PCI DSS colocation compliance in 2026 means your data center must own the physical layer — access controls, surveillance, visitor logs, media destruction — while you own everything above it: network segmentation, encryption, and application security. The split is documented in a shared responsibility matrix. A colo with a current QSA-issued Attestation of Compliance reduces your audit scope; one without it shifts that validation burden entirely to you.
What Does PCI DSS Actually Scope at the Physical Layer?
Most conversations about PCI DSS focus on application security, tokenization, and network controls. Those matter. But if your cardholder data environment (CDE) lives in a colocation facility, your QSA is going to ask hard questions about the building before they get to your firewall rules.
PCI DSS v4.0 Requirement 9 is where your data center earns its keep. It requires:
- Restricted physical access to systems in the CDE
- Documented visitor authorization and escort procedures
- Video surveillance of entry/exit points with 90-day retention
- Physical access control lists reviewed at least every 90 days
- Documented procedures for media destruction and disposal
That last one trips people up more than you'd expect. When you decommission a server, your colo provider needs to document what happened to the drives — either a certificate of destruction from a third-party vendor or documented on-site shredding. If your provider hands you a decommissioned server and says "good luck," that's a gap your QSA will flag.
Requirement 12 adds facility-level policy requirements: your data center needs documented security policies, incident response procedures for physical breaches, and evidence they're actually following them. Not a binder on a shelf — evidence of execution.
What's Your Responsibility vs. Your Data Center's?
This is where most compliance programs get into trouble. The shared responsibility model in colocation isn't as clean as it is with a hyperscaler (where everything is documented in a 200-page whitepaper). In colo, you negotiate it.
Here's a practical breakdown:
| Control Area | Data Center Owns | You Own |
|---|---|---|
| Physical access to facility | ✓ | |
| Visitor logs and escort procedures | ✓ | |
| Surveillance footage retention | ✓ | |
| Physical access list review (90-day) | ✓ | |
| Media destruction documentation | ✓ | |
| Cabinet/cage access controls | Shared | Shared |
| Network segmentation | ✓ | |
| Encryption of cardholder data | ✓ | |
| Logical access controls | ✓ | |
| Application-layer security | ✓ | |
| Monitoring and logging of CDE systems | ✓ | |
| Incident response (cyber) | ✓ |
The "Shared" row on cabinet access is worth explaining. Your data center controls who can enter the building and reach your cage. You control who has the key or combination to your specific cabinet. Both matter. A QSA will ask about both.
If your colo provider can hand you a written responsibility matrix, that's a good sign. If they look at you blankly when you ask for one, you're going to spend a lot of billable hours with your QSA working it out from scratch.
What Does a QSA-Issued AOC Actually Get You?
A data center's Attestation of Compliance isn't magic. It doesn't make your environment PCI compliant — it makes the facility's physical controls pre-validated so your auditor doesn't have to test them independently.
Here's what that means practically: instead of your QSA spending time testing whether the data center's surveillance system retains footage for 90 days, they accept the AOC as evidence and move on. That's billable hours you don't pay. For a typical QSA engagement, a clean AOC from your colo provider can reduce assessment time by 20–30 hours depending on scope.
The AOC also needs to be current. PCI DSS assessments are annual. If your data center's AOC is 18 months old, your QSA may not accept it without additional validation. Ask your provider for their most recent assessment date and whether they're listed on the Visa or Mastercard service provider lists — that's public, verifiable, and your auditor will check.
IDACORE's Boise facility holds current PCI DSS certification alongside SOC 2 Type II and HITRUST CSF. When you're building a compliance program that spans multiple frameworks — common in healthcare SaaS or fintech — having a single facility that satisfies all three means you're not managing separate audit relationships for each.
What Changed in PCI DSS v4.0 That Affects Colo Customers?
PCI DSS v4.0 became the only active standard on March 31, 2024. If your compliance program is still referencing v3.2.1 controls, you're already behind.
The changes most relevant to colocation customers:
Targeted risk analysis. v4.0 gives organizations more flexibility to customize control frequencies — but that flexibility comes with documentation requirements. If you're doing physical access list reviews quarterly rather than monthly, you need a documented risk analysis that justifies it. Your data center needs to support this with their own documentation.
