A company is subject to PCI DSS and plans to use a cloud provider to process credit card transactions. The cloud provider has been assessed by a Qualified Security Assessor (QSA). According to PCI DSS, what must the company obtain from the provider to demonstrate compliance?
The PCI DSS Attestation of Compliance evidences the provider's assessed compliance status, while the Responsibility Matrix defines which requirements the provider covers versus the customer. Together they satisfy the obligation to demonstrate compliance for card processing.
Why this answer
Under PCI DSS, when a customer uses a cloud provider to process cardholder data, the provider must be assessed by a QSA and issue an Attestation of Compliance (AOC) along with a Responsibility Matrix (also called a Shared Responsibility Matrix or PCI DSS Responsibility Matrix). The AOC documents the provider's validated compliance status, and the Responsibility Matrix defines which PCI DSS requirements are met by the provider versus the customer. Together they let the customer demonstrate its own compliance to its acquirer or QSA.
Exam trap
CCSP often tests the confusion between compliance frameworks — candidates see 'cloud provider' and 'compliance' and reach for SOC 2 or ISO 27001, but PCI DSS specifically requires a QSA-issued AOC and Responsibility Matrix from the service provider.
How to eliminate wrong answers
Option B is wrong because a Business Associate Agreement is a HIPAA construct governing protected health information, not a PCI DSS artifact — it has no bearing on cardholder data compliance. Option C is wrong because an ISO 27001 certificate attests to an information security management system, not to PCI DSS controls; it is useful evidence but does not satisfy PCI DSS's specific requirement for a QSA-assessed AOC. Option D is wrong because a SOC 2 Type II report covers the Trust Services Criteria (security, availability, etc.) and, while often used as supporting evidence, is not the PCI DSS-specific attestation the standard requires from a service provider.