriaCustomerSharedNotes
6.1–6.3Secure development practices, vulnerability management, and patch management for Auctria platform codeAuctria is responsible for secure development, patching, and vulnerability management of the platform
6.4Integrity and security of payment page integrations on Auctria-hosted pagesAuctria is responsible for the integrity of payment integrations on its platform. Customers must not modify, replace, or inject scripts into any Auctria-hosted payment flow.
6.5Change control, environment separation, and test data management for Auctria releasesAuctria manages its own software release and change management process

Requirement 7 — Restrict Access to System Components and Cardholder Data by Business Need to Know

ReqRequirement / Control AreaAuctriaCustomerSharedNotes
7.1–7.2Access control model and least-privilege access assignment for Auctria platformAuctria enforces role-based access control on the platform
7.3Access control system configured with deny-all default for the Auctria platform
7.2 (customer admin)Access assigned to customer administrator accounts within AuctriaCustomers are responsible for managing which of their staff have admin access in Auctria and applying least privilege

Requirement 8 — Identify Users and Authenticate Access to System Components

ReqRequirement / Control AreaAuctriaCustomerSharedNotes
8.2–8.3User identity management, MFA enforcement, and authentication policies on the Auctria platformAuctria enforces MFA, password complexity, lockout, and session timeout for all platform users
8.6Management of application and system accounts within the Auctria platform
8.2 (customer users)Customer responsibility to manage their own user accounts: provisioning, deprovisioning, and access reviewsCustomers must promptly remove access for departed staff and review active accounts periodically

Requirement 9 — Restrict Physical Access to Cardholder Data

ReqRequirement / Control AreaAuctriaCustomerSharedNotes
9.1–9.4Physical security of Auctria platform infrastructure and cloud environmentAuctria's infrastructure runs on AWS; physical data centre security is managed by AWS. Customers have no physical access to Auctria systems.
9.5Protection of point-of-interaction (POI) devices — card readers and tap-to-payApplies to Auctria-provisioned encrypted readers (WisePad, M2). Auctria manages device software and firmware; customers are responsible for physical custody, tamper inspection, and staff training at event venues. See POI Device Responsibilities document for details. Note: USB keyboard-wedge (HID) readers are generic devices not provisioned by Auctria and are not covered by the POI document.

Requirement 10 — Log and Monitor All Access to System Components and Cardholder Data

ReqRequirement / Control AreaAuctriaCustomerSharedNotes
10.2–10.6Audit logging, log integrity, and log review for Auctria platform componentsAuctria maintains comprehensive audit logs for all platform activity
10.7Detection and response to failures of critical security controls on the Auctria platform
10.2 (customer env)Audit logging for customer-controlled systems that connect to or integrate with AuctriaCustomers are responsible for logging within their own infrastructure and integration layers

Requirement 11 — Test Security of Systems and Networks Regularly

ReqRequirement / Control AreaAuctriaCustomerSharedNotes
11.1Security policies and procedures for testingEach party maintains testing policies for their own environment
11.3.1Internal vulnerability scanning of Auctria platform (quarterly, authenticated, post-change)Auctria performs credentialed internal scans; customers must perform their own internal scans if they have in-scope systems
11.3.2External vulnerability scanning by ASV (quarterly)Auctria contracts and manages ASV scans of its external-facing infrastructure
11.4Penetration testing of Auctria platform (annual internal and external)Auctria commissions annual pen tests; results and remediation are internal to Auctria
11.5IDS/IPS and file integrity monitoring on the Auctria platform
11.6Tamper detection for payment page scripts loaded in consumer browsersAuctria monitors its payment pages for unauthorized changes. Customers must not alter payment page code.

Requirement 12 — Support Information Security with Organizational Policies and Programs

ReqRequirement / Control AreaAuctriaCustomerSharedNotes
12.1–12.2Overall information security policy and acceptable use policyEach party maintains its own information security policies
12.3Targeted risk analysis and technology reviewsEach party conducts its own risk analysis for its environment
12.4PCI DSS compliance program and executive accountability for the Auctria platformAuctria maintains a formal PCI DSS compliance program; customers rely on Auctria's AOC for platform coverage
12.5PCI DSS scope management and asset inventory for Auctria platformCustomers must confirm whether their own systems are in scope and inform Auctria of significant changes
12.6Security awareness training for Auctria personnelCustomers are responsible for security awareness training for their own staff
12.6 (customer)Security awareness training for customer personnel who use or administer Auctria
12.8Third-party service provider (TPSP) management — Auctria's vendor relationshipsAuctria manages due diligence and compliance monitoring of its own subprocessors
12.9Auctria acknowledgment of responsibility for requirements it manages on behalf of customersAuctria provides a signed AOC and this responsibility matrix to customers on request
12.10Incident response plan and testing for Auctria platformAuctria maintains its own IR plan; customers must maintain their own IR plan for their environment. Auctria will notify customers of any security incidents affecting their data per contractual obligations.

Last reviewed: May 2026
PCIResponsibilityMatrix
/compliance/PCI-Responsibilty-Matrix/
compliance
PCI-Responsibilty-Matrix
PCI DSS v4.0 Shared Responsibility Matrix
© Auctria 2013-2026