Is Authorize.net PCI DSS compliant?
KA-04449
182
07/24/2026 22:16 PM
3.0
Overview
This article explains how to obtain verification of Authorize.net Payment Card Industry Data Security Standard (PCI DSS) compliance, including access to the Authorize.net Attestation of Compliance (AoC). Use this article when you need to confirm Authorize.net's current PCI DSS status for your organization's compliance documentation, vendor reviews, or audit requirements.
Payment Card Industry Data Security Standard (PCI DSS)
The Payment Card Industry Data Security Standard (PCI DSS) is a comprehensive set of security requirements established by the major payment card brands to help protect payment card data. Authorize.net maintains PCI DSS compliance and undergoes annual validation.
You can obtain verification of Authorize.net PCI DSS compliance through the Visa Global Registry of Service Providers.
Obtaining Authorize.net PCI DSS Verification
- Visiting the Visa Global Registry of Service Providers.
- Entering Authorize.Net in the Company Name field under Find a Service Provider.
- Selecting Search.
- Opening the listing for Cybersource (including Authorize.net and K.K.).
- Reviewing the compliance information associated with the service provider listing.
Attestation of Compliance (AoC)
The Attestation of Compliance (AoC) is the formal document issued as part of PCI DSS validation. The Visa Global Registry of Service Providers contains current validation information for Authorize.net and related compliance documentation.
Common Questions
- Is Authorize.net PCI DSS compliant?
- Yes. Authorize.net maintains PCI DSS compliance and undergoes annual validation.
- Where can I verify Authorize.net's PCI DSS compliance?
- You can verify Authorize.net's PCI DSS compliance through the Visa Global Registry of Service Providers by searching for "Authorize.Net" and opening the CyberSource (including Authorize.Net and K.K.) listing.
- Why does the Visa Global Registry list Authorize.net under CyberSource?
- Authorize.net's compliance information is listed under the "CyberSource (including Authorize.Net and K.K.)" entry, which reflects the corporate service provider registration.
- What is an Attestation of Compliance (AoC)?
- The Attestation of Compliance (AoC) is the formal document issued as part of PCI DSS validation to confirm that an organization has met the required security standards.
- How can I access Authorize.net's Attestation of Compliance (AoC)?
- You can access the current validation information and related compliance documentation for Authorize.net directly through the Visa Global Registry of Service Providers.
- How often does Authorize.net renew its PCI DSS compliance?
- Authorize.net undergoes PCI DSS validation annually.
Glossary
- PCI DSS – Payment Card Industry Data Security Standard
- AoC – Attestation of Compliance
Related Resources
- Authorize.net Data Security and Compliance
- What Is PCI Compliance and how do I find out if I am compliant?
- Requesting SSAE-18 SOC Reports
- Vendor Questionnaire and Due Diligence Requests
Was this article helpful?
