→ Back to Home
AWS Security

AWS Expands PCI DSS and 3DS Compliance Scope, Enhancing Secure Payment Processing

Amazon Web Services (AWS) has successfully completed its Spring 2026 Payment Card Industry Data Security Standard (PCI DSS) and Three Domain Secure (3DS) certifications. This renewal brings a significant expansion to the compliance scope, incorporating three additional AWS services and one new AWS Region. Specifically, Amazon Bedrock AgentCore, AWS Parallel Computing Service, and AWS Skill Builder are now included, alongside the Asia Pacific – New Zealand region. These updated compliance packages, which include the Attestation of Compliance (AOC) and an AWS Responsibility Summary, are readily accessible to customers via AWS Artifact, a self-service portal designed to streamline audit processes. This development holds substantial importance for any organization that processes, stores, or transmits payment card data and leverages AWS infrastructure. The expanded scope means that businesses in the financial sector, e-commerce, and other industries subject to PCI regulations can now confidently integrate a wider array of AWS services into their compliant architectures. This directly addresses previous limitations, potentially removing the need for complex workarounds or maintaining certain workloads on-premises solely due to compliance requirements. The availability of refreshed documentation through AWS Artifact is a practical benefit, simplifying the often-onerous audit preparation and execution for compliance and security teams. The continuous expansion of compliance certifications by leading cloud providers like AWS is a clear and established trend within the cloud computing landscape. This trend is largely driven by the increasing regulatory demands placed on cloud deployments and the accelerating migration of sensitive, mission-critical workloads to the cloud. As more businesses entrust their core operations, including payment processing, to cloud platforms, the onus is on providers to demonstrate rigorous adherence to industry-specific and global security standards. This move by AWS reinforces its commitment to the shared responsibility model, where AWS secures the underlying cloud infrastructure, while providing customers with the necessary tools and certifications to build and operate secure applications within that environment. The inclusion of services like Amazon Bedrock AgentCore also highlights the growing intersection of advanced AI capabilities with stringent security and compliance requirements. In practice, security architects and DevOps engineers should proactively review the updated “AWS Services in Scope by Compliance Program” page to identify how these newly certified services can be integrated into their existing or planned PCI-compliant environments. This presents an opportunity to optimize and modernize payment-related workloads, potentially leading to greater agility, scalability, and cost efficiency. Leveraging AWS Artifact for the latest AOC and Responsibility Summary will be critical for maintaining an up-to-date compliance posture and facilitating smoother audit experiences. Furthermore, this expansion underscores the ongoing need for practitioners to deeply understand the nuances of the shared responsibility model and to actively utilize AWS's comprehensive suite of compliance and security tools to bolster their overall security posture.
#pci dss#3ds#compliance#aws security#financial services#aws artifact
Read original source