If your support team touches card data, your outsourcing partner's security becomes your security. SupportYourApp holds PCI DSS Level 1 certification as a service provider, the highest tier the standard offers. This article explains what that involves each year and why it matters when you're choosing who handles your customers.
Key takeaways
- The top validation tier for service providers comes with an independent audit that repeats every year, not a one-off badge.
- A set of separate checks sits behind the certificate, from outside network scans to a signed form your auditors can request.
- For clients, it means lighter compliance work and support agents who can handle payment issues without handing them off.
- It also gives you a clear yardstick for comparing outsourcing vendors before any card data changes hands.
Why Your Vendor's Security Is Your Problem Too
Third parties now show up in far more breaches than they used to. Verizon's 2025 Data Breach Investigations Report found that third-party involvement doubled to 30% of breaches in a single year. For companies that outsource support, that figure lands close to home. Agents see payment details. Their access becomes part of your attack surface.
That's why security certifications carry so much weight when you compare vendors. They're proof from an outside party, not a promise in a sales deck. Buyers know the difference. And PCI DSS Level 1 is the hardest one for a support provider to earn.
What Is PCI DSS Level 1?
Card brands sort service providers into two tiers, mostly by volume. Visa, for example, places any provider handling more than 300,000 of its transactions a year at Level 1. That tier demands an on-site assessment by a Qualified Security Assessor (QSA) rather than a self-assessment questionnaire. It's the harder route.
The standard itself comes from the PCI Security Standards Council, which the major card brands founded. Today's assessments run against PCI DSS v4.0.1, the current version. Assessors test Level 1 providers on every requirement that applies to them. Size doesn't buy exemptions.
The Five Checks Behind Every Annual Assessment
Level 1 isn't a certificate you earn once and frame on the wall. SupportYourApp repeats the full verification process every year, and each cycle covers five checks. Some run quarterly in between. Here's what each one involves and why it's there.
Quarterly scan by an approved scanning vendor (ASV)
An outside firm approved by the PCI Security Standards Council scans every internet-facing system for known weaknesses. We fix anything it flags and rescan until the result comes back clean. A failed scan doesn't count.
Annual Report on Compliance (ROC) by a Qualified Security Assessor
An independent QSA spends time on site, testing each applicable control and questioning the people who run them. The ROC is the full written record of that audit, and it's the core of Level 1 validation.
Penetration test
Security specialists try to break into our network and applications the way an attacker would. It runs at least once a year and again after any significant change. We fix every finding.
Internal vulnerability scan
Every quarter, we scan from inside the network to catch gaps an outside scanner can't reach, like an unpatched server only staff can see. Where the PCI penetration test acts like an attacker, this scan works like a routine health check.
AOC form
This signed document summarises the assessment and confirms we meet the standard. It's the file clients and their auditors ask for, since it's far shorter than the full audit report. Ask us for ours.
Skip any of these and the whole validation fails. That's by design. The standard assumes security drifts over time unless someone outside the company keeps checking, so the checks never stop. For us, that rhythm has become part of normal operations.
What PCI DSS Level 1 Certification Means for You as a Client
The first benefit is less compliance work on your side. When your own auditors review your vendors, they can rely on our attestation of compliance (AOC). It proves we passed. You don't have to audit us yourself. That can shrink your assessment scope and speed up security reviews during procurement.
Second, agents can do more. SupportYourApp's teams can handle cardholder data and billing disputes inside an environment that outside specialists test every year. For fintech companies and eCommerce brands, support can then solve payment problems on first contact. Customers don't get bounced.
Third, trust you can check. Our security page lists every certification we hold, from ISO/IEC 27001 to our GDPR, CCPA and HIPAA compliance. Each one now sits alongside our status as a PCI DSS service provider at the highest validation level.
If you're still comparing vendors, our roundup of PCI-compliant call center providers is a useful place to start. If you want a support team that works to Level 1 standards, get your quote and we'll plan around your payment flows.