Stronger authentication requirements. Multi-factor authentication is now required for all access into the CDE, including physical access systems where technically feasible. Ask your data center whether their access control systems support MFA — some older badge systems don't, and that's a conversation to have before your audit.
Increased focus on ongoing compliance. v4.0 explicitly moves away from point-in-time compliance toward continuous monitoring. Your data center should be able to demonstrate ongoing adherence, not just produce a certificate from last year's assessment.
Customized implementation. v4.0 allows organizations to meet the intent of a requirement through alternative controls if they can demonstrate equivalent security. This is more relevant to your own environment than your colo facility, but it means your QSA engagement will be more complex — which puts more weight on having clean documentation from your data center to reduce scope elsewhere.
What Should You Actually Ask a Colocation Provider Before Signing?
Don't wait until your QSA engagement to discover your data center can't answer basic compliance questions. These are the questions worth asking during the sales process:
"Can you provide your current PCI DSS AOC?" If they have one, they'll have it ready. If they hedge, assume they don't.
"When was your last QSA assessment and when is the next one?" You want a provider on an annual cycle, not one who did a one-time assessment three years ago.
"Can you provide a written shared responsibility matrix?" This should be a standard document. It protects both parties.
"How do you handle media destruction for decommissioned hardware?" Ask for a sample certificate of destruction. See if they have a documented process or if it's ad hoc.
"What's your process if there's a physical security incident?" They should have a documented incident response procedure for physical breaches — not just cyber incidents.
"What other compliance frameworks do you hold?" SOC 2 Type II and HITRUST CSF alongside PCI DSS means the facility has been through rigorous third-party assessment across multiple control frameworks. That's meaningful.
A provider who can answer all of these clearly, quickly, and with documentation is one you can build a compliance program around. One who can't is one you'll be explaining to your QSA.
Frequently Asked Questions
Does my colocation data center need to be PCI DSS certified?
Not necessarily certified, but it needs to be compliant with the physical security and environmental controls that fall under PCI DSS scope. Many data centers provide a PCI DSS Attestation of Compliance (AOC) or are listed on the Visa/Mastercard service provider lists, which simplifies your own audit. Without this documentation, you're responsible for validating those controls yourself — which is expensive and time-consuming.
What is the difference between a PCI DSS certified data center and a PCI compliant one?
A "certified" data center has completed a formal QSA assessment and holds an Attestation of Compliance (AOC) for the services it provides. A "compliant" data center meets the requirements but may not have gone through third-party validation. For your PCI audit, a QSA-issued AOC from your colo provider is the cleanest path — it reduces your assessment scope and gives your auditor something concrete to reference rather than relying on your own testing of physical controls.
Which PCI DSS requirements apply to the data center, and which are my responsibility?
PCI DSS v4.0 splits responsibility at the service boundary. Your data center is typically responsible for Requirements 9 (physical access controls, visitor logs, camera retention), parts of Requirement 12 (facility security policies), and environmental controls. You own everything above the physical layer: network segmentation, encryption, access control to cardholder data, application security, and monitoring. Your colo provider should give you a responsibility matrix — if they can't, that's a red flag.
How does PCI DSS v4.0 change what I need from my colocation provider in 2026?
PCI DSS v4.0 became the only active standard on March 31, 2024, with customized implementation requirements fully in effect. The biggest change affecting colo customers is stronger requirements around targeted risk analysis, physical access review frequency, and media destruction documentation. Your data center needs to demonstrate ongoing compliance, not just point-in-time certification. Ask your provider how often they review physical access lists and whether they can provide documented evidence of media destruction for decommissioned hardware.
Can I use a colocation facility in Idaho for PCI DSS compliance with cardholder data?
Yes. Idaho-based colocation facilities can fully support PCI DSS compliant environments for cardholder data. IDACORE's Boise facility holds SOC 2 Type II, PCI DSS, and HITRUST CSF certifications, with physical security controls, documented access logs, and audit support that satisfy QSA requirements. Idaho data residency also means your cardholder data doesn't cross state lines — which simplifies data flow diagrams and reduces the geographic scope your auditor needs to assess.
If you're building or auditing a PCI DSS environment and want a data center that can hand you a current AOC, a written responsibility matrix, and a support team that actually knows your rack — not a ticket queue — talk to us about colocation at IDACORE Boise. We've been through enough compliance audits alongside our customers to know exactly what your QSA is going to ask.