What is cardholder data?
Cardholder data is the primary account number (PAN) on a payment card, plus the cardholder name, expiry date, and service code when stored with it. PCI DSS (Payment Card Industry Data Security Standard) sets the controls for any system that stores, processes, or transmits it. That set of systems is called the cardholder data environment (CDE).
What the buyer is really asking
The best answer for most SaaS companies is that card numbers never touch your systems because a PCI-compliant processor handles them. If that is true, name the processor and your SAQ type. If you do store or transmit card data, describe your cardholder data environment and its PCI DSS validation.
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you protect cardholder data?”
- “Describe your cardholder data environment (CDE).”
- “Are you PCI DSS compliant?”
- “Do you store credit card numbers?”
Evidence to have ready
- Your PCI DSS Attestation of Compliance or completed SAQ
- The payment processor's AOC, if card data never reaches you
- A data flow diagram for card payments
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.