Microsoft 2021 O365 PCI AOC v3.2.1
Microsoft 2021 O365 PCI AOC v3.2.1
Microsoft 2021 O365 PCI AOC v3.2.1
PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 June 2018
© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 1
DocuSign Envelope ID: 2A8BBB16-E4D9-46BF-9BBA-6C794704563B
PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 June 2018
© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 2
DocuSign Envelope ID: 2A8BBB16-E4D9-46BF-9BBA-6C794704563B
Describe how and in what capacity your business is Microsoft M365 is a SaaS service provider, offering
otherwise involved in or has the ability to impact the SharePoint Online (SPO), and OneDrive for Business
security of cardholder data. (ODB) services (ODBSPO) to customers of all sizes.
SPO and/or ODB customers, or subscribers, may store
or transmit CHD in their allocated environments.
Subscribers are responsible for all applicable PCI
requirements pertaining to CHD handling in transit or at
rest, whereas M365 is responsible for SPO and ODB
system components’ applicable PCI requirements. SPO
and ODB infrastructure is hosted and managed by
Microsoft Azure. Azure is a Level 1 PCI-DSS compliant
Service Provider as validated by AOC version 3.2.1,
dated 03/05/2021.
PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 June 2018
© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 3
DocuSign Envelope ID: 2A8BBB16-E4D9-46BF-9BBA-6C794704563B
PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 June 2018
© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 4
DocuSign Envelope ID: 2A8BBB16-E4D9-46BF-9BBA-6C794704563B
PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 June 2018
© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 5
DocuSign Envelope ID: 2A8BBB16-E4D9-46BF-9BBA-6C794704563B
If Yes:
Does your company have a relationship with one or more third-party service providers (for Yes No
example, Qualified Integrator Resellers (QIR), gateways, payment processors, payment
service providers (PSP), web-hosting companies, airline booking agents, loyalty program
agents, etc.) for the purpose of the services being validated?
If Yes:
Microsoft Azure Azure provides Infrastructure as a Service (IaaS), Colocation services, and
network devices management.
PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 June 2018
© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 6
DocuSign Envelope ID: 2A8BBB16-E4D9-46BF-9BBA-6C794704563B
Name of Service Assessed: Microsoft SharePoint Online and OneDrive for Business
Requirement 1: 1.3.6 – N/A – M365 does not store CHD in any system
components
Requirement 3: 3.1, 3.2, 3.3, 3.4 – N/A – M365 does not directly store,
process or transmit CHD. All CHD handling requirements
are the customers’ responsibilities.
3.4.1 – N/A – M365 does not use disk encryption to store
customer data, potentially containing CHD. Instead, M365
uses the file-level encryption to encrypt the customer
data.
3.5, 3.5.1, 3.5.2, 3.5.3, 3.5.4, 3.6, 3.6.1, 3.6.2, 3.6.3,
3.6.4, 3.6.5, 3.6.6, 3.6.7, 3.6.8 - N/A – M365 does not
directly store, process or transmit CHD. All CHD handling
requirements are the customers’ responsibilities.
PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 June 2018
© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 7
DocuSign Envelope ID: 2A8BBB16-E4D9-46BF-9BBA-6C794704563B
Requirement 7:
Requirement 9: 9.5.1, 9.6, 9.6.1, 9.6.2, 9.6.3, 9.7, 9.7.1, 9.8, 9.8.1, 9.8.2 –
Not applicable – M365 does not backup cardholder data
to an external/removable media.
9.9, 9.9.1, 9.9.2, 9.9.3 – N/A – M365 does not
own/maintain POS devices
Requirement 10: 10.2.1 – N/A – M365 does not directly store, process or
transmit CHD.
Requirement 12: 12.3.9, 12.3.10 – N/A - M365 does not directly store,
process or transmit CHD or allow vendors access.
Appendix A1: A1.1, A1.2, A1.3, A1.4 - N/A - M365 is not a shared
hosting provider.
Appendix A2: A2.1 – N/A - M365 does not directly process any card-
present transactions from any system including point-of-
sale (POS) devices.
A2.2 – N/A - M365 does not directly process any card-
present transactions from any system including point-of-
sale (POS) devices.
PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 June 2018
© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 8
DocuSign Envelope ID: 2A8BBB16-E4D9-46BF-9BBA-6C794704563B
This Attestation of Compliance reflects the results of an onsite assessment, which is documented in an
accompanying Report on Compliance (ROC).
The assessment documented in this attestation and in the ROC was completed 07/29/2021
on:
Have compensating controls been used to meet any requirement in the ROC? Yes No
Were any requirements in the ROC identified as being not applicable (N/A)? Yes No
Were any requirements in the ROC unable to be met due to a legal constraint? Yes No
PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 June 2018
© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 9
DocuSign Envelope ID: 2A8BBB16-E4D9-46BF-9BBA-6C794704563B
Compliant: All sections of the PCI DSS ROC are complete, all questions answered affirmatively,
resulting in an overall COMPLIANT rating; thereby Microsoft OneDrive for Business and SharePoint
Online has demonstrated full compliance with the PCI DSS.
Non-Compliant: Not all sections of the PCI DSS ROC are complete, or not all questions are
answered affirmatively, resulting in an overall NON-COMPLIANT rating, thereby N/A has not
demonstrated full compliance with the PCI DSS.
Target Date for Compliance: N/A
An entity submitting this form with a status of Non-Compliant may be required to complete the Action
Plan in Part 4 of this document. Check with the payment brand(s) before completing Part 4.
Compliant but with Legal exception: One or more requirements are marked “Not in Place” due to a
legal restriction that prevents the requirement from being met. This option requires additional review
from acquirer or payment brand.
If checked, complete the following:
Affected Requirement Details of how legal constraint prevents requirement being met
N/A N/A
The ROC was completed according to the PCI DSS Requirements and Security Assessment
Procedures, Version 3.2.1, and was completed according to the instructions therein.
All information within the above-referenced ROC and in this attestation fairly represents the results of
my assessment in all material respects.
I have confirmed with my payment application vendor that my payment system does not store
sensitive authentication data after authorization.
I have read the PCI DSS and I recognize that I must maintain PCI DSS compliance, as applicable to
my environment, at all times.
If my environment changes, I recognize I must reassess my environment and implement any
additional PCI DSS requirements that apply.
PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 June 2018
© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 10
DocuSign Envelope ID: 2A8BBB16-E4D9-46BF-9BBA-6C794704563B
1
Data encoded in the magnetic stripe or equivalent data on a chip used for authorization during a card-present transaction. Entities
may not retain full track data after transaction authorization. The only elements of track data that may be retained are primary
account number (PAN), expiration date, and cardholder name.
2
The three- or four-digit value printed by the signature panel or on the face of a payment card used to verify card-not-present
transactions.
3
Personal identification number entered by cardholder during a card-present transaction, and/or encrypted PIN block present
within the transaction message.
PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 June 2018
© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 11
DocuSign Envelope ID: 2A8BBB16-E4D9-46BF-9BBA-6C794704563B
PCI DSS v3.2.1 Attestation of Compliance for Onsite Assessments – Service Providers, Rev. 1.0 June 2018
© 2006-2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 12