Search code examples
securitycloudazure-sql-databasepci-dss

Is SQL Azure PCI-DSS Compliant?


If I were to use separate Windows Server that was PCI-DSS compliant, would I still be compliant if I had a SQL Azure hosting the backend? This is assuming that I'm compliant at the application layer, and that I'm only storing permitted values (like no CVV), etc.


Solution

  • AWS is now PCI DSS 2.0 Level 1 compliant, so the assumptions that Level 1 is not achievable by a cloud vendor is not correct:

    http://aws.amazon.com/security/pci-dss-level-1-compliance-faqs/

    In addition, Rackspace has also achieved PCI Level 1 compliance:

    http://www.rackspace.co.uk/rackspace-home/media-centre/news/article/article/rackspace-enhances-security-with-pci-accreditation/

    It is true that Microsoft has not yet achieved PCI compliance for Windows Azure.

    It is likely that they are actively working on addressing any limitations in Windows Azure so that they will also be able to provide this service to their customers and remain competitive, but as of today they have not yet achieved PCI compliance.